Rafter thumbnail

Rafter

Scan GitHub repositories for security vulnerabilities, secrets, and code issues with AI-powered SAST and actionable fix suggestions. Rafter connects to your GitHub with one click, delivers severity-tagged findings with plain-English remediation steps, and integrates with Claude Code, Cursor, and other AI coding agents.

0.0 (0 reviews)

Categories

Overview

Rafter is an AI-powered code security platform designed for developers, startups, and engineering teams who ship code on GitHub and need to catch vulnerabilities before they reach production. Founded in October 2025 and based in San Francisco, Rafter provides one-click security scanning for GitHub repositories, combining AI-driven static analysis with actionable, plain-English fix suggestions that integrate directly with AI coding assistants.

How It Works

Rafter connects to a GitHub repository with read-only permissions and runs a full security scan from its web dashboard without requiring terminal setup or configuration expertise. The scanning engine detects hardcoded secrets such as API keys, tokens, and database credentials, common web vulnerabilities including SQL injection and cross-site scripting, insecure authentication patterns, and risky dependency configurations. Each finding is tagged by severity and includes the exact file location and vulnerable line number, allowing developers to pinpoint issues instantly. Beyond static code analysis, Rafter also offers live website security flight checks that assess performance, accessibility, best practices, and SEO.

AI-Ready Fixes and Agent Integration

Rafter is built from the ground up to work alongside AI coding agents. Each vulnerability finding includes a structured remediation description in plain English, formatted as a copy-ready prompt that developers can paste directly into Claude Code, ChatGPT, Cursor, Windsurf, or any supported AI coding assistant. The tool supports nine major agent platforms including Claude Code, Codex CLI, OpenClaw, Gemini CLI, Cursor, Windsurf, Continue.dev, Aider, and Hermes. Integration methods vary by platform, with skill-based agents receiving the full Rafter skill set while MCP-based agents connect through the Rafter MCP server. The Rafter CLI is available via npm and pip, released under the MIT license.

Local Security Toolkit

Rafter ships a free, open-source CLI that works entirely offline with no account, no API key, no telemetry, and no data ever leaving the machine. Features include fast secret scanning with over 21 built-in patterns covering AWS, GitHub, Google, Slack, Stripe, Twilio, database connection strings, JWTs, private keys, and more. Pre-commit hooks block secrets before they enter version control. A command policy enforcement layer routes shell commands through a risk-assessment system with tiered approval levels. A tamper-evident audit log with SHA-256 hash chaining records every security-relevant event. Custom pattern rules can be added through a project configuration file.

CI/CD and Remote Analysis

Rafter integrates into CI/CD pipelines via GitHub Actions, GitLab CI, and CircleCI. A reusable GitHub Action provides deterministic output with stable exit codes, making it suitable for automated security gates. For deeper audits, Rafter's remote API performs agentic analysis combining a full SAST and SCA toolchain with reasoning about authentication, authorization, and business logic vulnerabilities. The engine traces data flows across files and cross-references findings with industry-standard static analysis and dependency scanning tools. Results are available as structured JSON or Markdown reports pipeable to any automation workflow.

Pricing and Privacy

Rafter is free forever for individual developers and open-source projects. The local CLI toolkit requires no account and has no usage limits. Paid plans are available through AppSumo lifetime deals starting at $39. Privacy is a core principle: no code leaves the machine during local scanning, and remote analysis deletes code immediately after processing completes. The CLI collects no telemetry and functions without network access. An affiliate program is available for partners.

Tool Overview

Pricing

PaidFree Trial
Added:...
Updated:...

Similar AI Tools

ChatGPT Code Interpreter thumbnail

ChatGPT Code Interpreter

OpenAI sandboxed Python environment within ChatGPT that executes code, analyzes data, creates visualizations, and processes files through natural language conversations.

ParseHub Web Scraper thumbnail

ParseHub Web Scraper

ParseHub is a powerful visual web scraping tool that extracts data from any website without writing code. It handles JavaScript, AJAX, pagination, and login forms, making it suitable for data analysts, marketers, researchers, and developers who need structured web data for lead generation, price monitoring, market intelligence, and data science workflows.

9Router thumbnail

9Router

A free, open-source local proxy that routes AI coding tools across 40+ model providers with smart quota-aware fallback.

Stable Diffusion WebUI (AUTOMATIC1111) thumbnail

Stable Diffusion WebUI (AUTOMATIC1111)

Open-source browser interface for Stable Diffusion AI image generation with txt2img, img2img, inpainting, LoRA, and extensible plugin architecture.

Mockitt thumbnail

Mockitt

Mockitt is an AI-native all-in-one product design and prototyping platform by Wondershare that unifies prototyping, UI design, whiteboarding, diagramming, and AI slide generation in a single workspace.