princekushwah2611

CodeWarden — Security skill for Claude Code

Security community

CodeWarden is an autonomous code review agent that watches every pull request on GitHub.

How to install CodeWarden

This entry records only its repository, not the path inside it, so there is no exact command to give. Open princekushwah2611/CodeWarden and copy the folder into ~/.claude/skills/, or the file into ~/.claude/agents/.

What CodeWarden does

CodeWarden is an autonomous code review agent that watches every pull request on GitHub. It pairs deterministic static analysis (Semgrep with OWASP Top 10 rulesets) with Claude's reasoning to find real vulnerabilities, rank them by severity, and explain both the risk and the fix. A RAG pipeline on ChromaDB indexes your team's own engineering guidel

Alternatives in Security

  • Token Scan — Meme coin and token security scan — checks for rug pull vectors (hidden mint, honeypot, fee manipulation, LP l 3.8k ★
  • Node9 Proxy — The Execution Security Layer for the Agentic Era 209 ★
  • Vibeship Scanner — a free vulnerability and security scanner for vibe coders, with 2000+ rulesets, and copy pasteable Master AI F 120 ★

README

🛡️ CodeWarden

**An agentic AI reviewer that watches every pull request for security risk and standards drift.**

CodeWarden is an autonomous code review agent that integrates directly with GitHub to review pull requests in real time. It performs multi-layered static security scans (Semgrep + OWASP Top 10), pairs findings with an LLM reasoning engine (Claude), and enforces team-specific coding standards using a Retrieval-Augmented Generation (RAG) pipeline powered by ChromaDB.


🌟 Key Capabilities

  1. **Security Scanner Agent**

    • Combines deterministic AST/SAST scanning (Semgrep OWASP Top 10 rulesets) with LLM deep reasoning.
    • Categorizes issues with precise severity (critical, high, medium, low) and explains why the vulnerability is risky and how to remediate it.
    • In-code suppression support via // codewarden-ignore comments.
  2. **RAG Standards Agent**

    • Ingests and vectorizes your team's internal engineering guidelines, conventions, and style guides.
    • Dynamically retrieves standard chunks matching changed files in PR diffs.
    • Enforces team conventions without generic or noisy lint warnings.
  3. **Intelligent Aggregation Layer**

    • Merges findings from both agents, eliminates duplicates, and ranks them by severity.
    • Posts line-specific GitHub comments and a formatted review summary with clear emojis and action recommendations (approve, comment, or request-changes).
  4. **Interactive Developer Dashboard**

    • Dark-mode-first developer UI built with React 19, Tailwind CSS v4, and Recharts.
    • Overview metrics: Total PRs, Critical issues caught, Average response time, and Team health score.
    • Detailed repository settings, standards document management, and review inspection with syntax-highlighted diffs and inline finding markers.

🏗️ Architecture

                       ┌────────────────────┐
                       │   GitHub Repo       │
                       │  (PR opened/synced) │