Sigil – source code security analysis for MCP servers (open source)
Source-code MCP security auditing. Existing scanners check descriptions; sigil reads actual code.
Static analysis tool that detects and automatically fixes ReDoS vulnerabilities in Python using sre_parse AST analysis.
AST-level regex analysis with auto-fix beats string-based ReDoS checkers.
Python developers, security engineers
Bandit · Semgrep · regex-denied
That was the result of a production ReDoS.
I was interested to know how frequent such patterns are in Python libraries that we use everyday.
Source-code MCP security auditing. Existing scanners check descriptions; sigil reads actual code.
Catches architectural erosion that Ruff and Semgrep miss entirely.
CLI-first SEO automation that resolves keyword cannibalization automatically.
Yet another PCAP analyzer competing with Wireshark and Zeek.
Markdown linter with credential scanning in code blocks, exits hard on security findings.
Smart refusal model beats reckless auto-fixers, but secret scanning is already solved ground.