Project overview
thanos-snap-security applies an authorization gate before reviewing websites, frontend code, Android packages, iOS IPAs, or mobile source. Its static checks cover secrets, dependencies, configuration, authentication, permissions, deep links, WebViews, storage, and build settings, then produce remediation-focused findings with redacted evidence. It stays read-only and offline by default; active access to a live target needs explicit permission, while exploitation, brute force, persistence, denial of service, and data exfiltration are always refused.
Repository facts
- Primary language
- Python
- License
- MIT
- Repository updated
- Jul 7, 2026
- Default branch
- main
Resource types
General skill
Use cases
Security and privacyFrontend development
Platforms
Claude Code, Codex, and more
Runtime
Command lineLocal
Capabilities
Security guardrailVerification and evals
Audience
Security engineers