Scandrix
Deterministic policy engine

Drixy rules library.

Production-tested AST review rules. Enforce security constraints, architecture boundaries, and team standards with zero false alarms.

Preview any rule with dry-run before enforcing it org-wide.

$ scandrix rules test --diff pr.diff
Rules shipped
6 production-tested
Matching
Deterministic AST
Languages
Go · TS · Py
False alarms
Zero by design

Showing 6 of 6 rules

01sec-001critical

Enforce Parameterized SQL Queries

Forbids string concatenation or template literals when forming database queries to eliminate SQL injection vectors.

Language: AllCategory: SecurityDeterministic AST-matcher
sec-001.yaml
version: 1
rule:
  id: sec-001
  name: enforce-parameterized-sql
  severity: critical
  description: Never use string formatting or concatenation in database queries
  match:
    ast_call:
      - "db.Query($QUERY)"
      - "db.Exec($QUERY)"
    where:
      $QUERY: "binary_expression(op='+', type='string') | template_string"
  message: "Critical SQL Injection risk detected. Always use parameterized queries (e.g. $1, ?, :param)."
02sec-002critical

Prevent Hardcoded API Keys & Secrets

Detects hardcoded high-entropy tokens, JWTs, Stripe keys, GitHub tokens, and private keys in repository diffs.

Language: AllCategory: SecurityDeterministic AST-matcher
sec-002.yaml
version: 1
rule:
  id: sec-002
  name: no-hardcoded-secrets
  severity: critical
  description: Secrets must be loaded from process.env or secret managers
  match:
    entropy_scan:
      threshold: 4.5
    regex:
      - "(sk_live_[0-9a-zA-Z]{24})"
      - "(ghp_[0-9a-zA-Z]{36})"
      - "(kodus_[0-9a-zA-Z]{32})"
      - "(scandrix_[0-9a-zA-Z]{32})"
  message: "Hardcoded credential detected. Move all secret values to environment variables."
03arch-001critical

Enforce Multi-Tenant Query Scoping

Guarantees that database queries in tenant-scoped entities explicitly filter by tenant_id or org_id to prevent IDOR.

Language: GoCategory: ArchitectureDeterministic AST-matcher
arch-001.yaml
version: 1
rule:
  id: arch-001
  name: tenant-isolation-guard
  severity: critical
  description: All workspace database operations must include organizationId
  match:
    ast_query:
      entity: "WorkspaceEntity | RepositoryEntity"
    missing_filter: "tenant_id | organization_id"
  message: "Cross-tenant data leakage vulnerability: query is missing tenant_id filtering."
04perf-001warning

Detect Unbounded Goroutines & Async Spawns

Flags raw 'go func()' invocations without wait groups, worker pools, or context cancellation controls.

Language: GoCategory: PerformanceDeterministic AST-matcher
perf-001.yaml
version: 1
rule:
  id: perf-001
  name: bounded-concurrency-check
  severity: warning
  description: Spawning goroutines without context or pool leads to resource exhaustion
  match:
    ast_statement: "go func() { ... }()"
    without_ancestor: "sync.WaitGroup | errgroup.Group | workerpool.Pool"
  message: "Unbounded goroutine detected. Wrap in errgroup.Group or use a bounded worker pool."
05rel-001warning

Require Error Return Handling

Flags blank identifier error assignment in critical operations like database writes and network calls.

Language: GoCategory: ReliabilityDeterministic AST-matcher
rel-001.yaml
version: 1
rule:
  id: rel-001
  name: no-ignored-errors
  severity: warning
  description: Never discard errors from fallible operations
  match:
    ast_assignment:
      left: "_"
      right_type: "error"
  message: "Error return explicitly discarded. Log or handle the error appropriately."
06style-001critical

Forbid Client-Exposed Secret Prefixes

Prevents developers from prefixing secret API keys with NEXT_PUBLIC_ or VITE_, leaking them into client bundles.

Language: TypeScriptCategory: SecurityDeterministic AST-matcher
style-001.yaml
version: 1
rule:
  id: style-001
  name: no-public-secret-prefix
  severity: critical
  description: Secrets must never have client-exposed prefixes
  match:
    env_assignment:
      key_regex: "^(NEXT_PUBLIC_|VITE_|REACT_APP_).*(SECRET|PRIVATE_KEY|TOKEN|PASSWORD)"
  message: "Fatal security violation: secret key exposed via public frontend prefix."

Your stack, your standards

Write rules in plain words.

Define architectural patterns and code standards in plain English or AST YAML — dry-run them on history, then enforce org-wide.