KunLun-M — Open-source static code analysis for PHP, Nodejs/JavaScript, Python, Golang, Java and C/C++, with AST-based semantic scanning and one-click AI Agent integration (OpenClaw, Codex, Claude Code, Hermes, and more).
About the project
Kunlun-M is a static security-analysis tool that examines source code for vulnerabilities using semantic analysis based on abstract syntax trees. Security researchers and developers use it with PHP, JavaScript or Node.js, Python, Go, Java, and C or C++ projects, with additional basic scanning for Chrome extensions. Its catalogue skill connects the analysis workflow with coding agents.
A scripted workflow for Kunlun-M, a static security scanner that examines source code without running it. It supports PHP, JavaScript, Solidity smart contracts, and Chrome extensions, and can create scanner rules and tamper settings.