Skip to content

Latest commit

Β 

History

36 Commits

Folders and files

NameName
Last commit message
Last commit date
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 

Repository files navigation

πŸ›‘οΈ Sentinel AI Security CLI

Hack yourself before someone else does.

Application Security CLI combining Deterministic AST Parsing, Knowledge/Attack Graphs, Multi-File Codebase Context, Gemini 2.5 Flash AI Reasoning, and Zero-Breakage Autonomous Patching.


⚑ Why Sentinel?

Traditional security tools rely solely on superficial regex pattern matching or unguided text prompts that trigger high false-positive rates and corrupt source files when attempting fixes.

Sentinel compiles your codebase into Sentinel IR, builds a Knowledge Graph, synthesizes multi-hop Attack Graphs, extracts deep multi-file codebase context (interfaces, exports, dependencies), performs CISO-grade reasoning powered by Gemini 2.5 Flash, and applies autonomous fixes backed by zero-breakage verification and snapshot rollback.

Polyglot Source Code ──► Sentinel IR ──► Security Knowledge Graph ──► Attack Graph ──► Deep Multi-File Context ──► Gemini 2.5 Flash Reasoning ──► Autonomous Patching & Zero-Breakage Verification

πŸš€ Quick Start & Installation

Option 1: Global npm Installation

npm install -g sentinel-ai-cli

Option 2: Run directly via npx

npx sentinel-ai-cli attack .

Option 3: Local Clone & Development

git clone https://github.com/Drix10/sentinal.git
cd sentinal
npm install
npm run build
npm run start -- attack .

πŸ”‘ Configuration & API Key Setup

Sentinel uses Gemini 3.5 Flash for deep security analysis. Get a free API key from Google AI Studio.

Configure your API key:

sentinel set-key

Sentinel validates the key and securely saves it locally to ~/.sentinel/config.json.


πŸ’» CLI Commands & Workflow

1. Execute Security Scan & Attack Graph Synthesis (sentinel attack)

Analyze current directory:

sentinel attack .

Export GitHub-compatible SARIF 2.1.0 report for GitHub Code Scanning / Security Tab:

sentinel attack . --format sarif --output sentinel-report.sarif

Export JSON format report:

sentinel attack . --format json --output sentinel-report.json

2. System Diagnostic Check (sentinel doctor)

Run environment, Node.js version, TSConfig, and Gemini API key diagnostics:

sentinel doctor

3. Deep Finding Explanation (sentinel explain)

View forensic root-cause analysis, exploit mechanics, CIA triad impact, OWASP details, and step-by-step developer remediation:

sentinel explain FINDING-100

4. Autonomous AI Patching & Verification (sentinel fix)

Synthesize a drop-in secure code patch with deep codebase awareness and run automated zero-breakage verification (AST diagnostics, tsc compilation, test runner execution, and detector re-scans) before finalizing the fix:

sentinel fix FINDING-100

Preview Diff Without Modifying Disk (--dry-run):

sentinel fix FINDING-100 --dry-run

Skip Compiler/Test Verification (--no-verify):

sentinel fix FINDING-100 --no-verify

πŸ›‘οΈ Zero-Breakage Guarantee: If a patch introduces compilation or test regressions, Sentinel automatically invokes AI self-correction retry, and restores the pre-patch snapshot from .sentinel/backups/ if verification fails.

5. Ignore Finding (sentinel ignore)

Mark a finding as ignored with an optional developer justification reason:

sentinel ignore FINDING-100 --reason "Mitigated by upstream Cloudflare WAF rule"

πŸ“Š Example Terminal Output

 ╔══════════════════════════════════════════════════════════════════════╗
 β•‘      S E N T I N E L   A I   S E C U R I T Y   P L A T F O R M       β•‘
 β•‘      Deterministic Program Analysis β€’ Attack Graph β€’ AI Reasoning    β•‘
 β•šβ•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•

 Target: /path/to/target-repo

βœ” Project Detected & Topology Analyzed

β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚ PROPERTY               β”‚ VALUE / METADATA                                  β”‚
β”œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”Όβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€
β”‚ Project Name           β”‚ my-app-backend                                    β”‚
β”‚ Framework              β”‚ Express                                           β”‚
β”‚ Language               β”‚ TypeScript                                        β”‚
β”‚ Package Manager        β”‚ npm                                               β”‚
β”‚ Source Directory       β”‚ src                                               β”‚
β”‚ Docker Configured      β”‚ No                                                β”‚
β”‚ Env Configured         β”‚ Yes                                               β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”΄β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜

β”Œβ”€β”€ [+] SENTINEL IR COMPILER METRICS (@sentinel/plugin-typescript) ──────────┐
β”‚ IR Project Compilation: Successful                                         β”‚
β”‚ AST Source Files Parsed: 32                                                β”‚
β”‚ Extracted API Routes: 32                                                   β”‚
β”‚ AST Node Processing: TypeScript Morph Plugin Active                        β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜

βœ” Discovered 44 HTTP API routes
β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚ METHOD β”‚ ROUTE PATH                           β”‚ SOURCE FILE                β”‚
β”œβ”€β”€β”€β”€β”€β”€β”€β”€β”Όβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”Όβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€
β”‚ GET    β”‚ /health                              β”‚ src/index.ts               β”‚
β”‚ POST   β”‚ /analyze                             β”‚ src/routes/ai-mrv.routes.tsβ”‚
β”‚ POST   β”‚ /login                               β”‚ src/routes/auth.routes.ts  β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”΄β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”΄β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜

βœ” Found 43 package dependencies
β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚ PACKAGE NAME                         β”‚ VERSION          β”‚ SCOPE            β”‚
β”œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”Όβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”Όβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€
β”‚ @google/generative-ai                β”‚ 0.21.0           β”‚ dependency       β”‚
β”‚ express                              β”‚ 4.18.2           β”‚ dependency       β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”΄β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”΄β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜

βœ” Found 0 secret patterns
β”Œβ”€β”€ [+] KNOWLEDGE GRAPH & ATTACK GRAPH ENGINE MATRIX ────────────────────────┐
β”‚ Knowledge Graph Nodes: 112 (Routes, Secrets, Dependencies)                 β”‚
β”‚ Topology Edges: 2992 (USES_DEPENDENCY, READS_SECRET)                       β”‚
β”‚ Synthesized Exploit Paths: 0 Attack Graph Vectors                          β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜

βœ” Security Report Synthesized Successfully!

 β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
 β”‚  SECURITY RISK SCORE: 95/100   [β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘]          β”‚
 β”‚  STATUS: GOOD SECURITY POSTURE                                           β”‚
 β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜

β”Œβ”€β”€ [+] EXECUTIVE SUMMARY ───────────────────────────────────────────────────┐
β”‚ The security assessment of the target project reveals a robust baseline    β”‚
β”‚ posture. Sentinel's engines detected zero active multi-hop attack graph    β”‚
β”‚ exploit vectors and no exposed hardcoded secrets.                          β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜

β”Œβ”€β”€ [+] ATTACK SURFACE DISCOVERED ───────────────────────────────────────────┐
β”‚ 1. 44 HTTP API endpoints                                                   β”‚
β”‚ 2. 43 runtime dependencies                                                 β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜

 [+] FINDING LIFECYCLE STORE SUMMARY
β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚ ID            β”‚ SEVERITY   β”‚ VULNERABILITY TITLE     β”‚ LOCATION   β”‚ CONF.  β”‚
β”œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”Όβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”Όβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”Όβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”Όβ”€β”€β”€β”€β”€β”€β”€β”€β”€
β”‚ FINDING-100   β”‚ LOW        β”‚ Outdated AWS SDK Maj... β”‚ Depende... β”‚ 90%    β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”΄β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”΄β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”΄β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”΄β”€β”€β”€β”€β”€β”€β”€β”€β”˜

β”Œβ”€β”€ [+] NEXT STEPS & ACTION PLAN ────────────────────────────────────────────┐
β”‚ DEVELOPER REMEDIATION WORKFLOW & NEXT STEPS:                               β”‚
β”‚                                                                            β”‚
β”‚  1. Examine OWASP Details & Source Evidence:                               β”‚
β”‚     sentinel explain FINDING-100                                           β”‚
β”‚                                                                            β”‚
β”‚  2. Synthesize Autonomous AI Security Patch:                               β”‚
β”‚     sentinel fix FINDING-100                                               β”‚
β”‚                                                                            β”‚
β”‚  3. Triage False Positives or Accept Risk:                                 β”‚
β”‚     sentinel ignore FINDING-100 --reason "Reviewed by AppSec team"         β”‚
β”‚                                                                            β”‚
β”‚  4. Re-verify Code Base After Remediation:                                 β”‚
β”‚     sentinel attack .                                                      β”‚
β”‚                                                                            β”‚
β”‚  Findings persisted to: .sentinel/findings.json                            β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜

πŸ› οΈ Technology Stack

  • Core Runtime: TypeScript 5.x, Node.js (ES2022)
  • AST Compiler & IR: ts-morph, fast-glob
  • AI Reasoning Engine: @google/generative-ai (gemini-3.5-flash with gemini-3.0-flash fallback)
  • CLI Framework & UI: commander, chalk, ora

πŸ“„ License

MIT License


Made with ❀️ to help developers hack themselves first.

About

CLI tool for scanning repositories and reporting vulnerabilities

Topics

Resources

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages