CodeTrust scans every PR for security flaws, hallucinated dependencies, and quality issues in AI-generated code. 2 lines of YAML. Works with Copilot, Cursor, Claude, and every AI coding tool.
Every scan checks 6 dimensions of trust. Zero false positive mode included.
SQL injection, command injection, path traversal, hardcoded secrets, insecure random, eval/exec usage, prototype pollution. OWASP Top 10 covered.
400+ phantom API patterns. Catches when AI invents non-existent methods, cross-language confusion (.trim() in Python), fictional HTTP codes, phantom decorators.
Detects hallucinated packages (AI commonly invents "utils", "helpers"), deprecated APIs, and unnecessary dependencies with stdlib alternatives.
Off-by-one errors, missing null checks, type mismatches, unreachable code, inconsistent returns, error handling gaps. Multi-language support.
PEP 8 violations, naming convention mismatches, wildcard imports, mixed require/import, mixed tabs/spaces. Keeps AI code consistent with your style.
Functions without tests, missing error path testing, API endpoints without integration tests. Ensures AI-generated code is actually tested.
CLI, API, GitHub Action, or MCP server. Your choice.
Paste AI-generated code below and see the trust score instantly.
50% cheaper than Snyk. Pay per developer, not per repo.
For open source & personal projects
For teams shipping AI-assisted code
For regulated industries & large teams
45% of AI-generated code contains vulnerabilities. CodeTrust catches them before they reach production.
pip install codetrust