Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Codeguard-copilot — AI-powered security co-pilot that catches vulnerabilities as you code. Real-time security scanning, educational explanations, and auto fixes for developers. | Kitploit
Tools/GitHubGitHub/niffyhunt/codeguard-copilot
Defensive ToolsStatic AnalysisVulnerability ScannersStatic Code Analysis (SAST)Vulnerability AnalysisCode AnalysisDevSecOpsSecret DetectionThreat IntelligenceLearning & EducationAI Security
182 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
GitHub
niffyhunt/codeguard-copilot

Codeguard-copilot

AI-powered security co-pilot that catches vulnerabilities as you code. Real-time security scanning, educational explanations, and auto fixes for developers.

View Repository
Share

CodeGuard Copilot — Intelligent Security Ecosystem

Version License Patterns Languages WraithCore

Your AI-Powered Security Guardian — Now Connected to Live Attacker Intelligence

Features • Architecture • Raven Integration • Installation • Roadmap • Contributing


What is CodeGuard Copilot?

CodeGuard Copilot catches security vulnerabilities as you code, not after you commit. It combines deterministic regex pattern detection with AI-powered deep analysis and live attacker intelligence from the Raven/WraithWall ecosystem to give you context no other VS Code security extension can.

What makes it different:

  • 50+ vulnerability patterns across JavaScript, TypeScript, Python, Java, PHP, Go, Rust, C++, C#, Ruby
  • Raven Intelligence Bridge — attacker behavior from live honeypots informs which vulnerabilities matter most
  • Security Knowledge Graph — connects findings to CWEs, MITRE techniques, attacker behavior, and remediation
  • AI Security Rule Generation — learns new detection patterns from real-world exploit data
  • Interactive Security Training — learn WHY code is vulnerable, not just THAT it is

Features

Real-Time Detection (Phase 1)

  • Scans as you type with configurable debounce (default 500ms)
  • 35+ built-in vulnerability patterns (17 core + 18 expanded)
  • Multi-language: JS, TS, Python, Java, PHP, Go, Rust, C++, C#, Ruby
  • Pattern-based detection (<10ms response)
  • Workspace-wide scanning with progress tracking

AI-Powered Deep Analysis (Phase 1)

  • Context-aware security analysis using Claude, GPT-4, or Groq
  • Identifies logic flaws, business logic vulnerabilities, and framework anti-patterns
  • Configurable AI provider and API key
  • Daily usage budget (guard against API costs)

Custom Rules & Plugins (Phase D)

  • .codeguard.json custom rule configuration — regex, severity, CWE, per-file
  • Plugin system for custom analyzers (SecurityAnalyzer interface)
  • Shared rule sets for team collaboration
  • Rule suppressions and path exclusions

Raven Intelligence Bridge (Phase D)

  • Attacker → Pattern: Cowrie honeypot attacker behavior → proposed CodeGuard patterns
  • Code → Threat: CodeGuard findings → MITRE-mapped threat feedback for Raven
  • Attacker-Aligned Prioritization: Findings that match real attacker behavior get elevated priority
  • Security Knowledge Graph: finding → file → function → CWE → MITRE → attacker behavior → fix

Security Training Mode (Phase D)

  • 3 interactive training modules (SQLi, XSS, hardcoded secrets)
  • Vulnerable vs secure code side-by-side
  • Real-world breach examples + quiz
  • Webview-based — works inside VS Code

CI/CD Native Integration

  • GitHub Actions workflow (scan on push/PR, Semgrep + Snyk bridge)
  • GitLab CI example configuration
  • Artifact upload for security reports

Intelligent Quick Fixes

  • One-click secure code replacements
  • "Explain this vulnerability" → webview with detailed analysis
  • "Learn more" → opens CWE reference
  • "Ignore this warning" → inline suppression comments

Architecture

Architecture Pipeline

Analysis Pipeline

Coverage

Exploitability Scoring

Exploitability Scoring

Deployment Modes

Deployment Modes │ │ │ │ │ │ ┌─────────────┐ ┌────────────────┐ │ │ │ │ │ Knowledge │ │ Raven Bridge │ │ │ │ │ │ Graph │ │ ← attacker data │ │ │ │ │ │ finding→CWE │ │ → threat intel │ │ │ │ │ │ →MITRE→fix │ │ │ │ │ │ │ └─────────────┘ └────────────────┘ │ │ │ └──────────────────┬───────────────────┘ │ │ │ │ │ ▼ │ │ ┌──────────────────────────────────────┐ │ │ │ Developer Feedback │ │ │ │ QuickFix · Explain · Suppress · Fix │ │ │ │ Training · Report · CI/CD │ │ │ └──────────────────────────────────────┘ │ │ │ └──────────────────────────────────────────────┘ │ ▼ ┌──────────────────────────────────────────────┐ │ WraithWall / Raven │ │ │ │ Cowrie Honeypot → Attacker Telemetry │ │ Campaign Correlation → Behavioral DNA │ │ CISA KEV → OWASP → Composite Scoring │ │ Cross-Repo Systemic Patterns │ │ Dark-Web Breach Monitoring │ └──────────────────────────────────────────────┘


---

## Raven Intelligence Bridge

CodeGuard Copilot is the **frontend intelligence consumer** for Raven's attacker telemetry pipeline. When Cowrie honeypots observe real attackers using exploitation techniques, the patterns flow into CodeGuard:

Attacker uses SQL injection on honeypot ↓ Raven detects: CWE-89, credential_access, threat_score=85 ↓ RavenIntelBridge.ingestEvent() receives event ↓ Generates candidate CodeGuard pattern at confidence 0.85 ↓ Proposed pattern: "SQL Injection (attacker-observed)" ↓ Human review → published as CodeGuard rule ↓ Developers protected against the actual exploit


Conversely, when CodeGuard finds a vulnerability, it generates structured Raven feedback:

CodeGuard finding: CWE-798 hardcoded secret in auth/login.js ↓ RavenThreatFeedback.generateIntelligence() ↓ MITRE techniques: T1552, T1078 ↓ Raven priority score: 72 (network attack vector, low complexity) ↓ Raven elevates this finding in composite scoring ↓ SOC team sees: "Attacker-aligned credential finding in production repo"


---

## Detected Vulnerability Categories

### Critical
SQL Injection (CWE-89), Command Injection (CWE-78), NoSQL Injection (CWE-943), Hardcoded Secrets (CWE-798), Insecure Deserialization (CWE-502)

### High
XSS (CWE-79), DOM-based XSS, Path Traversal (CWE-22), File Upload (CWE-434), Weak Crypto (CWE-327), Unsafe Blocks (Rust), Unescaped HTML (Go)

### Medium
CORS Misconfiguration (CWE-942), Open Redirect (CWE-601), Insecure Random (CWE-338), ReDoS (CWE-1333), Memory Leak (C++), Mass Assignment (Ruby)

### Low
Weak Password Storage, Express Trust Proxy, Missing Security Headers, Framework anti-patterns

### Language-specific (18 new)
Go: SQLi, Insecure Random, Hardcoded Secret, Unescaped HTML
Rust: Unsafe Block, Hardcoded Secret, Command Injection, Weak Crypto
C++: Buffer Overflow, Memory Leak, SQL Injection
C#: SQL Injection, Connection String, Insecure Deserialization
Ruby: SQL Injection, Command Injection, Mass Assignment, Unsafe YAML

---

## Fine-Tuned Security Model (v0.3.1)
Download Tool