Skip to content
vetkit
Early accessFree during beta — request an invite

Vet your code before you ship it.

Paste a GitHub repo, run an audit, get a graded report. vetkit checks for leaked secrets, vulnerable dependencies, risky code patterns and repo hygiene — whether the code was written by your team, a contractor or an AI agent.

  • Read-only access
  • Your code is never executed
  • Secret values never stored

acme/payments-api@main·9f3c2e1

SUCCEEDED
Grade B

86/100

10 findings · 0 critical

Security
87
Secrets
87
Dependencies
74
Hygiene
98
Quality
100

Top findings4 of 10

  • HIGH

    Slack webhook URL committed to source

    src/notify/slack.ts:14

  • HIGH

    lodash 4.17.20 — command injection (CVE-2021-23337)

    package-lock.json

  • MEDIUM

    SQL built from string concatenation

    src/db/orders.ts:88

  • INFO

    No SECURITY.md disclosure policy

    repository root

AI signal · beta · not scoredJSONMarkdownSARIF
Illustrative sample report. Not a real repository.

How it works

From repository URL to report in three steps

No agents to install, no pipelines to wire up. Start in the browser; automate later with the API or MCP.

  1. Connect GitHub

    Sign in with GitHub and install the vetkit GitHub App on the repositories you choose — public or private. It asks for read-only access and nothing more.

    Contents · Metadata · Pull requests — read

  2. Run an audit

    Paste a repository URL and pick a branch, tag or commit, or turn on auto-audit to re-run on every push to the default branch. vetkit makes a shallow, throwaway checkout and runs its analyzers against the files — without installing, building or executing anything.

    github.com/acme/payments-api @ main

  3. Get a graded report

    An A–F grade, a score per category, and every finding with file, line, severity and a suggested fix. Re-run later to see which findings are new and how many you fixed. Download Markdown or SARIF, or fetch JSON over the API.

    B · 86/100 · 10 findings

What we check

Four analyzers, one graded report

Each audit runs proven open-source scanners and vetkit's own checks, then normalizes everything into a single list of deduplicated findings. The report names every analyzer and tool version that ran.

gitleaks

Secrets

API keys, tokens, private keys and credentials committed to the working tree.

  • Cloud, SaaS and payment provider keys
  • Findings are redacted — secret values are never stored
  • Only a one-way hash is kept to track a finding across audits
OSV-Scanner · osv.dev

Dependencies

Known vulnerabilities in the packages your lockfiles pin, matched against the open OSV database.

  • npm, PyPI, Go, crates.io, Maven, RubyGems and more
  • CVE / GHSA identifiers and severity on every finding
  • Upgrade guidance when a fixed version exists
SAST · vetkit rule set

Static analysis

Pattern-based analysis for risky code: injection, unsafe deserialization, weak crypto and similar mistakes.

  • 64 vetkit-authored rules for JS/TS, Python, Go, Java, PHP and Ruby, growing during the beta
  • CWE references and a suggested fix per rule
  • A repository cannot disable rules with its own config files
native checks

Repo hygiene

The basics that make a codebase safe to hand over, open-source or deploy.

  • LICENSE, README, .gitignore, CI config, lockfile, SECURITY.md
  • Committed .env files, key files, node_modules or build output
  • Oversized files that do not belong in git
Beta · not scored

AI-authorship signal

A heuristic estimate of how much of a codebase was written with AI assistance, based on commit trailers and cadence, agent config files such as CLAUDE.md or AGENTS.md, and a model review of a small sample of files.

Honest caveat: AI authorship cannot be reliably detected from code. This is a signal, not evidence — a conversation starter. It is informational only and never affects your grade.

How grading works

Each category starts at 100 and loses points per finding, weighted by severity and capped per severity so a pile of minor findings cannot sink a repo. Categories are weighted into an overall score and a letter grade.

A
≥ 90
B
≥ 80
C
≥ 70
D
≥ 60
F
< 60

An unresolved critical finding caps the grade at D, and the report tells you why. Suppress false positives with a reason and an optional expiry; suppressions carry over to later audits and stay visible in the audit trail.

Security & privacy

A code auditor should be the least risky thing you connect

We built vetkit around least privilege and short retention, because you are trusting it with your source.

  • Read-only GitHub App

    vetkit can read the repositories you grant it. It cannot push, open issues, change settings or touch other repos.

  • Your code is never executed

    No install scripts, builds or tests. Analyzers only read files, symlinks are disabled at checkout, and a repo’s own scanner config is ignored.

  • Ephemeral checkouts

    Each audit uses a shallow clone in a fresh temporary directory that is deleted when the audit finishes — pass or fail.

  • Secret values are never stored

    Secret findings are redacted before they are saved. We keep the file, line and a one-way hash — never the credential itself.

  • Short-lived, unpersisted tokens

    GitHub access tokens are minted per audit, scoped to that one repository, expire within an hour and are never written to disk or database.

  • Hashed credentials

    Session tokens and API keys are stored only as hashes. An API key is shown exactly once, carries explicit scopes and can be revoked instantly.

GitHub App permissions

Exactly what the app requests. GitHub will ask you to approve any change.

Permissions requested by the vetkit GitHub App
PermissionAccess
ContentsFetch the files at the commit you auditRead
MetadataList repositories and default branchesRead
Pull requestsPull-request audits (coming soon)Read
Email addressesIdentify your account at sign-inRead

More detail on our security page and in the privacy policy.

MCP & API

Let your coding agent check its own work

The vetkit MCP server gives Claude Code — and any other MCP client — tools to connect repos, run audits and read findings. Everything in the app is also available over a documented REST API.

  • Audit acme/payments-api on main and summarize anything high or critical.
  • Which dependencies in the last audit have a fixed version available?
  • Compare this audit with the previous one — what did we fix?
Claude Code
claude mcp add vetkit -e VETKIT_API_KEY=vk_live_... -- npx -y @vetkit/mcp
REST API
# Start an audit on a connected repositorycurl -X POST https://api.vetkit.dev/v1/orgs/$ORG_ID/audits \  -H "Authorization: Bearer $VETKIT_API_KEY" \  -H "Content-Type: application/json" \  -d "{\"repositoryId\":\"$REPO_ID\",\"ref\":\"main\"}" # Download the report as SARIF for GitHub code scanningcurl "https://api.vetkit.dev/v1/orgs/$ORG_ID/audits/$AUDIT_ID/report?format=sarif" \  -H "Authorization: Bearer $VETKIT_API_KEY" -o vetkit.sarif

Pricing

Free during beta

vetkit is new and we are onboarding teams in small batches. During the beta every feature is free — in exchange, we would love your feedback on what the reports get right and wrong.

Beta

$0no credit card required

  • Public and private GitHub repositories
  • All analyzers; the AI-authorship signal (beta) is rolling out gradually
  • Graded reports with Markdown and SARIF downloads, JSON over the API
  • API keys with scopes, REST API and the MCP server
  • Team organizations with owner, admin, member and viewer roles, plus an audit log
Request access

Fair-use limits during beta

Concurrent audits
3 per organization
Audit starts
30 per hour per organization
API requests
60 per minute per key (adjustable up to 600)

When paid plans arrive we will announce them in advance, and nothing you run during the beta will be billed retroactively.

FAQ

Questions, answered plainly

Something missing? Email mehmetnamiduru@vetkit.dev.

How do I get access?
vetkit is in early access and we are onboarding teams in small batches. Email mehmetnamiduru@vetkit.dev with your name, your team and the repositories you want to audit, and we will get back to you.
Do you run my code?
No. vetkit never installs dependencies, runs build scripts or executes tests. Every analyzer reads files from a shallow checkout; nothing from your repository is ever executed.
Do you store my source code?
No. The checkout lives in a temporary directory that is deleted as soon as the audit finishes. We store the findings: rule, file path, line numbers and a short snippet (up to 1 KB) around the issue so the report is useful. Snippets for secret findings are redacted.
What happens when you find a secret?
The value is redacted before anything is saved. We keep a one-way hash so the same secret can be recognized in later audits without ever storing it. You should still rotate any credential that was committed — git history keeps it even after you delete the file.
What access does the GitHub App need?
Read-only access to contents, metadata and pull requests on the repositories you select, plus your email address at sign-in. It cannot write to your repositories. See the permissions table.
Which languages and ecosystems are supported?
Secret scanning and hygiene checks work on any repository. Dependency scanning covers the lockfile formats supported by OSV-Scanner, including npm, pnpm, Yarn, pip, Poetry, Go modules, Cargo, Maven, Gradle, Bundler and Composer. Static-analysis coverage depends on the vetkit rule set, which is growing during the beta — every report lists exactly which analyzers ran.
How reliable is the AI-authorship signal?
Treat it as a hint, not a verdict. AI authorship cannot be reliably detected from code, so the signal is labelled beta, shows its evidence and caveats, and never affects your grade. When it runs, a small sample of files is sent to an AI model provider for analysis — see the privacy policy for details.
Can I use vetkit from CI or my coding agent?
Yes. Create an API key with only the scopes you need, then use the REST API from any pipeline or install the MCP server in Claude Code or another MCP client. Reports export to SARIF 2.1.0 for GitHub code scanning.
How do I delete my data?
You can delete individual audits in the app, disconnect a repository, and uninstall the GitHub App from your GitHub settings at any time. To delete your account or an organization with all associated data, email privacy@vetkit.dev and we will take care of it within 30 days.

Get a second pair of eyes on your next release.

We are onboarding teams in small batches. Tell us about your team and the repositories you want to audit, and we will get you set up — free during beta.

Prefer to write directly? mehmetnamiduru@vetkit.dev