Scan and verify code vulnerabilities

CodeMender lets you proactively scan your codebase for software weaknesses and execute proof-of-concept (PoC) exploits in your local sandbox to confirm exploitability and eliminate false positives.

Scan for vulnerabilities

To run a rapid security scan across your codebase, run cm find. Scan targeted modules or batches of 10 to 50 files at a time for optimal performance.

Scan a specific subdirectory:

cm find ./src/auth/

Scan only the modified files in a subdirectory:

cm find --diff ./src/auth/

Scan a single file:

cm find ./src/auth/session_manager.py

Skip interactive approval prompts during the scan:

cm find ./src/auth/ -y

For more information about scanning pull requests with --diff or running deep multi-session scans with --deep, see CodeMender find modes and Integrate with CI/CD.

Verify vulnerabilities

Once CodeMender identifies potential vulnerabilities, ask it to verify exploitability. During verification, CodeMender generates and executes a proof-of-concept (PoC) exploit (inside the default sandbox) to confirm whether the issue is genuinely exploitable.

Locate the finding-id from the output of cm report or cm find, then run:

cm verify FINDING_ID

Verification flags

The following flags configure cm verify:

Flag Default Description
-c, --context TEXT "" Pass steering instructions or application domain context to guide the agent (for example, cm verify FINDING_ID -c "Focus analysis on the multi-tenant session validation path").
--skip-exploit-verification false Perform static verification only without running active PoC exploits.
--sandbox true Explicitly enable or disable the sandbox for this run (for example, --sandbox=false to disable).
--unrestricted false Temporarily bypass all sandbox protections for this run, disabling file system boundaries and OS-level container isolation.
-y, --yes false Skip interactive confirmation prompts ([y/N]) for tool actions and PoC exploit execution. Commands remain contained within the OS-level sandbox container (exebox).