Aikido Security

Aikido Security is a developer-first software security platform. We scan your source code & cloud to show you which vulnerabilities are actually important.

GitHub 63 repos 483 followers

Explained projects

Inside `safechain-internals`: The Release Channel That Keeps Aikido Device Protection Alive
Inside `safechain-internals`: The Release Channel That Keeps Aikido Device Protection Alive
A tiny repository for binaries, MDM profiles, and anti-tamper rules reveals how enterprise security software gets installed, trusted, and kept running across Windows, macOS, and Linux.
8 min read · Apr 7, 2026
AikidoSec/aws-native-terraform-module: Terraform That Deploys Like an AWS Control Plane
AikidoSec/aws-native-terraform-module: Terraform That Deploys Like an AWS Control Plane
It uses Terraform where orchestration belongs, StackSets where AWS can fan out cleanly, and `moved` blocks to refactor live security roles without a destructive rewrite.
9 min read · Apr 7, 2026
aikido-kiro-power: Aikido's Kiro Power turns security into a write-time gate
aikido-kiro-power: Aikido's Kiro Power turns security into a write-time gate
This tiny repo does not scan code itself. It teaches Kiro to stop, check, fix, and rescan before unsafe code can move forward.
8 min read · Apr 7, 2026
zen-internals-node: The Firewall Hidden Inside V8
zen-internals-node: The Firewall Hidden Inside V8
zen-internals-node turns eval() and new Function() into a policy check, so Node.js code can be stopped at the instant it tries to become executable.
11 min read · Apr 6, 2026
AikidoSec/gcp-onboarding-terraform-module: how to onboard a cloud scanner without a shared secret
AikidoSec/gcp-onboarding-terraform-module: how to onboard a cloud scanner without a shared secret
This Terraform module encodes least privilege, API enablement, and keyless trust into one repeatable GCP handoff.
7 min read · Apr 6, 2026
opengrep-rules: The security rule that treats prompt injection like RCE
opengrep-rules: The security rule that treats prompt injection like RCE
AikidoSec’s opengrep-rules repository shows how static analysis is moving from code bugs to AI workflow abuse, one YAML file at a time.
9 min read · Apr 6, 2026
safe-chain-jfrog-plugin: Turning Artifactory Into a Dependency Bouncer
safe-chain-jfrog-plugin: Turning Artifactory Into a Dependency Bouncer
A deep dive into the JFrog extension that checks remote packages against live malware intel and blocks suspicious downloads before they land.
8 min read · Apr 6, 2026
safe-chain: Aikido Safe Chain and the Art of the Benevolent MITM
safe-chain: Aikido Safe Chain and the Art of the Benevolent MITM
How a local proxy intercepts your package manager to manipulate registry metadata and block zero-day supply chain attacks before they hit your disk.
7 min read · Mar 31, 2026

Yet to be explained

deploy-safe-chain
Script for distributing Aikido Safe-Chain to Mac users with Iru (Kandji). Should also work with Jamf and other tools.
Shell6 stars
Explain
tree-sitter-grammars
JavaScript2 stars
Explain