LoRexxar/Kunlun-M
2,416 stars · Last commit 2026-09-28
KunLun-M — Open-source static code analysis for PHP, Nodejs/JavaScript, Python, Golang, Java and C/C++, with AST-based semantic scanning and one-click AI Agent integration (OpenClaw, Codex, Claude Code, Hermes, and more).
README preview
[中文](README.zh.md) | English # KunLun-M [](https://github.com/LoRexxar/Kunlun-M/releases) [](./LICENSE)  **KunLun-M(昆仑镜)** is an open-source static code security analysis system. It builds an AST graph from source code and performs taint analysis to detect vulnerabilities. - **14 languages**: PHP / JavaScript / TypeScript / Python / Java / Go / Ruby / Rust / C / C++ / C# / Kotlin / Lua / Solidity - **AST graph engine**: Builds a full program graph (call graph, data flow, AST structure) for taint tracking - **CLI / Console / Web** three modes - **Built-in AI Agent skill**: One-click integration with Codex / Claude Code / Hermes etc. ## Quick Start ```bash # Install git clone https://github.com/LoRexxar/Kunlun-M.git && cd Kunlun-M