Install on GitHub
One click. Sebastion AI gets scoped, short-lived read access to the repos you choose. No PATs, no SSH keys, no seat invitations.
Sebastion AI scans your pull requests for real vulnerabilities, injection, hardcoded secrets, broken auth, supply-chain risks, insecure crypto and files findings as a structured GitHub issue with concrete fixes. Free for public repos.
Cloning repository…
src/agents/router.ts:42The string sk-ant-api03-… is committed in plaintext. Anyone with read access to the repo can drain your account. Rotate immediately and load from process.env.ANTHROPIC_API_KEY.
userId in api/threads/route.ts:87userId flows from the request body straight into a raw db.query() template. Use a parameterised query or the existing db.threads.findMany({ where: { userId } }) helper.
One click. Sebastion AI gets scoped, short-lived read access to the repos you choose. No PATs, no SSH keys, no seat invitations.
Sebastion clones each PR into an ephemeral microVM and traces user input across the diff, looking for real, exploitable security bugs, not style nits.
Each audit posts a single, structured issue on the PR with severity, file/line, a concrete fix, and, where relevant, a working proof-of-concept.
Free for public repos. $19 / dev / mo for private. $39 / dev / mo for teams. Pro and Team are billed only for developers who author pull requests in the last 30 days.
For solo developers and OSS maintainers.
For startups shipping AI features.
For growing engineering teams.
For private repos and regulated workloads.
Install Sebastion AI on your GitHub org and review your next pull request in under a minute.