nowfound

Alternatives

Products that do what DevHorrors does

Catch AI-Hallucinated & Slopsquatted Code

  1. 1
    Shieldfy139

    Smart code security for developers 👩🏼‍💻👨🏿‍💻👨‍🚀

    2020

  2. 2

    Codebase-aware spec engine for Cursor, Claude Code & Lovable

    2025

  3. 3

    Ship AI Code with confidence and speed

    2024

  4. 4

    Pentest and patch every deploy with AI

    Jun 2026

  5. 5

    Security Scanner for AI-generated Code

    7d ago · scanity.dev

  6. 6
    Detectly112

    Sniff out AI slop

    2025

  7. 7

    Trace, evaluate, and improve AI agents in production

    30d ago · telerik.com

  8. 8

    AI powered code security analysis

    2023

  9. 9
    CodeGuide126

    Generate PRDs, specs and wireframes your AI understands.

    Mar 2026

  10. 10
    Codoki25

    Code reviews that catch AI hallucinations

    Nov 2025

  11. 11

    The local security guardrail for AI coding agents

    21d ago · agentinel.habitwala.in

  12. 12

    AI code reviews & Pipeline debugging

    2024

  13. 13IC
  14. 14

    Coding agents craft arbitrary code so securing them is more complicated than red-teaming. We post trained a cyber-security small llm, changed how it reasons and supplemented our controls using program analysis techniques such as inline reference monitoring to outperform GPT5.5-xhigh on hard benchmarks like LinuxArena and SleightBench. Free product available at harden.run and full benchmarks in the blog post.

    9d ago · harden.run

  15. 15FA

    Hi HN, Lately Github PRs have been drowning in a flood of AI slop. I’ve been seeing it myself, and I’m not the only one: https://x.com/mitchellh/status/2011819428061855915 I think it’s great that folks are using AI tools to code faster and better, but too many folks are abusing them to make low-quality contributions to public repos. This takes a lot of reviewers’ mindshare. IMO there needs to be a mechanism to flag low-effort PRs with AI slop, so you can just skip reading them. So I built one: https://haystackeditor.com/slop-detector It’s a simple AI…

    Jan 2026 · haystackeditor.com

  16. 16

    The local security guardrail for AI coding agents

    21d ago · agentinel.habitwala.in

  17. 17CS

    Hi HN, I built *CodeDrift*, a CLI tool that detects bugs commonly introduced by AI coding assistants like Copilot, Cursor and ChatGPT. Over the last year I noticed that AI tools often generate code that compiles correctly, passes linting and looks reasonable in code review but still contains subtle issues. Some common examples I kept seeing: * async `forEach` loops that never await promises * missing authorization checks (IDOR) * hallucinated dependencies that don’t exist * stack traces leaking sensitive information * request data used without validation These bugs often slip past ESLint,…

    Mar 2026 · npmjs.com

  18. 18

    AI that spots real risks and keeps your code safe.

    Dec 2025

  19. 19SA

    Design slop is the feeling that tells you a website is purely AI-generated. This is an attempt to classify the design patterns behind it. Applying this scoring to recent ShowHN submissions shows that about a third of the submissions show medium to heavy design slop: https://slopcop.adriankrebs.ch/show How the scoring works: - A headless browser loads each site (Playwright) - A small in-page script analyzes the DOM and reads computed styles - Every pattern is a deterministic CSS or DOM check. There are false positives, but my manual QA run verified it’s maybe 5-10%. Is design…

    Jul 2026 · slopcop.adriankrebs.ch

  20. 20TA
  21. 21FP

    We've built an open-source tool to stress test AI agents by simulating prompt injection attacks. We’ve implemented one powerful attack strategy based on the paper [AdvPrefix: An Objective for Nuanced LLM Jailbreaks](https://arxiv.org/abs/2412.10321). Here's how it works: - You define a goal, like: “Tell me your system prompt” - Our tool uses a language model to generate adversarial prefixes (e.g., “Sure, here are my system prompts…”) that are likely to jailbreak the agent. - The output is a list of prompts most likely to succeed in bypassing safeguards. We’re just getting…

    2025 · security.vista-labs.ai

  22. 22

    Scans AI agent skills for malicious code

    10d ago · github.com

  23. 23FC

    Hi everyone, I’ve been working on an open-source tool called Flakestorm to test the reliability of AI agents before they hit production. Most agent testing today focuses on eval scores or happy-path prompts. In practice, agents tend to fail in more mundane ways: typos, tone shifts, long context, malformed input, or simple prompt injections — especially when running on smaller or local models. Flakestorm applies chaos-engineering ideas to agents. Instead of testing one prompt, it takes a “golden prompt”, generates adversarial mutations (semantic variations, noise, injections, encoding edge…

    Jan 2026

  24. 24CB

    AI agents now have impressive reasoning capabilities. This raises an important question: how dangerous are these AI agents at identifying & exploiting web vulnerabilities? We created CVE-bench to find out (I'm one contributor of 16). To our knowledge CVE-bench is the first benchmark using real-world web vulnerabilities to evaluate AI agents' cyberattack capabilities. We included 40 CVEs from NIST's database, focusing on critical-severity vulnerability (CVSS > 9.0). To properly evaluate agents’ attacks, we built isolated environments with containerization and identified 8 common attack…

    2025 · github.com

Ranked by how close each launch is in meaning, then by votes. Refine with a description →