GitHubMate Security ScannerAI-powered security scanning for your GitHub repositories — right inside VSCode. Scan any public or private GitHub repo for vulnerabilities, exposed secrets, IaC misconfigurations, and compliance gaps. Results appear instantly in a rich dashboard panel and in the VSCode Problems panel with inline file diagnostics. Features🔍 AI-Powered Security ScanningSend your codebase to an AI model that thinks like a security engineer — not just a regex matcher. Finds real vulnerabilities in context, not just pattern matches. 🔑 Secret DetectionCatches exposed API keys, tokens, passwords, and credentials across all file types before they hit production.
⚠️ OWASP Top 10 & LLM Top 10Detects the most critical web application and AI/LLM security risks:
🏗️ IaC & Dockerfile ScanningFinds misconfigurations in your infrastructure-as-code before they reach production:
📋 Compliance ReadinessAI-powered gap analysis for:
Each framework shows readiness status, top gaps, quick fixes, and estimated remediation timeline. 📄 SBOM ExportGenerate a Software Bill of Materials in JSON (CycloneDX-inspired) or CSV — ready for your security audits and vendor questionnaires. 📌 Inline DiagnosticsEvery finding appears as a VSCode diagnostic — hover over the squiggle in your editor to see the issue title, severity, and OWASP category. All findings also show up in the Problems panel ( Getting Started1. Sign in to GitHubWhen you run a scan for the first time, VSCode will prompt you to sign in with GitHub — no token setup needed. 2. Scan a repository
Open a GitHub repository in VSCode and run the scan. Results appear in the dashboard panel and the Problems panel. Commands
Settings
Security Risk ScoreEvery scan produces an overall security score (0–100) displayed prominently in the dashboard:
Severity breakdown, top 5 issues, ASVS level, and compliance status are all visible at a glance. Privacy
Requirements
Feedback & IssuesFound a bug or want a feature? Open an issue at github.com/manojalwisnz/githubmate-vscode Also available as a web app at githubmate.ai |