An open-source CLI and TypeScript SDK that uses AI to find, validate, and review security issues in code. It can scan repositories, diffs, or paths, trace attack paths, use custom threat models, and export findings in formats such as SARIF, JSON, and CSV.