Security scanner
Deterministic collection and developer-workflow scanning with evidence-backed findings.
RaksHex parses supported API collection/spec inputs and runs deterministic rules from @rakshex/scanner-core. Findings are persisted and surfaced through supported web, CLI, VS Code and GitHub workflows.
What a finding means
A scanner finding is evidence produced by an implemented rule. Rules can flag concrete risky patterns such as exposed credentials, insecure transport/configuration and authorization-sensitive API shapes where the scanner has a matching rule.
Do not treat a clean scan as proof that an application is vulnerability-free, and do not describe the scanner as a replacement for a penetration test or formal audit.
OWASP mapping
Where a rule is mapped to OWASP/CWE language, the mapping helps classification and remediation. It is not a claim of complete coverage of every OWASP category.
