AI-generated code, untested
Copilot, Claude Code, and Cursor write code at IDE speed. None of them scan it for security issues before it lands in your repo.
AegisQ CodeShield
Real-time security scanning for AI-generated code. 80+ rules across OWASP Top 10, OWASP LLM Top 10, and CISA Secure-by-Design. VS Code extension and a cross-platform MCP server. Source code never leaves the developer's machine. The free tier — the OWASP/CISA Security Scanner — is live on the marketplace today.
Developers are shipping AI-generated code, LLM integrations, and autonomous agents to production. Standard scanners catch SQL injection and XSS — they don't catch prompt injection, insecure output handling, or excessive agency. CodeShield is built for both.
Copilot, Claude Code, and Cursor write code at IDE speed. None of them scan it for security issues before it lands in your repo.
Prompt injection, training-data poisoning, model DoS, excessive agency — the OWASP LLM Top 10 lists ten classes of risk most SAST tools have never heard of.
Regulated teams (finance, health, defense) can't send proprietary or AI-generated code to a vendor's cloud. Scanning has to run locally.
SQL injection, XSS, auth flaws, insecure deserialization, full OWASP Top 10, OWASP LLM Top 10, and CISA Secure-by-Design coverage. One ruleset, two threat surfaces.
All scanning runs on the developer's machine. Source code, API keys, and proprietary logic are never transmitted externally. Zero telemetry by design.
Works with OpenAI, Anthropic, Google, and self-hosted models. Swap providers without changing the workflow or re-training the rule set.
Built on Model Context Protocol — the same protocol Claude Code, Cursor, and Windsurf use. CodeShield is in the editor where the code is, not alongside it.
Purpose-built detectors for the ten classes of LLM risk: prompt injection, insecure output, training-data poisoning, model DoS, supply-chain, and more.
Every finding includes severity classification, file location, the exact line range, and a specific remediation. Optional auto-fix with diff preview before apply.
Four steps from the marketplace to a clean merge. No SaaS account required.
Add the VS Code extension or run the MCP server locally. CI/CD integration via a single npm or pip package.
Real-time analysis as code is written; on-demand scans for full files; pre-merge scans in CI. 80+ rules, AI-specific risks included.
Prioritized findings with severity, location, and remediation. Optional auto-fix with diff preview before applying.
Compliance reports in OWASP, CISA, and CWE formats. Auditable, deterministic, no external data dependencies.
CodeShield exposes its scanning, explanation, and reporting capabilities as MCP tools. Claude Code, Cursor, Windsurf, and any MCP-compatible client can invoke them as part of normal coding.
Scan a file for vulnerabilities. Returns severity-prioritized findings against all 80+ rules.
Scan inline or AI-generated code snippets. Validate before integration into the codebase.
AI-powered vulnerability explanation. Risk, impact, and exploitation context in plain English.
Auto-fix generation with diff preview. See proposed code changes before they're applied.
Compliance report in Markdown / JSON / CSV. Export findings in OWASP, CISA, and CWE formats.
System status: version, license tier, scan count, and cache statistics at a glance.
v2.1.0 hardens CodeShield's own MCP server against the risks set out in the NSA's Model Context Protocol Security Information Sheet — so the tool you trust to find vulnerabilities holds to the same bar.
Aligned to the NSA Cybersecurity Information Sheet on MCP, v2.1.0 mitigates cross-server tool poisoning, silent capability drift, and token-lifecycle abuse in the MCP execution model.
Manifest hashing and trusted-publisher checks catch when an MCP tool's definition silently changes, and URN-based identifiers prevent tool name-collision attacks.
Carries forward v2.0's centralized secret redaction in logs and hardened input handling, with a 390+ test suite gating every release.
SonarQube, Veracode, and Checkmarx miss AI-specific risks entirely. CodeShield covers OWASP LLM Top 10 alongside classic vulnerabilities — one tool, both surfaces.
Copilot generates code. It doesn't scan for security issues. CodeShield validates what the AI writes, catching risks before they reach the repo.
Cloud-only scanners send code off-machine. CodeShield runs entirely locally, supports any LLM provider, and ships LLM-specific rules natively. No vendor lock-in.
Scan AI-generated code automatically in the IDE. No off-machine transmission, no slowdown.
Get assurance that AI-generated code meets internal standards. Full audit trail per scan.
OWASP Top 10, OWASP LLM Top 10, CISA Secure-by-Design — output in the formats auditors ask for.
Finance, healthcare, and defense need auditable, deterministic, local-only scanning. CodeShield is purpose-built for that.
The open-source OWASP/CISA Security Scanner. Live on the VS Code marketplace today.
$0
Forever free
AegisQ.owasp-cisa-security-scanner
For solo developers using AI coding assistants.
$19 / month
$190 / year (save $38)
For dev teams shipping with AI assistants.
$49 / month
$490 / year (save $98)
Enterprise pricing available. Contact sales for custom plans, air-gapped install, and dedicated SLAs.
Real-time AI-aware code security in your editor today. No SaaS account, no telemetry, no code leaving your machine.