Scans · Security

A security audit that ships the fix.

Keelen's Security scan is a deep security audit of your whole repo. An AI agent runs it in an isolated single use VM. It uses a read only token for one repo. That agent follows a fixed checklist of more than forty categories. The checklist covers four layers. One layer is code vulnerabilities. Another is leaked secrets, including those in git history. A third is dependencies and the supply chain. Infrastructure hardening is the fourth. The scan reports ranked findings and a coverage map. That map shows what was checked, what was partial, and what was skipped. Each skipped item comes with a reason.

Run the review from the dashboard. Or set your own agent or scheduler to call the MCP tool. Use it after a release, each day or each week. Keelen has no built in scan scheduler. Send the findings that need code changes into Keelen's development loop as Requests. Review the pull requests and checks under the project's merge settings. Some findings need a policy, legal or operational decision. Those stay with the right people.

Updated

  • The checklist is fixed. Every category ends the run as covered, partial, or skipped. A skip always comes with a reason.
  • Findings are ranked from critical down to info. Each one links to CWE and OWASP references. A fingerprint removes duplicates across runs.
  • Pick the code findings for a Request. Then review the pull request and checks. The project's merge settings control the merge.
  • The scan is read only by design. It runs in an isolated single use VM with a read only token for one repo. It cannot write anything.
  • Run it from the dashboard on demand. Or run it daily, weekly or monthly over MCP.

What it checks

The checklist adapts to your project. Apps that face the network get the full web control set. That set covers access control and sessions, XSS, CSRF and CORS. It also covers security headers, SSRF and rate limiting. Authentication is part of the set. Libraries and CLIs get public API misuse checks. They also get input checks on the public surface. Supply chain checks carry more weight for them. Game projects get client trust boundaries. They get tampering with save files too. Untrusted asset loading is also in scope. Projects that embed an LLM get a GenAI security pass. Four layers apply to everything. The first is code vulnerabilities. Next come hardcoded credentials in source and git history. Then dependencies can be vulnerable. They can be abandoned or typosquatted. Last is hardening for Dockerfiles, IaC and CI pipelines.

Coverage you can audit

Most scanners show you what they found. Keelen also shows what it looked at. The audit follows a fixed checklist, so it does not depend on what the model happened to notice. The report carries a coverage map for each category. A category is covered, partial or skipped, with a reason for each. We cannot prove zero misses. Use the stated coverage and reasons to understand this review's limits.

From finding to remediation Request

Send the findings that need code changes into Keelen's development loop. They arrive as Requests. Review the pull requests and checks. The project's merge settings govern them. Some findings need a policy, legal or operational decision. Those stay with the right people.

Run it on your cadence

Use the Run action on the project tab for a review on demand. For repeated reviews, set your own agent or scheduler to call run_security_review for this project, for example weekly, before each release, or after every incident. Keelen has no built in scan scheduler. Set up the project context and access first. Respect running reviews and limits. Read the result before you pick the next step.

Trigger it from any agent

claude mcp add --transport http keelen https://keelen.ai/mcp

Then the run_security_review MCP tool starts a run. It works from Claude Code, Cursor, a cron job, or any other tool that speaks MCP.

What it is not

This is a read only audit of the repository. It is not a penetration test. Nothing runs against a live system. The absence of a finding is not evidence of absence. Keep your existing dependency alerts. Keep your static analysis too. This audit adds to them.

Included on every paid plan

From $29 / month on Indie

FAQ

Can AI find security vulnerabilities in my code?

Yes, with honest limits. Keelen runs an AI agent over your whole repo. The agent follows a fixed checklist of more than forty security categories. It reports ranked findings. Each finding links to CWE and OWASP references. It also reports its own coverage for each category. That shows you what the review checked. No tool can prove the absence of vulnerabilities. Use the stated coverage and reasons. They show the limits of this review.

What does Keelen's Security scan check?

Every project gets four layers. The first is code vulnerability classes. Next is hardcoded secrets in source and git history. Then dependency and supply chain risk. Last is infrastructure hardening. That covers Dockerfiles, IaC and CI pipelines. Web apps also get the full web control set. It covers access control, sessions, XSS, CSRF, CORS, headers, SSRF and rate limiting. Libraries, CLIs, games and apps that embed an LLM each get their own modules.

Does the scan modify my repository?

No. The scan runs in an isolated single use VM. Its token is read only and scoped to one repository. Changes only happen if you send a finding to the loop. Then they arrive as normal pull requests. They pass the same verification gates as any other Keelen change. The gates follow how you set up the project.

How is this different from Dependabot or a SAST tool?

Those tools match patterns in one layer each. Keelen's scan is an agent. It reads your actual code the way a security engineer would. It covers code, secrets, dependencies and infrastructure in one pass. A selected finding can become a remediation Request. Any code work that follows goes through the project's review, verification and merge settings. Keep the scanners you already run. This scan adds to them.

How often should I run a security scan?

Weekly is a good default. Run one before each release and one after any incident. Reruns are cheap to read. Findings are fingerprinted, so a new run reconciles with the last. Fixed findings resolve. Dismissed ones stay dismissed. Only new findings ask for your attention. Trigger it from the dashboard. Or run it on a schedule with the run_security_review MCP tool.

Which plans include the Security scan?

Included on every paid plan, from Indie at $29/month. CMMC Level 2 controls are an Enterprise feature.

Does Keelen include a scan scheduler?

No. Start a review from the dashboard. Or set up an external agent or scheduler. Either one can call the scan's MCP tool. Daily, weekly and release driven cadences are examples. You set those up outside Keelen.

Does every finding become an automatic fix?

No. Read the evidence first. Then send the code fixes you pick to the loop. Some findings need a policy decision. Some need an operational one. Others need a legal one. Development follows the project's normal approval and merge controls.