An offline AI-powered vulnerability scanner that uses a local GGUF model (such as LLaMA 2) to detect and explain security vulnerabilities in source code.
This tool runs completely offline — no API keys, no internet required — making it perfect for hackathons, security workshops, and privacy-conscious development.
- Scans source code in a given directory (default:
src/) - Uses a local GGUF-based LLM to:
- Detect potential vulnerabilities
- Explain each vulnerability clearly
- Suggest a fix for each
- Works entirely offline — your code never leaves your machine
- Supports replacing LLaMA with any compatible GGUF model (Mixtral, Qwen, Phi, DeepSeek, etc.)
Due to its size, the model file is NOT stored in this repository.
You must download your own GGUF-format model and configure the tool to use it.
Recommended: [llama-2-7b.Q5_K_M.gguf] (https://huggingface.co/TheBloke/Llama-2-7B-GGUF) for best accuracy.
📦 Install Dependencies
pip install -r requirements.txt1️⃣ Make a models/ folder in the project root and place your .gguf model inside.
Example:
vuln-detector/
├── models/
│ └── llama-2-13b.Q5_K_M.gguf
2️⃣ Open config/settings.yaml
Change:
llama_model_path: "models/llama-2-13b.Q5_K_M.gguf"to the exact path of your model.
3️⃣ Open llm_analysis/llm_client.py Change:
MODEL_PATH = os.getenv("LLAMA_MODEL_PATH", "models/llama-2-13b.Q5_K_M.gguf")
to your model path.
4️⃣ (Optional) Set via environment variable instead:
set LLAMA_MODEL_PATH=models/YOUR_MODEL_FILE.gguf # Windows
export LLAMA_MODEL_PATH=models/YOUR_MODEL_FILE.gguf # Mac/Linux
python main.py 📝 Example Input (src/example.py):
def delete_file(filename):
os.system("rm " + filename)
delete_file("important_data.txt")
Output:
[INFO] Analysis for src/example.py:
- Vulnerability: Command Injection
- Explanation: Unvalidated user input passed to os.system allows arbitrary commands.
- Fix: Use subprocess.run([...], shell=False) with validated input.