A web application that analyzes Python code for security vulnerabilities. It combines Semgrep (static analysis) and OpenAI Agents (AI-powered review) to produce a report with CVSS scores and remediation suggestions.
- Upload or paste Python code
- Semgrep scan via MCP server
- Complementary analysis by an OpenAI agent
- Structured report: summary, severity, vulnerable snippet, suggested fix
| Layer | Technology |
|---|---|
| Frontend | Next.js 15, React, TypeScript, Tailwind CSS |
| Backend | FastAPI, Python 3.12, OpenAI Agents SDK |
| Analysis | Semgrep MCP, uv |
| Deployment | Docker, Terraform |
| Cloud | Azure Container Apps, Google Cloud Run |
├── backend/ # FastAPI API + security agent
├── frontend/ # Next.js UI (static export in production)
├── terraform/
│ ├── azure/ # Azure Container Apps deployment
│ └── gcp/ # Google Cloud Run deployment
├── Dockerfile # Single image (frontend + backend)
└── .env # API keys (not committed)
- Python 3.12 + uv
- Node.js 20+
- Docker (optional, for containerized deployment)
- OpenAI and Semgrep accounts
- Clone the repo and create a
.envfile at the project root:
OPENAI_API_KEY=sk-...
SEMGREP_APP_TOKEN=...- Start the backend:
cd backend
uv run server.py- In a second terminal, start the frontend:
cd frontend
npm install
npm run devdocker build -t securecode-ai .
docker run --rm -p 8000:8000 --env-file .env securecode-aiThe app is available at http://localhost:8000 (API + frontend served by FastAPI).
Infrastructure is managed with Terraform:
- Azure:
terraform/azure/— Container Apps + Azure Container Registry - GCP:
terraform/gcp/— Cloud Run + Artifact Registry
Both environments require openai_api_key and semgrep_app_token when running terraform apply.
The container needs at least 2 GB RAM in the cloud: Semgrep loads a large rule registry on startup.
Robin Chriqui — portfolio project showcasing full-stack AI, DevSecOps, and multi-cloud deployment.
MIT — see LICENSE.
