Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
GuardScan — 100% Free & Open Source • Privacy-First Security Scanning and AI Code Review CLI | Kitploit
Tools/GitHubGitHub/ntanwir10/guardscan
Static AnalysisVulnerability ScannersCode AnalysisCloud SecurityDevSecOpsUtilities & FrameworksSecret DetectionSupply Chain SecurityLearning & EducationAPI SecurityAI Security
154153 months agoNot yet reviewed
GitHub
ntanwir10/guardscan

GuardScan

100% Free & Open Source • Privacy-First Security Scanning and AI Code Review CLI

View RepositoryWebsite

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

🛡️ GuardScan

100% Free & Open Source • Privacy-First Security Scanning and AI Code Review CLI

  ____ _   _   _    ____  ____    ____   ____    _    _   _            ____ _     ___ 
 / ___| | | | / \  |  _ \|  _ \  / ___| / ___|  / \  | \ | |          / ___| |   |_ _|
| |  _| | | |/ _ \ | |_) | | | | \___ \| |     / _ \ |  \| |  _____  | |   | |    | |
| |_| | |_| / ___ \|  _ <| |_| |  ___) | |___ / ___ \| |\  | |_____| | |___| |___ | | 
 \____|\___/_/   \_\_| \_\____/  |____/ \____/_/   \_\_| \_|          \____|_____|___|

 Privacy-First AI Code Review & Security Scanning

License: MIT Node.js Version


🎉 Completely Free - No Subscriptions, No Limits

GuardScan is 100% free and open source! No credit system, no paywalls, no subscriptions.

What You Get (All FREE)

  • ✅ Unlimited static analysis - 9 security scanners + code quality tools
  • ✅ AI-enhanced code review - Bring your own API key (OpenAI, Claude, Gemini, Ollama)
  • ✅ Works fully offline - No internet required for static analysis
  • ✅ Privacy-first - Never uploads your source code
  • ✅ No usage limits - Scan unlimited LOC, unlimited repositories

🚀 Quick Start

# Install globally via npm
npm install -g guardscan

# Initialize GuardScan
guardscan init

# Run comprehensive security scan (100% FREE, offline)
guardscan security

# Configure AI provider for enhanced review (optional, BYOK)
guardscan config

# Run AI-enhanced code review
guardscan run

# Check status
guardscan status

🐳 Docker / Alpine Linux

For Docker environments, especially Alpine Linux:

# Install dependencies first
apk add --no-cache python3 make g++ pkgconfig cairo-dev pango-dev \
  libjpeg-turbo-dev giflib-dev pixman-dev freetype-dev build-base git

# Install GuardScan
npm install -g guardscan

# Set home directory (important for Docker)
export GUARDSCAN_HOME=/app/.guardscan

# Initialize
guardscan init

Documentation:

  • 📖 Comprehensive Docker Guide - Complete guide for Linux, macOS, and Windows
  • 🐧 Docker & Alpine Quick Reference - Alpine Linux-specific quick reference

📋 Core Features

🔒 Security Scanning (FREE, Offline)

GuardScan includes comprehensive security scanners:

  1. Secrets Detection - Find hardcoded API keys, passwords, tokens (20+ patterns)
  2. Dependency Vulnerabilities - Scan npm, pip, Maven, Cargo dependencies
  3. OWASP Top 10 - SQL injection, XSS, insecure configs, CSRF, XXE
  4. Docker Security - Dockerfile and container scanning
  5. Infrastructure as Code - Terraform, CloudFormation, Kubernetes security
  6. API Security - REST and GraphQL endpoint analysis

📊 Code Quality & Analysis (FREE, Offline)

  1. Code Metrics - Cyclomatic complexity, Halstead metrics, maintainability index
  2. Code Smells - 30+ anti-patterns (god classes, long methods, magic numbers)
  3. License Compliance - Check dependency licenses (MIT, GPL, Apache, etc.)
  4. Compliance Checks - GDPR, HIPAA, PCI-DSS compliance scanning
  5. Linter Integration - ESLint, Pylint, RuboCop, etc.
  6. LOC Counter - Language-aware line counting (20+ languages)

🧪 Testing & Performance (FREE, Offline)

  1. Test Runner - Execute and analyze Jest, pytest, JUnit tests
  2. Mutation Testing - Validate test suite effectiveness (requires Stryker - optional)
  3. Performance Testing - Load testing and benchmarking (requires k6 - optional)
  4. SBOM Generation - Software Bill of Materials (CycloneDX, SPDX)

Note: Performance and mutation testing require optional external tools.

🤖 AI-Enhanced Features (BYOK - Bring Your Own Key)

9 Advanced AI-Powered Features:

  1. Code Explainer (guardscan explain) - Understand complex code
  2. Code Review (guardscan review) - Comprehensive AI code review
  3. Commit Generator (guardscan commit) - Generate commit messages
  4. Docs Generator (guardscan docs) - Auto-generate documentation
  5. Test Generator (guardscan test-gen) - Generate unit tests
  6. Refactoring Suggestions (guardscan refactor) - Improve code quality
  7. Threat Modeling (guardscan threat-model) - Security architecture analysis
  8. Migration Assistant (guardscan migrate) - Framework/language migrations
  9. Interactive Chat (guardscan chat) - RAG-powered codebase Q&A

🌍 Multi-Language Support

AST Parsers for 7+ Languages:

  • TypeScript/JavaScript
  • Python
  • Java
  • Go
  • Rust
  • Ruby
  • PHP
  • C#

🔌 AI Provider Integrations

Configure any AI provider you prefer:

  • OpenAI (GPT-4, GPT-4 Turbo, GPT-3.5)
  • Anthropic Claude (Claude 3 Opus, Sonnet, Haiku)
  • Google Gemini (Gemini Pro)
  • Ollama (Local, privacy-focused - llama2, codellama, mistral)
  • LM Studio (Local models)
  • OpenRouter (Access to multiple models)

You pay the AI provider directly - GuardScan charges nothing!


🛠️ Commands

All commands are 100% FREE with no limits!

Configuration Commands

CommandDescription
guardscan initInitialize config, generate client_id
guardscan configConfigure AI provider & settings
guardscan statusShow configuration and repo info
guardscan resetClear local cache & config

Security & Analysis Commands

CommandDescription
guardscan securityRun comprehensive security scan (offline)
guardscan scanQuick security scan
guardscan runAI-enhanced full code review (BYOK)

Testing & Quality Commands

CommandDescription
guardscan testRun tests & code quality analysis
guardscan perfPerformance testing & load testing (requires k6 - optional)
guardscan mutationMutation testing for test quality (requires Stryker - optional)

Note: perf and mutation commands require optional external tools. See Testing Tools Guide for installation and usage details.

Utility Commands

CommandDescription
guardscan sbomGenerate Software Bill of Materials
guardscan rulesCustom YAML-based rule engine

AI-Powered Commands (BYOK)

CommandDescription
guardscan explain <file>Explain how code works
guardscan review <file>Comprehensive AI code review
guardscan commitGenerate commit messages
guardscan docs <file>Auto-generate documentation
guardscan test-gen <file>Generate unit tests
guardscan refactor <file>Get refactoring suggestions
guardscan threat-modelSecurity architecture analysis
guardscan migrateFramework/language migration help
guardscan chatInteractive Q&A about codebase (RAG)

🔒 Privacy Guarantees

We take privacy seriously:

❌ Never Stored or Transmitted

Download Tool