GitHub - danoszz/penthera: Lightweight website/app security scanner for vibecoded apps:: run it from your AI agent (Cursor/Claude Code) or the CLI. Black-box + white-box, OWASP-mapped, SARIF-ready. Au

00:01:13 ・ source: https://github.com/danoszz/penthera

Transcript

hostenPenthera is a lightweight security scanner you run from your AI agent or the CLI.
guestjaPenthera は、AI エージェント(Cursor や Claude Code)またはコマンドラインから実行できる軽量なセキュリティスキャナーです。
hostenIt finds exposed API routes, weak auth, hardcoded secrets, and missing headers before you ship.
guestja公開されている API ルート、脆弱な認証、ハードコードされたシークレット、セキュリティヘッダーの欠落を本番リリース前に検出します。
hostenJust tell your agent: scan my app for security issues, and it runs black-box and white-box tests automatically.
guestjaエージェントに「セキュリティ問題をスキャンして」と言うだけで、ブラックボックスとホワイトボックスの両方のテストが自動実行されます。
hostenResults map to OWASP standards and output as SARIF for GitHub code scanning.
guestja結果は OWASP 標準にマッピングされ、GitHub コードスキャン用に SARIF 形式で出力できます。
hostenIt also auto-fixes found issues and re-scans to confirm they are resolved.
guestja見つかった問題を自動修正し、改善されたことを再スキャンで確認することもできます。
hostenImportant: use it only on systems you own or have explicit written permission to test.
guestja重要なのは、自分が所有する、または明確な許可を得たシステムに対してのみ使用することです。