
AI 기반 보안 코파일럿으로, 코딩하는 동안 취약점을 잡아냅니다. 개발자를 위한 실시간 보안 스캔, 교육적 설명, 자동 수정 기능을 제공합니다.
CodeGuard Copilot은 커밋한 후가 아니라 코딩하는 동안 보안 취약점을 잡아냅니다. 결정론적 정규식 패턴 탐지와 AI 기반 심층 분석, 그리고 Raven/WraithWall 에코시스템의 실시간 공격자 인텔리전스를 결합하여 다른 어떤 VS Code 보안 확장 프로그램도 제공할 수 없는 컨텍스트를 제공합니다.
차별점:
.codeguard.json 사용자 정의 규칙 구성 — 정규식, 심각도, CWE, 파일별


│ │ │ │
│ │ ┌─────────────┐ ┌────────────────┐ │ │
│ │ │ Knowledge │ │ Raven Bridge │ │ │
│ │ │ Graph │ │ ← attacker data │ │ │
│ │ │ finding→CWE │ │ → threat intel │ │ │
│ │ │ →MITRE→fix │ │ │ │ │
│ │ └─────────────┘ └────────────────┘ │ │
│ └──────────────────┬───────────────────┘ │
│ │ │
│ ▼ │
│ ┌──────────────────────────────────────┐ │
│ │ Developer Feedback │ │
│ │ QuickFix · Explain · Suppress · Fix │ │
│ │ Training · Report · CI/CD │ │
│ └──────────────────────────────────────┘ │
│ │
└──────────────────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────┐
│ WraithWall / Raven │
│ │
│ Cowrie Honeypot → Attacker Telemetry │
│ Campaign Correlation → Behavioral DNA │
│ CISA KEV → OWASP → Composite Scoring │
│ Cross-Repo Systemic Patterns │
│ Dark-Web Breach Monitoring │
└──────────────────────────────────────────────┘
---
## Raven Intelligence Bridge
CodeGuard Copilot은 Raven의 공격자 텔레메트리 파이프라인을 위한 **프론트엔드 인텔리전스 소비자**입니다. Cowrie 허니팟이 익스플로잇 기법을 사용하는 실제 공격자를 관찰하면, 그 패턴이 CodeGuard로 흘러 들어옵니다:
Attacker uses SQL injection on honeypot ↓ Raven detects: CWE-89, credential_access, threat_score=85 ↓ RavenIntelBridge.ingestEvent() receives event ↓ Generates candidate CodeGuard pattern at confidence 0.85 ↓ Proposed pattern: "SQL Injection (attacker-observed)" ↓ Human review → published as CodeGuard rule ↓ Developers protected against the actual exploit
반대로, CodeGuard가 취약점을 발견하면 구조화된 Raven 피드백을 생성합니다:
CodeGuard finding: CWE-798 hardcoded secret in auth/login.js ↓ RavenThreatFeedback.generateIntelligence() ↓ MITRE techniques: T1552, T1078 ↓ Raven priority score: 72 (network attack vector, low complexity) ↓ Raven elevates this finding in composite scoring ↓ SOC team sees: "Attacker-aligned credential finding in production repo"
---
## 탐지되는 취약점 카테고리
### 심각 (Critical)
SQL Injection (CWE-89), Command Injection (CWE-78), NoSQL Injection (CWE-943), Hardcoded Secrets (CWE-798), Insecure Deserialization (CWE-502)
### 높음 (High)
XSS (CWE-79), DOM-based XSS, Path Traversal (CWE-22), File Upload (CWE-434), Weak Crypto (CWE-327), Unsafe Blocks (Rust), Unescaped HTML (Go)
### 중간 (Medium)
CORS Misconfiguration (CWE-942), Open Redirect (CWE-601), Insecure Random (CWE-338), ReDoS (CWE-1333), Memory Leak (C++), Mass Assignment (Ruby)
### 낮음 (Low)
Weak Password Storage, Express Trust Proxy, Missing Security Headers, Framework anti-patterns
### 언어별 (18개 신규)
Go: SQLi, Insecure Random, Hardcoded Secret, Unescaped HTML
Rust: Unsafe Block, Hardcoded Secret, Command Injection, Weak Crypto
C++: Buffer Overflow, Memory Leak, SQL Injection
C#: SQL Injection, Connection String, Insecure Deserialization
Ruby: SQL Injection, Command Injection, Mass Assignment, Unsafe YAML
---
## 파인튜닝된 보안 모델 (v0.3.1)
CodeGuard의 파인튜닝된 모델(`Niffy90/codeguard-security-7b`)은 **Qwen2.5-7B-Instruct** 기반의 LoRA 어댑터로, 8개 카테고리에 걸친 32개의 보안 취약점 패턴으로 학습되었습니다:
- **모드 1 (기본 — HF Router API):** GPU 불필요. 사용자 정의 보안 시스템 프롬프트와 함께 HuggingFace의 가장 빠른 추론 제공자를 사용합니다.
- **모드 2 (로컬 GPU — `CODEGUARD_LOCAL_MODEL=1`):** QLoRA 4비트 양자화로 파인튜닝된 LoRA 어댑터를 로드합니다. 약 5GB의 GPU VRAM이 필요합니다.
```bash
# Local GPU inference
CODEGUARD_LOCAL_MODEL=1 codeguard scan app.py
# Or via Python
CODEGUARD_LOCAL_MODEL=1 python3 -c "
from codeguard import CodeGuardEngine
engine = CodeGuardEngine(use_local_model=True)
findings = engine.scan_file('app.py')
print(findings)
"
학습 데이터셋: WraithWall 허니팟 네트워크(500 세션)에서 1,666개 예제, OpenPhish + URLhaus(500 피싱 URL), CISA KEV(500 CVE), 그리고 정상 샘플(166개). QLoRA를 통해 T4 GPU에서 학습되었습니다.
git clone https://github.com/niffyhunt/codeguard-copilot.git
cd codeguard-copilot
npm install
npm run compile
# Press F5 in VS Code to launch Extension Development Host
pip install raven-guard
raven-guard scan .
raven-guard scan app.py --severity critical,high
raven-guard scan . --format sarif --output results.sarif
raven-guard doctor