fraim-dev/fraim
A flexible framework for security teams to build and deploy AI-powered workflows that complement their existing security operations.
Built on a modular plugin architecture, Fraim executes multiple specialized workflows—Risk Flagger (contextual PR review), Code Security Analysis (LLM-powered vulnerability detection across languages), and IAC Analysis (Terraform/CloudFormation/Kubernetes misconfigurations)—each producing SARIF output for CI integration. It supports multiple LLM providers (Anthropic, OpenAI, Google Gemini) and runs as a CLI or GitHub Action, with optional Langfuse observability for tracing model usage and performance.
153 stars.
Stars
153
Forks
15
Language
Python
License
MIT
Category
Last pushed
Feb 09, 2026
Commits (30d)
0
Get this data via API
curl "https://pt-edge.onrender.com/api/v1/quality/llm-tools/fraim-dev/fraim"
Open to everyone — 100 requests/day, no key needed. Get a free key for 1,000/day.
Higher-rated alternatives
intuitem/ciso-assistant-community
CISO Assistant is a one-stop-shop GRC platform for Risk Management, AppSec, Compliance & Audit,...
SecureCodeWarrior/ai-security-rules
This repository contains security rule files designed to be used with AI-assisted developer tools.
Haserjian/assay
Receipt-native AI safety toolkit. Build, sign, and verify Proof Packs that prove what your AI...
ogulcanaydogan/Verifiable-AI-Output-Ledger
Tamper-evident, cryptographically signed audit ledger for AI/LLM outputs. DSSE envelopes, RFC...
ogulcanaydogan/LLM-Supply-Chain-Attestation
Cryptographic attestation framework for LLM supply-chain security, tamper-evident provenance for...