SECURITY / DEVELOPER TOOLS

Tobacco

A defensive source auditor that reports review candidates with location, confidence and coverage notes.

Current state
Review utility
Discipline
Security · Developer tools
Built with
Python / AST analysis / SARIF / OSV advisory integration / GitHub Actions

The idea

Suspicious code patterns are useful starting points when their meaning and limits are explicit. Tobacco makes those candidates readable through stable rule IDs, suggested review context and structured reports, while keeping scanned source execution out of the default workflow.

How it works

Python AST analysis resolves selected aliases and local assignments; JavaScript, PHP and configuration checks use bounded text patterns. Optional dependency advisory lookup and single-response HTTP checks extend the report surface. JSON/SARIF serialization records locations and fingerprints while omitting matched secret values.

What’s implemented

  • Offline source/configuration review with severity and confidence
  • Selected dependency-advisory matching and HTTP metadata checks
  • Text, JSON and SARIF reports with configurable failure thresholds
  • Scope exclusions, skipped-file coverage notes and redacted findings

PROJECT STATUS / REVIEW UTILITY

Where it stands

Defensive review utility

  • Pattern matches do not establish reachability, attacker control or exploitability
  • No whole-program dataflow, business-logic assessment or full parsing outside Python
  • False positives and missed vulnerabilities are expected; clean output is not a security clearance

Source & resources

Documentation behind this project page

Reviewed October 1, 2026. Project descriptions reflect a source review; repository validation claims were not independently reproduced.