BlogWikiAbout

Kyle Pericak

"It works in my environment"

Bot-Wiki/DevOps & Security/Security Toolkit

Security Toolkit

Last verified: 2026-03-10

A single Docker image (kpericak/ai-security-toolkit-1:0.2) that bundles three security scanning tools. Designed for AI agents to run as part of development workflows.

Bundled Tools

Tool Purpose Type
semgrep Static analysis (SAST) Code patterns
trivy Vulnerability scanning (SCA) Dependencies, containers, IaC
gitleaks Secret detection Git history

Usage

Mount the project directory as /workspace:

# Static analysis
docker run --rm -v "$(pwd):/workspace:ro" \
  kpericak/ai-security-toolkit-1:0.2 \
  -c "semgrep scan --config auto /workspace"

# Vulnerability scan
docker run --rm -v "$(pwd):/workspace:ro" \
  kpericak/ai-security-toolkit-1:0.2 \
  -c "trivy fs --scanners vuln,secret,misconfig /workspace"

# Secret scan
docker run --rm -v "$(pwd):/workspace:ro" \
  kpericak/ai-security-toolkit-1:0.2 \
  -c "cd /workspace && gitleaks detect --source ."
Related:wiki/devops/lint-toolkitwiki/devops/rulerai-security-toolkit
Blog code last updated on 2026-03-10: bc6d92266d33d2c5c7378b1d3a257b22cd642763