PRSniffer

AI code review → scan → fix → ship.
For people reviewing GitHub pull requests and GitLab merge requests. AI code review and AppSec for GitHub and GitLab — PR walkthroughs, Change Stack triage, and repo scanning with VS Code and Cursor.
Eight scan types
Secrets
Hardcoded credentials and tokens.
SCA
Dependency advisories from lockfiles.
SAST
Pattern rules for common code flaws.
IaC
Terraform, Kubernetes, and cloud config.
Container
Dockerfile and base-image checks.
License
Copyleft and unknown dependency licenses.
Malware
Typosquats and risky install scripts.
API security
OpenAPI and schema exposure checks.
Two tiers
- Static. The eight scanners run offline with no API key. In the extension,
prsniffer.offlinekeeps the review on those heuristics. - AI, optional. Bring your own key —
OPENROUTER_API_KEY,OPENAI_API_KEY, orANTHROPIC_API_KEY— or hand a fix to an editor agent. Scanning does not require it.
Limits
Built-in rules are line and pattern matches, not dataflow or taint tracking. The heuristic SAST pack covers JavaScript/TypeScript, Python, and Go. Other languages need OpenGrep on PATH. Findings still need a person to triage them.
Sign in
Use the GitHub or GitLab account that owns your repositories.
Install from a VSIX
Marketplace install is not available for this build. Cursor uses the same package format. The Cursor file is built from the VS Code source with package name prsniffer-cursor. VS Code package 0.3.1. Cursor package 0.3.1.
- Download the VSIX for the editor you use.
- Open the Extensions view.
- Open the ... menu in that view.
- Choose Install from VSIX and pick the file.