CodeMender lets you proactively scan your codebase for software weaknesses and execute proof-of-concept (PoC) exploits in your local sandbox to confirm exploitability and eliminate false positives.
Scan for vulnerabilities
To run a rapid security scan across your codebase, run cm find. Scan targeted modules or batches of 10 to 50 files at a time for optimal performance.
Scan a specific subdirectory:
cm find ./src/auth/
Scan only the modified files in a subdirectory:
cm find --diff ./src/auth/
Scan a single file:
cm find ./src/auth/session_manager.py
Skip interactive approval prompts during the scan:
cm find ./src/auth/ -y
For more information about scanning pull requests with --diff or running deep
multi-session scans with --deep, see CodeMender find
modes and Integrate with
CI/CD.
Verify vulnerabilities
Once CodeMender identifies potential vulnerabilities, ask it to verify exploitability. During verification, CodeMender generates and executes a proof-of-concept (PoC) exploit (inside the default sandbox) to confirm whether the issue is genuinely exploitable.
Locate the finding-id from the output of cm report or cm find, then run:
cm verify FINDING_ID
Verification flags
The following flags configure cm verify:
| Flag | Default | Description |
|---|---|---|
-c, --context TEXT |
"" |
Pass steering instructions or application domain context to guide the
agent (for example, cm verify FINDING_ID -c "Focus
analysis on the multi-tenant session validation path").
|
--skip-exploit-verification |
false |
Perform static verification only without running active PoC exploits. |
--sandbox |
true |
Explicitly enable or disable the sandbox for this run (for example,
--sandbox=false to disable).
|
--unrestricted |
false |
Temporarily bypass all sandbox protections for this run, disabling file system boundaries and OS-level container isolation. |
-y, --yes |
false |
Skip interactive confirmation prompts ([y/N]) for tool
actions and PoC exploit execution. Commands remain contained
within the OS-level sandbox container (exebox).
|