Source Code Scanner
Type: source-code
Category: Source Code
Access Mode: AGENT
Produces: algorithm
The source code scanner analyzes codebases to find cryptographic API calls, hardcoded secrets, and crypto library imports. It supports local directories and remote Git repositories.
What It Discovers
Section titled “What It Discovers”- Crypto API calls — function/method invocations that use cryptographic primitives (e.g.,
Cipher.getInstance("AES/CBC/PKCS5Padding"),hashlib.sha256()) - Hardcoded keys — secrets, keys, and tokens embedded in source files
- Crypto library imports — import statements for cryptographic packages
Supported Languages
Section titled “Supported Languages”| Language | Detection Coverage |
|---|---|
| Java | JCA/JCE, BouncyCastle, Spring Security |
| Python | hashlib, cryptography, PyCryptodome, ssl |
| Go | crypto/*, x509, tls |
| JavaScript | crypto, node-forge, jose, webcrypto |
| TypeScript | Same as JavaScript |
| C# | System.Security.Cryptography, BouncyCastle |
Configuration
Section titled “Configuration”Scanning Local Directories
Section titled “Scanning Local Directories”paths: - /home/dev/projects/payment-service - /opt/apps/auth-service/srcexcludePaths: - node_modules - target - .git - vendorcryptoApiCalls: truehardcodedKeys: trueimportStatements: truedepth: standardScanning Git Repositories
Section titled “Scanning Git Repositories”repos: - url: https://github.com/yourorg/payment-service.git branch: main token: ghp_xxxxxxxxxxxx - url: https://gitlab.internal/team/auth-service.git branch: develop username: scanner token: glpat-xxxxxxxxxxxxexcludePaths: - node_modules - vendorgitBlame: truedepth: deepCombined (Local + Remote)
Section titled “Combined (Local + Remote)”paths: - /opt/apps/legacy-servicerepos: - url: https://github.com/yourorg/new-service.git branch: mainexcludePaths: - node_modules - target - build - distConfig Fields
Section titled “Config Fields”| Field | Type | Required | Default | Description |
|---|---|---|---|---|
paths | string list | No* | — | Local directories to scan |
repos | object list | No* | — | Git repositories to clone and scan |
repos[].url | string | Yes | — | HTTPS clone URL |
repos[].branch | string | No | main | Branch to clone |
repos[].username | string | No | — | Auth username |
repos[].token | string | No | — | Auth token (PAT, app password) |
excludePaths | string list | No | node_modules, target, .git, vendor, build, dist | Directory names to skip |
cryptoApiCalls | boolean | No | true | Detect crypto API function calls |
hardcodedKeys | boolean | No | true | Detect hardcoded keys and secrets |
importStatements | boolean | No | true | Detect crypto library imports |
gitBlame | boolean | No | false | Enrich findings with git blame (who introduced it, when) |
depth | string | No | standard | Scan depth: shallow, standard, or deep |
*At least one of paths or repos is required.
Scan Depth
Section titled “Scan Depth”| Depth | Behavior |
|---|---|
shallow | Fast scan — only import statements and obvious API calls |
standard | Balanced — API calls, imports, common hardcoded patterns |
deep | Thorough — includes data flow analysis, cross-file resolution, more patterns |
Source Inspector
Section titled “Source Inspector”Discovered source code findings are viewable in the Source Inspector page, which provides:
- Per-project breakdown of crypto usage
- File-level drill-down showing exact line numbers
- Language distribution across projects
- Algorithm usage patterns per repository
- Private repos — Use personal access tokens or deploy keys for authentication
- Monorepos — Point to the root;
excludePathshandles build output - CI/CD integration — Run source-code scans as part of your pipeline and import results via the CI/CD import endpoint
- Git blame — Enable for audit trails showing who introduced crypto usage and when
Related
Section titled “Related”- Binary Scanner — Scan compiled binaries for crypto
- Source Inspector — Explore findings per project
- Import/Export — CI/CD pipeline integration