PRSniffer

PRSniffer

PRSniffer

AI code review → scan → fix → ship.

For people reviewing GitHub pull requests and GitLab merge requests. AI code review and AppSec for GitHub and GitLab — PR walkthroughs, Change Stack triage, and repo scanning with VS Code and Cursor.

Eight scan types

  • Secrets

    Hardcoded credentials and tokens.

  • SCA

    Dependency advisories from lockfiles.

  • SAST

    Pattern rules for common code flaws.

  • IaC

    Terraform, Kubernetes, and cloud config.

  • Container

    Dockerfile and base-image checks.

  • License

    Copyleft and unknown dependency licenses.

  • Malware

    Typosquats and risky install scripts.

  • API security

    OpenAPI and schema exposure checks.

Two tiers

  • Static. The eight scanners run offline with no API key. In the extension, prsniffer.offline keeps the review on those heuristics.
  • AI, optional. Bring your own key — OPENROUTER_API_KEY, OPENAI_API_KEY, or ANTHROPIC_API_KEY — or hand a fix to an editor agent. Scanning does not require it.

Limits

Built-in rules are line and pattern matches, not dataflow or taint tracking. The heuristic SAST pack covers JavaScript/TypeScript, Python, and Go. Other languages need OpenGrep on PATH. Findings still need a person to triage them.

Sign in

Use the GitHub or GitLab account that owns your repositories.

I can't log in

Install from a VSIX

Marketplace install is not available for this build. Cursor uses the same package format. The Cursor file is built from the VS Code source with package name prsniffer-cursor. VS Code package 0.3.1. Cursor package 0.3.1.

  1. Download the VSIX for the editor you use.
  2. Open the Extensions view.
  3. Open the ... menu in that view.
  4. Choose Install from VSIX and pick the file.

Run the stack yourself · Docs · I can't log in