LoRexxar/Kunlun-M

2,416 stars · Last commit 2026-09-28

KunLun-M — Open-source static code analysis for PHP, Nodejs/JavaScript, Python, Golang, Java and C/C++, with AST-based semantic scanning and one-click AI Agent integration (OpenClaw, Codex, Claude Code, Hermes, and more).

README preview

[中文](README.zh.md) | English

# KunLun-M

[![GitHub release](https://img.shields.io/github/release/LoRexxar/Kunlun-M/all.svg)](https://github.com/LoRexxar/Kunlun-M/releases)
[![license](https://img.shields.io/github/license/LoRexxar/Kunlun-M.svg)](./LICENSE)
![Python 3.13](https://img.shields.io/badge/python-3.13-blue.svg)

**KunLun-M(昆仑镜)** is an open-source static code security analysis system. It builds an AST graph from source code and performs taint analysis to detect vulnerabilities.

- **14 languages**: PHP / JavaScript / TypeScript / Python / Java / Go / Ruby / Rust / C / C++ / C# / Kotlin / Lua / Solidity
- **AST graph engine**: Builds a full program graph (call graph, data flow, AST structure) for taint tracking
- **CLI / Console / Web** three modes
- **Built-in AI Agent skill**: One-click integration with Codex / Claude Code / Hermes etc.

## Quick Start

```bash
# Install
git clone https://github.com/LoRexxar/Kunlun-M.git && cd Kunlun-M

View full repository on GitHub →