{"categories":[{"label":"Security","url":"https://skillfed.io/packages/category/security/2"}],"enrichment":{"capability":"Cycode is a command-line security scanner that detects secrets, infrastructure-as-code misconfigurations, software composition vulnerabilities, and static analysis issues in your repositories.","skillfed_tags":["secrets-detection","devops-security","vulnerability-scanning"],"use_cases":["Scan a Git repository before pushing to detect leaked credentials, API keys, or tokens in commit history.","Validate Terraform or CloudFormation configurations for security misconfigurations in infrastructure-as-code files.","Identify vulnerable dependencies in package manifests (requirements.txt, package.json, etc.) as part of SCA.","Integrate into pre-commit hooks to block commits containing secrets or policy violations before they reach the repository.","Generate software bill-of-materials (SBOM) reports for compliance and supply-chain security audits.","Run static analysis on source code to flag common security anti-patterns and coding issues."],"what_it_does":"Cycode is a production-grade CLI tool for scanning code repositories across four security domains: secret detection, infrastructure-as-code validation, software composition analysis (SCA), and static application security testing (SAST). It integrates into local development workflows via command-line invocation, pre-commit hooks, or CI/CD pipelines, and supports authentication through browser-based login, manual credential configuration, or environment variables.\n\nThe tool scans repositories, individual paths, commit history, and Terraform plans, then reports findings with configurable severity thresholds and remediation guidance. It allows fine-grained result filtering\u2014ignoring specific secrets by value or hash, paths, rules, or packages\u2014and can generate SBOM reports. An experimental MCP (Model Context Protocol) server mode and beta platform command extend its capabilities for integration with AI tools and centralized policy management.","worth_installing":"Yes. Cycode is actively maintained, has no known vulnerabilities, low install friction, and a permissive MIT license. It is production-stable (Development Status 5) and supports current Python versions (3.9\u20133.14). Install it if you need a unified CLI for secrets, IaC, SCA, and SAST scanning; authentication setup is required before first use."},"id":"cycode","links":{"html":"https://skillfed.io/packages/cycode","md":"https://skillfed.io/packages/cycode.md","pypi":"https://pypi.org/project/cycode/"},"maintenance":{"status":"active"},"meta":{"latest_release":"2026-08-13","license_spdx":"MIT","license_treatment":"permissive","name":"cycode","python_support":"supports_current","summary":"Boost security in your dev lifecycle via SAST, SCA, Secrets & IaC scanning."},"popularity":{"monthly_downloads":176729,"position":10235,"tier":"top_15000"},"security":{"n_vulnerabilities":0},"version":"3.19.1"}
