frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

Open in hackernews

Show HN: Free local security checks for AI coding in VSCode, Cursor and Windsurf

9•jaimefjorge•5h ago
Hi HN!

We just launched Codacy Guardrails, an IDE extension with a CLI for code analysis and MCP server that enforces security & quality rules on AI-generated code in real-time. It hooks into AI coding assistants (like VS Code Agent Mode, Cursor, Windsurf), silently scanning and fixing AI-suggested code that has vulnerabilities or violates your coding standards, while the code it’s being generated.

We built this because coding agents can be a double-edged sword. They do boost productivity, but can easily introduce insecure or non-compliant code. One recent research team at NYU found that 40% of Copilot’s outputs were buggy or exploitable [1]. Other surveys mention that people are spending more time debugging AI-generated code [2].

That's why we created “guardrails” to catch security problems early.

Codacy Guardrails uses a collection of open-source static analyzers (like Semgrep and Trivy) to scan the AI’s output against 2000+ rules. We currently support JavaScript/TypeScript, Python, and Java, focusing on things like OWASP Top 10 vulns, hardcoded secrets, dependency checks, code complexity and styling violations, and you can customize the rules to match your project’s needs. We're not using any AI models, it's “classic” static code analysis working alongside your AI assistant.

Here’s a quick demo: https://youtu.be/pB02u0ntQpM

The extension is free for all developers. (We do have paid plans for teams to apply rules centrally, but that’s not needed to use the extension and local code analysis with agents.)

Setup is pretty straightforward: Install the extension and enable Codacy’s CLI and MCP Server from the sidebar.

We’re eager to hear what the HN community thinks! Does this approach sound useful in your AI coding workflow? Have you encountered security issues from AI-generated code?

We hope Codacy Guardrails can make AI-assisted development a bit safer and more trustworthy. Thanks for reading!

Get extension: https://www.codacy.com/get-ide-extension Docs: https://docs.codacy.com/codacy-guardrails/codacy-guardrails-...

Sources [1]: NYU Research: https://www.researchgate.net/publication/388193053_Asleep_at... [2]: https://devops.com/survey-ai-tools-are-increasing-amount-of-...

Comments

tosh•4h ago
kudos @ shipping this jaime

Can you explain how/when the "guardrails" are run in Cursor? I mean: how does the extension hook in so that the code in the diff view gets changed?

Does this also work with agents like Claude Code and Amp? I guess since there is an MCP it can already work even though it's not explicitly mentioned in the docs?

What are your thoughts on running something like guardrails during dev-time vs CI time?

jaimefjorge•4h ago
thanks tosh!

The guardrails are ran every time there is code being generated by the agent. We give instructions to the coding agents to run the guardrails on the code that is changed. It doesn't YET work with Claude Code and Amp but because it leverages an MCP server, we can easily do it. It's in the plans to do.

I think dev-time is critical, because AI is producing large swaths of code as we speak. We also make sure that regardless of what happens in dev time, we can always run our cloud checks in CI time. Thanks for your questions!

rdevzw•4h ago
Just gave this a try, pretty interesting how a simple python script generated with two un-named models uses requests library version with CVE's. The scary part is, the script ran. This changes things in terms of leveraging AI. I will come back with more feedback soon, but for now, this is amazing
jaimefjorge•3h ago
Hey thanks for testing! That's been my experience well, it's very frequent to see libraries with vulnerable versions being introduced in code. What's also interesting is that, despite using incredible AI coding models like Sonnet 4, you still get CVEs in your code. Try this with Codacy Guardrails: "create a Java server using undertow".

Thanks for testing. Please do share your feedback when you test further!

SpikedCola•3m ago
On the https://www.codacy.com/get-ide-extension page, clicking the logo in the top-left corner of your webpage goes to https://www.codacy.com/home?hsLang=en which is 404. The logo link on other pages is working.

Show HN: Cozypkg: How We Simplified Local Development with Helm and Flux

https://medium.com/m/global-identity-2
1•kvaps•13s ago•0 comments

Better Images for Humans and Computers

https://ethz.ch/en/news-and-events/eth-news/news/2025/06/better-images-for-humans-and-computers.html
1•geox•1m ago•0 comments

The unexpected payoffs of basic research: From Woese to Wired

https://www.tandfonline.com/doi/full/10.4161/rna.27701
1•jdcampolargo•1m ago•0 comments

LexisNexis Partners with Harvey to Bring Its Content to the Harvey App

https://www.businessinsider.com/lexisnexis-harvey-form-strategic-alliance-amid-growing-competition-2025-6
1•gmays•3m ago•0 comments

Show HN: Interactive Literature Reviews with Visual Knowledge Maps

https://www.proread.ai/litreview
2•kanodiaashu•7m ago•0 comments

RaptorCast: Designed to enable fast and reliable communication on Monad

https://www.category.xyz/blogs/raptorcast-designing-a-messaging-layer
1•wwolffrec•7m ago•1 comments

A.I. Might Take Your Job. Here Are 22 New Ones It Could Give You

https://www.nytimes.com/2025/06/17/magazine/ai-new-jobs.html
1•samaysharma•8m ago•0 comments

Zed Debugger

https://zed.dev/debugger
8•tanelpoder•8m ago•0 comments

Show HN: I made a A.I trading journal to stop overtrading

https://www.tradelogger.dev/
1•m0onpi•9m ago•0 comments

Zed Editor – The Debugger Is Here

https://zed.dev/blog/debugger
3•diggan•10m ago•0 comments

CEO Andy Jassy shares 7 ways Amazon operates like 'the largest startup'

https://www.aboutamazon.com/news/workplace/ceo-andy-jassy-amazon-worlds-largest-startup
1•samaysharma•10m ago•0 comments

iPhone Sales Jump 15% in April-May as Apple Reclaims China Lead

https://www.macrumors.com/2025/06/17/iphone-sales-jump-apple-reclaims-china-lead/
2•mgh2•12m ago•0 comments

Record-High Foreign Ownership of the US Equity Market

https://www.apolloacademy.com/record-high-foreign-ownership-of-the-us-equity-market/
1•kamaraju•12m ago•0 comments

I built an easy way to wipe your X/Twitter posts periodically

https://github.com/sergiotapia/x-twitter-delete
1•sergiotapia•13m ago•1 comments

Show HN: Turn long form videos into short form clips

https://useclipfactory.com
1•jmcbca04•13m ago•0 comments

Show HN: Issu - CLI for Markdown issue management and time tracking

https://issu.dev
1•candiddevmike•14m ago•0 comments

Money sent home by international migrants is ~3x as much as global foreign aid

https://ourworldindata.org/data-insights/money-sent-home-by-international-migrants-is-almost-three-times-as-much-as-global-foreign-aid
2•therabbithole•14m ago•0 comments

Iowa S.C. upholds 2023 law, says police can now search trash without warrants

https://www.usatoday.com
2•miles•15m ago•0 comments

The reason people buy new iPhones (hint: it's not AI)

https://9to5mac.com/2025/06/18/the-real-reason-people-buy-new-iphones-hint-its-not-ai/
2•mgh2•15m ago•0 comments

Show HN: Built a tool to help you spot emotional patterns before they spiral

https://www.thryvejournal.com/
1•mduru99•17m ago•0 comments

Show HN: VerifyWise, an open-source governance platform for AI compliance

https://verifywise.ai/
3•gorkemcetin•17m ago•0 comments

Show HN: Brand Stori – AI audits your website like an enterprise buyer in 2min

https://brandstori.ai/
2•AnuraagTyagi•19m ago•1 comments

The Value of Chess Pieces

https://lichess.org/@/TotalNoob69/blog/the-real-value-of-chess-pieces/bpmshLXx
3•fzliu•19m ago•1 comments

Bad Apples Spoil the Barrel: Negative Members and Dysfunctional Groups

https://www.researchgate.net/publication/237683988_How_When_and_Why_Bad_Apples_Spoil_the_Barrel_Negative_Group_Members_and_Dysfunctional_Groups
2•georgecmu•22m ago•0 comments

HashChain: A family of fast factor-based sublinear exact-matching string se

https://github.com/nishihatapalmer/HashChain
2•fanf2•23m ago•0 comments

Sam Altman on AGI, GPT-5, and what’s next

https://www.youtube.com/watch?v=DB9mjd-65gw
1•TheJCDenton•26m ago•0 comments

Arcee AI releases 4.5B foundation LLM model

https://www.arcee.ai/blog/deep-dive-afm-4-5b-the-first-arcee-foundational-model
5•abhi1thakur•27m ago•0 comments

Fenic: The dataframe (re)built for LLM inference

https://github.com/typedef-ai/fenic
3•asiramdas•29m ago•0 comments

Beat Saber Is Ending Playstation VR and PS VR2 Support

https://www.uploadvr.com/beat-saber-ends-playstation-vr-support/
4•PaulHoule•32m ago•0 comments

The Tesla Brain Drain

https://www.theatlantic.com/technology/archive/2025/06/tesla-doge-elon-musk/683217/
4•JumpCrisscross•32m ago•0 comments