Automated pull-request cybersecurity review. Scans diffs with a deterministic CWE rule engine (instant, offline), and can optionally request a KIN model brief from the live nyxspecter4/kin-cybersec Space. Every report states exactly which engine produced it.
- On pull_request, fetches the diff and scans changed lines for CWE patterns: SQL injection, command injection, XSS, path traversal, SSRF, hardcoded secrets, JWT confusion.
- Optionally requests a live KIN model brief (set
KIN_MODEL_BRIEF: 'true'). - Posts a PR comment with findings, line numbers, remediations — and an explicit engine label.
- Optionally fails CI when findings are present.
Honesty by design: the rule scan is regex-level, offline, and labeled as such. The model brief (when requested) is labeled as model output. No fabricated "verified by model" claims.
Add .github/workflows/security-scan.yml to your repository:
name: KIN Security Review
on:
pull_request:
types: [opened, synchronize, reopened]
permissions:
pull-requests: write
contents: read
jobs:
review:
runs-on: ubuntu-latest
steps:
- name: Checkout repository
uses: actions/checkout@v4
- name: Run KIN Security Action
uses: NyxSpecter4/kin-security-action@v1
with:
github-token: ${{ secrets.GITHUB_TOKEN }}
fail-on-vulnerability: 'false'
env:
KIN_MODEL_BRIEF: 'true' # optional: also request a live model brief| Input | Required | Default | Description |
|---|---|---|---|
github-token |
Yes | ${{ github.token }} |
GitHub Token used to fetch PR diffs and post comments. |
severity-threshold |
No | 'High' |
Minimum severity level to report (Critical, High, Medium). |
fail-on-vulnerability |
No | 'false' |
If 'true', terminates the workflow with exit code 1 when flaws are detected. |
Environment variables:
KIN_MODEL_BRIEF—'true'to request a live model brief (default'false').KIN_SPACE_URL— override the Space base URL.KIN_MODEL_TIMEOUT_MS— model timeout (default75000).
Built at BountyWarz — the cyber-education platform behind this tool. More from the same studio: kin-security-action · kin-security-plugin · monk-plugin · Kinetigor Desk.
MIT © NyxSpecter4