LATEST
AGENT SCAN ACROSS 22 LANGUAGESv2.1.0: every text file read at a stated level — full rules in 22 languages plus web-page scripts and notebooks · agent CLIs launched with their checks off, encoded prompts and hidden hosts, local models with no URL in the file: the three 2025 attack shapes found by name · churn now measures Julia, Lua and Elixir — 62 languages · tested on 25 public repositories · the licence check no longer stalls every run · the Agent Scan page · download ENCODED PAYLOADS AND A FASTER, STRICTER AGENT SCANv2.0.2: a second pass decodes base64, hex and compressed literals and rates hidden AI code that the file executes CRITICAL · the rogue-agent pattern is CRITICAL in every scanned language · Ruby and C# false CRITICALs removed · agent scan start-up 25 s → 0.1 s on a 115 MB tree · Metrics + Agent Scan runs from the GUI again · every demo opens an in-tool source page verified against a frozen baseline · download VERSION 2.0.1v2.0.1: the metric definitions moved (a move is not churn, braces never count, unclassified text out of the totals) so 1.9 and 2.0 numbers are not comparable · 114 known-answer fixtures behind the engine · every headless mode licence-gated · the Action reads its gate rules from the base branch · download SECURITY RELEASEv1.9.9: AI-BOM provider counts made exact (one provider however the code spells it; frameworks reported separately) · the agent map folds to match · committed credentials, build surface and the AI-vs-exec-only split now in the machine-readable JSON · download CODE DELTA THREAT DETECTION AND CODE SECURITY TOOL PORTFOLIO — EXPANDED AND UPGRADEDv1.9.8: committed credentials found and shown redacted · merge gates for credentials, new install hooks and new remote-fetching build files · download-URL deltas on fetching build files · Agents mode in the Code Browser with the 3-D agent map as a first-class view · download MULTI-CORE ENGINE — new in v1.9.7: scans use every core with byte-identical results — large scans roughly halved — plus Code Browser inheritance, a sortable class-complexity view and a density dial on the class visualiser · download BUILD-FILE ALERTS — new in v1.9.6: a scan that compares two versions now flags every build/CI/packaging file that changed — the xz-utils entry route — install hooks first, in the GUI, the agent report and the PR comment · download THE CODE BROWSER — new in v1.9.5: the diff and the whole project's structure in one page — Changes, Overview, Files, Classes and Visualiser tabs, a directory tree, a class index with methods at file:line, a 3D include map and a class ego view coloured by this scan's churn · download THE AUDITED DIFF — new in v1.9.4: a rebuilt diff (now the Code Browser’s Changes tab) where every counter is a claim you can click, walk and cite — plus moves tracked across files and git overlays showing AI provenance, age of destroyed code and per-author churn · download TRACEABLE NUMBERSv1.9.3 fixes the PR comment’s generated-file count: it now counts only the generated files that churned in your PR, so the number traces to the diff · download TRUE_CHURN IN CI — new in v1.9.2: pull-request comments now separate authored churn from generated churn — in a real npm/cli release, 80.1% of the churn came from one lockfile · read the paper TRUE_CHURN — new in v1.9.1: separating authored code from generated code — lockfile and codegen churn subtotalled, TRUE_CHURN = what your developers actually wrote · plus Agent Infrastructure: rogue agents and committed agent credentials found in your tree · download NEW PAPER — why LLOC is what really counts: a 35-line file holds 5 working statements, and a 12-line churn was really 1 · read the paper NEW MEASUREMENT — 28.4% of NVIDIA’s open GPU driver tree is data, not code — single statements up to 3MB · read how it was found NEW REPORT — six and a half years of Erlang/OTP, measured statement by statement — and what a line counter misses · read the report WE SCANNED CHROMIUM — 43.5 million lines of code, one command, one laptop · read the report NEW PAPER — AI-assisted development barely edits code, it replaces it: established projects rework 1 statement in 6, agent-built code 1 in 500 · read Paper C v1.9.0 released — all non-specified programming languages churned as U_LOC · TOTAL LOC · spreadsheet report columns · full coverage accounting · download LIVE DEMO — watch CodeDelta report on a real pull request · view on GitHub BUSINESS LANGUAGE BUNDLE added for the finance industry — COBOL, JCL, PL/I · see the languages FREE TO TEST until 31 October 2026 — two lines in a workflow, no signup · run it in CI AGENT SCAN ACROSS 22 LANGUAGESv2.1.0: every text file read at a stated level — full rules in 22 languages plus web-page scripts and notebooks · agent CLIs launched with their checks off, encoded prompts and hidden hosts, local models with no URL in the file: the three 2025 attack shapes found by name · churn now measures Julia, Lua and Elixir — 62 languages · tested on 25 public repositories · the licence check no longer stalls every run · the Agent Scan page · download ENCODED PAYLOADS AND A FASTER, STRICTER AGENT SCANv2.0.2: a second pass decodes base64, hex and compressed literals and rates hidden AI code that the file executes CRITICAL · the rogue-agent pattern is CRITICAL in every scanned language · Ruby and C# false CRITICALs removed · agent scan start-up 25 s → 0.1 s on a 115 MB tree · Metrics + Agent Scan runs from the GUI again · every demo opens an in-tool source page verified against a frozen baseline · download VERSION 2.0.1v2.0.1: the metric definitions moved (a move is not churn, braces never count, unclassified text out of the totals) so 1.9 and 2.0 numbers are not comparable · 114 known-answer fixtures behind the engine · every headless mode licence-gated · the Action reads its gate rules from the base branch · download SECURITY RELEASEv1.9.9: AI-BOM provider counts made exact (one provider however the code spells it; frameworks reported separately) · the agent map folds to match · committed credentials, build surface and the AI-vs-exec-only split now in the machine-readable JSON · download CODE DELTA THREAT DETECTION AND CODE SECURITY TOOL PORTFOLIO — EXPANDED AND UPGRADEDv1.9.8: committed credentials found and shown redacted · merge gates for credentials, new install hooks and new remote-fetching build files · download-URL deltas on fetching build files · Agents mode in the Code Browser with the 3-D agent map as a first-class view · download MULTI-CORE ENGINE — new in v1.9.7: scans use every core with byte-identical results — large scans roughly halved — plus Code Browser inheritance, a sortable class-complexity view and a density dial on the class visualiser · download BUILD-FILE ALERTS — new in v1.9.6: a scan that compares two versions now flags every build/CI/packaging file that changed — the xz-utils entry route — install hooks first, in the GUI, the agent report and the PR comment · download THE CODE BROWSER — new in v1.9.5: the diff and the whole project's structure in one page — Changes, Overview, Files, Classes and Visualiser tabs, a directory tree, a class index with methods at file:line, a 3D include map and a class ego view coloured by this scan's churn · download THE AUDITED DIFF — new in v1.9.4: a rebuilt diff (now the Code Browser’s Changes tab) where every counter is a claim you can click, walk and cite — plus moves tracked across files and git overlays showing AI provenance, age of destroyed code and per-author churn · download TRACEABLE NUMBERSv1.9.3 fixes the PR comment’s generated-file count: it now counts only the generated files that churned in your PR, so the number traces to the diff · download TRUE_CHURN IN CI — new in v1.9.2: pull-request comments now separate authored churn from generated churn — in a real npm/cli release, 80.1% of the churn came from one lockfile · read the paper TRUE_CHURN — new in v1.9.1: separating authored code from generated code — lockfile and codegen churn subtotalled, TRUE_CHURN = what your developers actually wrote · plus Agent Infrastructure: rogue agents and committed agent credentials found in your tree · download NEW PAPER — why LLOC is what really counts: a 35-line file holds 5 working statements, and a 12-line churn was really 1 · read the paper NEW MEASUREMENT — 28.4% of NVIDIA’s open GPU driver tree is data, not code — single statements up to 3MB · read how it was found NEW REPORT — six and a half years of Erlang/OTP, measured statement by statement — and what a line counter misses · read the report WE SCANNED CHROMIUM — 43.5 million lines of code, one command, one laptop · read the report NEW PAPER — AI-assisted development barely edits code, it replaces it: established projects rework 1 statement in 6, agent-built code 1 in 500 · read Paper C v1.9.0 released — all non-specified programming languages churned as U_LOC · TOTAL LOC · spreadsheet report columns · full coverage accounting · download LIVE DEMO — watch CodeDelta report on a real pull request · view on GitHub BUSINESS LANGUAGE BUNDLE added for the finance industry — COBOL, JCL, PL/I · see the languages FREE TO TEST until 31 October 2026 — two lines in a workflow, no signup · run it in CI

CodeDeltaAI Agent Scan

AI Agent Scan is now so powerful, so comprehensive, we've given it its own dedicated page. It reads every text file in your tree, applies the full rules in 22 languages, and finds by name the three ways the 2025 malware wave hid a model inside a program.

  keep scrolling  
22 languages
get the full rules — plus the script blocks of web pages and the code cells of notebooks. Every other text file is still read.
25 repositories
public code, 30,000+ files, run through the scanner before release — every HIGH and CRITICAL result read by a person
3 attack shapes
from the 2025 incident record — a hijacked agent CLI, an encoded prompt, a local model — each found and named in the report

Everything Agent Scan finds

AI SDK importsOpenAI, Anthropic, Gemini, LangChain and the rest — per-language tables
Model endpointshosted APIs and local servers — Ollama, llama.cpp, vLLM — by host, with the jurisdiction
The rogue patterna process launch or code evaluation within ten lines of a model call — CRITICAL
Agent CLI launchesclaude, gemini, codex, copilot, aider, opencode, q — with the permission-bypass flags named
Encoded promptsbase64, hex and compressed literals decoded; instructions to a model hidden inside them
Hidden hostsa model endpoint assembled from an encoded string, reported as hidden
Model calls in loopsthe cost and runaway risk of a model called per iteration
Prompt injectionprompts built from unchecked input
Web pages, notebooks, CIscript blocks, code cells and workflow steps scanned as the code they hold
Committed credentialsAPI keys and private keys in the tree, shown redacted
AI Bill of Materialsevery provider, endpoint and jurisdiction — native or CycloneDX
Coverage on every resulteach file says which level of scan it received
What it finds

The AI inside your software — where it is wired in, and where it runs what a model says.

Agent Scan is about what the code does at run time, not who wrote it. It reads the source for the places a program talks to a model, then looks at what happens to the reply. A reply that is printed is routine. A reply that is passed to a shell, an exec, an eval or a process launcher is the shape that LLM-enabled malware takes, and it is rated CRITICAL wherever the scanner has the language's launch table.

SDKNamed libraries

Imports of AI SDKs and agent frameworks, from a table kept per language — Python, JavaScript and Java through to Kotlin, Swift, Go, Rust, R, Julia and PowerShell.

HOSTModel endpoints

Hosted model APIs by host name with the country the provider is in, and local inference servers — Ollama, llama.cpp, vLLM — whether named directly, read from OLLAMA_HOST, or reached through the Ollama client library.

ROGUEModel output executed

A process launch or code evaluation within ten lines of a model call. This is the finding that separates a chatbot from a program that does what a model tells it. CRITICAL, with the line number.

CLIAgent CLIs launched from code

A program that runs claude, gemini, codex, copilot, aider, opencode or q with a prompt is HIGH. One that passes the flag that switches off the agent's permission checks is CRITICAL — the shape of the nx supply-chain attack.

ENCODEDHidden prompts and hosts

Base64, hex and compressed string literals are decoded. A decoded string that reads as instructions to a model is reported as an encoded prompt; a decoded model host is reported as hidden. Either one in a file that runs commands is CRITICAL.

LOOPCalls inside loops

A model called once per iteration is a cost and a runaway risk. The rule checks that the call sits inside the loop's block, not merely below a loop header somewhere above.

EMBEDCode inside other files

The script blocks of HTML, Vue, Svelte and Astro pages are scanned as JavaScript; the code cells of a Jupyter notebook as Python, with the cell named in the finding; workflow steps, Dockerfiles and Jenkinsfiles as shell.

KEYSCommitted credentials

API keys and private keys sitting in the tree, found by format and shown redacted — one policy line away from failing the build.

BOMAI Bill of Materials

The same scan produces an inventory of every provider, endpoint and jurisdiction the code reaches, native or CycloneDX, and a policy gate that blocks a merge on unapproved providers or foreign-hosted models.

Three attack shapes

The 2025 incident record, in the scanner's own words.

Three public incidents in 2025 each hid a model inside a program in a different way. The samples below are inert files written in the shape of each one; the cards are the scanner's real output on them, unedited.

Agent Scan report card: supply-chain/telemetry.js rated CRITICAL — agent CLI 'claude' launched with its permission checks bypassed (line 4), agent CLI 'gemini' (line 5); the source panel marks lines 4 and 5
A hijacked agent CLI. In August 2025 a compromised release of the nx build tool shipped a post-install script that ran the developer's own Claude, Gemini and Q command-line agents with their safety checks switched off, and used them to search the machine for wallets and credentials (nx advisory GHSA-cxm3-wv7p-598c). The scanner reports agent CLI 'claude' launched with its permission checks bypassed (line 4) and the same for gemini on line 5 — CRITICAL — and the source panel marks both lines.
Agent Scan report card: loader/update_check.py rated CRITICAL — encoded_prompt (line 2, base64: 'Make a list of commands to gather computer information…'), process launch near AI API call (line 8), instructions to a model hidden in an encoded string in a file that runs commands
An encoded prompt. In July 2025 Ukraine's CERT reported LameHug, malware that kept its instructions to a model as a base64 string, sent them to a hosted Qwen model and ran the commands that came back (Cato CTRL analysis). The scanner decodes the literal on line 2, quotes its opening words — "Make a list of commands to gather computer information…" — and reports the launch on line 8.
Agent Scan report card: local/env.sh rated CRITICAL — ai_http_endpoint(local:OLLAMA_HOST), process launch near AI API call (line 4)
A local model, no URL in the file. In August 2025 ESET described PromptLock, ransomware that generated its scripts at run time from a locally hosted open-weight model (ESET Research, WeLiveSecurity). A program talking to Ollama need never write an address: it reads OLLAMA_HOST or calls the client library. The scanner reports the local endpoint from that alone, and the launch of its reply on line 4.

Real output from CodeDelta on inert sample files written in the shape of each incident. No incident code is distributed with the tool.

Coverage

Every text file is read. Each result says at which level.

A scanner that opens only the file types it knows best leaves the rest of the tree unexamined without saying so. Agent Scan reads every text file up to 2 MB and records on each result which of three levels it received, so a clean tree is a clean tree and not a silence.

Full rules — SDK tables, model calls, agent frameworks, loops, and the rogue rule — in C, C#, C++, Dart, Elixir, Go, Groovy, Java, JavaScript, Julia, Kotlin, Lua, Perl, PHP, PowerShell, Python, R, Ruby, Rust, Scala, Swift and TypeScript; also the script blocks of HTML, Vue, Svelte and Astro files and the code cells of Python notebooks.

Endpoint level — model endpoints, encoded payloads and the language's own launch and eval calls, with no SDK table — in shell scripts, CI recipes, Dockerfiles, Jenkinsfiles and Objective-C. The curl model | bash shape lives here and rates CRITICAL.

Text level — model endpoints and encoded payloads, plus Markdown code blocks that would rate HIGH or CRITICAL under their language's rules — for every other readable file, ELEVATED at most.

The user guide's language table carries the level per extension; that column is generated from the scanner's own tables, so the two cannot drift apart.

See the language table in the guide →

  • FULL

    22 languages

    C, C#, C++, Dart, Elixir, Go, Groovy, Java, JavaScript, Julia, Kotlin, Lua, Perl, PHP, PowerShell, Python, R, Ruby, Rust, Scala, Swift, TypeScript.

  • SCRIPT

    Web pages

    HTML, Vue, Svelte and Astro: the <script> blocks and inline event handlers scanned as JavaScript, findings attributed to the page and line.

  • CELL

    Notebooks

    Jupyter code cells scanned as Python, including ! shell lines; each finding names the file line and the cell.

  • ENDPOINT

    Shell, CI, containers

    Shell scripts, GitHub and GitLab workflows, Dockerfiles, Jenkinsfiles, Objective-C: endpoints, encoded payloads and launches.

  • TEXT

    Everything else

    Any readable file to 2 MB: endpoints, encoded payloads, dangerous Markdown code blocks. ELEVATED at most.

  • LABEL

    Stated on every file

    The report, the JSON and the CSV carry the coverage level per file; the summary line counts the files at each.

The report

One card per file: the rating, the reasons, the lines.

Every finding is a sentence a reviewer can check against the source in the same panel. The screens below are from one scan of the sample tree — click any picture to enlarge it.

Agent Scan report header and summary: scanned 42 files, 16 CRITICAL, 2 HIGH, 12 ELEVATED; coverage line — 30 files with full language rules, 2 at endpoint level, 10 at text level; tiles for all flagged, critical, high, elevated, normal
The summary. What the scan is, what it is not, the counts, and the coverage line — 30 files with the full rules, 2 at endpoint level, 10 at text level — before a single card.
Agent Scan report card: notebooks/agent.ipynb, Jupyter notebook, rated CRITICAL — eval/exec near AI API call (line 28, cell 3)
A notebook. The OpenAI import and an exec of the reply, reported as line 28, cell 3 so the reviewer opens the right cell.
Agent Scan report card: .github/workflows/fix.yml, CI recipe, shell/CI scan, rated CRITICAL — agent CLI 'codex' launched with its permission checks bypassed (line 7)
A CI recipe. A workflow step running codex exec with its approval checks off. The badge says the file had the shell/CI level of scan.
Agent Scan report card: android/Assistant.kt, Kotlin, rated CRITICAL — process launch near AI API call (line 5); View Source open with line 5, Runtime.getRuntime().exec(reply), marked ROGUE AGENT
View Source. A Kotlin file calling the OpenAI client and handing the reply to Runtime.getRuntime().exec. The panel marks the cited line; a card's every line number can be checked this way without leaving the report.

Real output from CodeDelta — every figure above is produced by the tool from an actual scan, not a mock-up.

In the Code Browser

Every agent on one screen, the map of who talks to whom, and one click to the code.

The same scan opens in the Code Browser as an Agents view and as a 3-D map in the Visualiser. Files are coloured by their Agent Scan risk; providers hosted in sovereignty-sensitive jurisdictions are red. Click any picture to enlarge it.

CodeDelta Code Browser, Agents view: eleven files that call AI listed with risk, AIS score and the signals that fired; below, the fifteen providers the repository talks to with CN and RU jurisdictions in red
Every agent, on one screen. The Code Browser's Agents view: each file that calls AI, its risk and score, the exact signals that fired — and below, all fifteen providers this one small repository talks to, CN and RU jurisdictions in red.
CodeDelta Code Browser, Visualiser in agents mode: files connected to the model providers they call, drawn as a 3-D scene, red links to CN and RU providers
The agent map. Your files, connected to the model providers they call — red links lead to sovereignty-sensitive jurisdictions. Drag to orbit, zoom, hover any dot for its story.
CodeDelta Code Browser, Files view: multi_agent.py opened at its source, langchain and crewai imports and the crew set-up visible
One click to the evidence. Click any file in the Agents view and the source opens at the flagged code — here multi_agent.py, spinning up autonomous crews with langchain and crewai.

Real screens from the Code Browser on the demo repository.

Evidence

Tested on public code before it was described here.

Twenty-five public repositories, more than 30,000 files, were scanned with the released v2.0.2 scanner and with this one, on the same clones. Every HIGH and CRITICAL result from the new scanner was read by a person. The repositories were the SDKs and agent frameworks themselves — openai-python, anthropic-sdk-python, aider, gemini-cli, llama.cpp, ollama-python, openai-kotlin, koog, MacPaw OpenAI, SwiftAnthropic, go-openai, langchaingo, ruby-openai, langchainrb, async-openai, rig, openai-java, openai-scala-client, brainlid/langchain, ellmer, PromptingTools.jl, lua-openai, openai-php/client, langchain_dart, PSOpenAI — the hardest case, because code that implements agents looks like code that runs them.

OPENED4,693 files became 19,499

Across the eighteen repositories in the second run, the v2.0.2 scanner opened 4,693 files; this one opens 19,499. In the Swift, Kotlin, Scala, Elixir, R, Julia and Lua repositories the released scanner opened none at all: SwiftAnthropic 0 → 59 files, ellmer 0 → 391, koog 124 → 2,616, openai-java 64 → 4,023.

FOUNDA real one, in llama.cpp

The first real-world hit of the agent-CLI rule: llama.cpp's own .github/workflows/ai-issues.yml runs opencode run with a prompt on a self-hosted runner. HIGH, and correct — it is an agent launched from CI.

FIXEDFalse positives removed on real code

llama.cpp HIGH 18 → 4 (decode loops are not model calls); gemini-cli's help text naming gemini -p HIGH → NORMAL; a test that serves a loopback address CRITICAL → NORMAL; a CI recipe that installs and starts Ollama CRITICAL → NORMAL; a Ruby string containing backticks CRITICAL → ELEVATED. Each has a fixture that failed before the fix and a guard that keeps the rule on.

KEPTWhat stayed HIGH, and why

The remaining HIGH results are chat loops that call the model per turn — while True, for s.Scan(), for prompt in prompts — and the orchestration code inside the agent frameworks. Read by eye, each is the rule describing the thing.

SAMENothing regressed

Three fixed corpora and the tool's own 489-file tree rated identically before and after each false-positive fix; the demo samples are held to a frozen baseline; a parallel scan is bit-identical to a serial one.

RULESRules with a public source

The Kotlin and Swift SDK names were checked against the libraries' own repositories and Apple's documentation before they went in a table; the web-page event-handler names come from the MDN list. A guess is not a rule.

Limits

What a static scan can and cannot say.

Findings are patterns in source that warrant a human's look, not confirmed malicious activity; the report says so at the top of every run. The rogue rule works on proximity — a launch within ten lines of a model call — so a program that fetches a reply in one file and runs it from another is two ELEVATED files, not one CRITICAL.

Encoded literals are decoded once — base64 or hex, compressed or not — so a string encoded twice over is not read. A file that both serves a local model and pipes its output to a shell is treated as the server side and missed by the rogue rule. An agent CLI named as one element of an argument list is found only when its subcommand follows it directly.

Against careless concealment — the encoded prompt, the environment-variable host, the agent run from a CI step — this is a first tier that did not exist before. Against a determined adversary who builds every string at run time, no scan of the source is the last word, and this page does not claim to be.

  • NORMAL

    No AI use found

    Nothing in the file matched an SDK, an endpoint or a launch rule at the level it was scanned.

  • ELEVATED

    Uses AI, routine

    An SDK or endpoint is present. The ceiling for text-level files.

  • HIGH

    Riskier use

    A model called inside a loop, an agent CLI launched with a prompt, prompts built from unchecked input.

  • CRITICAL

    Runs what a model says

    The rogue pattern, an agent CLI with its checks bypassed, an encoded prompt or hidden host in a file that runs commands.

Run it on your own tree.

Download a time-limited trial license and run Agent Scan locally, from the desktop app or one command. No source code is transmitted.

Try CodeDelta

Back to the overview →    The detection paper →