Blacklock SAST Security Scan
Perform a security scan on your source code as you write. Find hardcoded
secrets, vulnerable dependencies, risky code patterns, and misconfigured
infrastructure -- all without leaving your editor.
Works with: VS Code | Claude Code | OpenAI Codex CLI
What It Does
Blacklock CodeScan combines five purpose-built scanners into one workflow:
- Source Code Scanner — SQL injection, XSS, hardcoded secrets, and other risky code patterns
- Secrets Scanner — hardcoded API keys, tokens, and credentials; the matched value is never shown unmasked in the UI
- Dependency Scanner — known CVEs in your project's dependencies, with fixed-version suggestions
- IaC Scanner — misconfigurations in Dockerfiles, Kubernetes manifests, and Terraform
- Code Quality Scanner — broader code-quality and security linting
Run them together with Scan All, or scope to just Source Code or
Dependencies from their own tabs. Findings from every scanner land in one
combined list on the All tab — sorted by severity, with the source
engine tagged on each row so you can tell which tool found what, and
duplicate findings (the same secret or issue found by more than one tool)
merged into one entry, keeping the highest reported severity.
Additional behavior worth knowing:
- Scan the whole workspace, just the current file, or only what's changed (diff lines / diff files)
- Respects
.gitignore for workspace scans, and always skips build artifacts (node_modules, __pycache__, compiled binaries, .env files) regardless of gitignore state
- Jump straight from a finding to the exact line in your editor
- Suppress findings you've triaged, per-project
- Scanning tools (opengrep, trivy, gitleaks, checkov, qlty) install automatically on first use — no manual setup
Quick Start
If you're setting up the Claude Code or Codex CLI plugin, download the matching blacklock-shield binary for your platform from Releases. The VS Code extension installs its own scanning tools automatically — see below.
VS Code Extension
Security scanning across 5 engines, with a dedicated findings panel and
inline jump-to-line.
Install
Build the extension:
git clone https://github.com/blacklock-security/block-ide-plugins.git
cd block-ide-plugins
npm install && npm run compile && npx vsce package
In VS Code: Ctrl+Shift+X > ... menu > Install from VSIX > select the .vsix file.
How to Use
Open the Blacklock CodeScan sidebar (Activity Bar icon), pick a scope
(Workspace / Current File / Diff Lines / Diff Files), and click Scan.
Findings appear grouped by tab — All (everything, merged and
sorted by severity), Source Code, or Dependencies — or run any
scan directly from the Command Palette (Ctrl+Shift+P):
CodeScan: Scan All
CodeScan: Scan Source Code
CodeScan: Scan Dependencies
CodeScan: Scan Secrets
CodeScan: Scan Infrastructure
CodeScan: Scan Quality
Click any finding to jump to its exact location; enable On Save in the
sidebar to scan the current file automatically on every save.
Settings
Search "Blacklock" in VS Code Settings (Ctrl+,):
| Setting |
Default |
What it does |
sourceScanner.rules |
"auto" |
Opengrep rules config path, or "auto" for defaults |
sourceScanner.exclude |
[] |
Extra directories to exclude from source scans |
dependencyScanner.scanners |
["vuln", "secret"] |
Trivy scanner types to run |
dependencyScanner.severity |
["CRITICAL", "HIGH", "MEDIUM"] |
Severity levels to report for dependency vulnerabilities |
scanner.executionMode |
"parallel" |
Run the 5 scanners concurrently, or one at a time |
scanner.persistRawOutput |
false |
Write each tool's raw JSON to .blacklock/scan-results/ for debugging |
scanOnSave |
false |
Automatically scan the current file on save |
Claude Code Plugin
A plugin that gives Claude 7 security scanning commands, plus a post-edit hook that automatically scans every file Claude touches.
Install
mkdir -p ~/.claude/plugins/blacklock-shield
cp -r claude-code-plugin/{hooks,commands,mcp.json,shield.config.json} ~/.claude/plugins/blacklock-shield/
Restart Claude Code.
Commands
/shield:audit Full audit (source + deps + infra)
/shield:source Source code scan only
/shield:deps Dependency CVE scan
/shield:infra Infrastructure config scan (Docker, K8s, Terraform)
/shield:triage Filter findings by severity/category/engine
/shield:details <file> Scan a specific file (or show cached results)
/shield:autoscan on|off Toggle auto-scan after every edit
Triage Options
/shield:triage severity=CRITICAL
/shield:triage severity=HIGH,CRITICAL category=injection
/shield:triage engine=SOURCE
Example Prompts
/shield:audit
"Fix all critical and high findings, then re-run the audit"
/shield:deps
"Upgrade all vulnerable packages to their fixed versions"
/shield:details src/auth/login.py
"Is the SQL query on line 42 actually vulnerable?"
/shield:infra
"Fix the Dockerfile issues and add a non-root USER"
/shield:autoscan on
"Now write me a new API endpoint for user registration"
(Claude auto-scans after every edit)
"Run a security audit and fix anything critical"
(Claude runs the audit, then makes fixes)
Codex CLI Plugin
An MCP skill that registers security scanning tools Codex can call on its own. Supports text, json, and sarif output formats.
Install
cd block-ide-plugins/codex-plugin
bash setup.sh
This copies the skill to ~/.codex/skills/blacklock-shield/, registers the MCP server in ~/.codex/config.toml, and installs scanning tools if missing. Restart Codex CLI.
Commands
$blacklock-shield audit Full audit (source + deps + infra)
$blacklock-shield source Source code scan only
$blacklock-shield deps Dependency CVE scan
$blacklock-shield infra Infrastructure config scan
$blacklock-shield triage Filter findings by severity/category/engine
$blacklock-shield details [file] Scan a specific file (or show cached results)
$blacklock-shield autoscan on|off Toggle auto-scan after every edit
Triage Options
$blacklock-shield triage severity=CRITICAL engine=SOURCE
$blacklock-shield triage category=injection
Example Prompts
$blacklock-shield audit
"Fix all critical findings and re-run the audit"
$blacklock-shield deps
"Upgrade every vulnerable package to the fixed version"
$blacklock-shield details src/api/handler.go
"Is this actually exploitable?"
$blacklock-shield autoscan on
"Refactor the auth module"
(Codex auto-scans after every edit)
"Check this project for security issues and fix anything critical"
(Codex picks the right tools automatically)
Building from Source
cd blacklock-shield
cargo build --release
# Binary: target/release/blacklock-shield
License
MIT -- see LICENSE.
Support