Files
☣️ Mr. The Plague ☣️andSquidSec Bot 31bd057301 test
Demo only — hardcoded secret + injection / dangerous API patterns.
See examples/README.md

Co-authored-by: SquidSec Bot <bot@squidsec.local>
2026-07-28 16:18:17 -04:00
..
2026-07-28 16:18:17 -04:00

SquidGate language samples

SquidSec logo

A SquidSec Open Source Project · SquidOffense.com

Open a sample PR for your language to see SquidGate annotate real findings (hardcoded secrets, injection, dangerous APIs).

Each PR adds one small demo file under examples/<language>/ with intentional vulnerabilities. Do not copy these patterns into production code.

# Language Sample PR
1 JavaScript #2
2 TypeScript #3
3 Python #4
4 Java #5
5 C# #6
6 Go #7
7 Rust #8
8 C++ #9
9 C #10
10 PHP #11
11 Ruby #12
12 Swift #13
13 Kotlin #14
14 Scala #15
15 Shell #16
16 Dart #17
17 PowerShell #18
18 SQL #19
19 Perl #20
20 Lua #21

What you should see

  1. Check run named SquidGate
  2. Line annotations on the sample file
  3. PR comment summarizing findings
  4. Check failure when severity ≥ block_on (default high)

Use on your repo

- uses: SquidSec/SquidGate@v1
  with:
    llm-api-key: ${{ secrets.LLM_API_KEY }}

Pin an immutable build: SquidSec/SquidGate@v1.0.0-build.N — see Releases.