Features

Everything you need to find and fix real security issues

OpenRouting pairs trusted open-source scanners with Claude's review so your team sees the issues that matter — in your code and in your AI-agent setup.

$ openrouting features
✓ scanners semgrep · gitleaks · trivy
✓ ai triage verdict · explanation · fix
✓ pr review changed files only
✓ agent setup skills · hooks · mcp
✓ reports pdf · markdown
real issues, with a fix attached
$ 

Proven scanners, one list

Code flaws from Semgrep, leaked secrets from Gitleaks (including git history), and infrastructure misconfigurations from Trivy — merged into a single findings list, deduplicated across scans.

Claude reviews every finding

Each finding gets an AI verdict (real issue or likely false positive), a confidence score, a plain-English explanation, and a suggested fix in your code's style.

Pull-request review

Open a PR, review only its changed files, and post a single summary comment back to GitHub — as you, on click, never automatically.

AI-agent setup review

OpenRouting detects LLM-agent setups — agents, skills, memory, MCP servers, hooks — and reviews them for prompt-injection, tool-safety, and secrets risks.

Trend and triage

Watch open findings fall over time. Triage at keyboard speed, mark false positives and accepted risk, and undo any change.

Downloadable reports

Generate an AI-written security report for any scan, with summary tables and per-finding detail, and download it as PDF or Markdown.

Built for developers

Connect a GitHub repository, pick a branch, and scan. Findings link straight to the exact file and line, with the flagged code shown inline.

Usage-based credits

Start with 100 free credits. Scans and reviews cost credits; failed runs are refunded automatically.

See it on your own repository

Connect a repo and get your first results in minutes.

Get started free