vakt

Intro

Install vakt and use DOM-0.8B to rank code for security review locally.

What is vakt?

vakt is a local code-security scanner. It extracts functions from a repository, scores them with DOM-0.8B, and ranks them for further investigation. Each function receives a severity score and scores for 18 CWE families.

Use it to triage an unfamiliar codebase, focus a code review, check changes in CI, or give a coding agent a security check through MCP. It does not generate patches or prove that a vulnerability is exploitable. Review flagged code in context; a clean report is not a guarantee that code is secure.

Source code is scored on your machine using Metal on Apple Silicon, CUDA 13 on supported NVIDIA hardware, or a Linux CPU.

Requirements

  • macOS on Apple Silicon, or Linux on amd64/arm64 with glibc 2.35 or newer.
  • Access to the gated DOM-0.8B model on Hugging Face. Request access on the model page before downloading.
  • A Hugging Face token or an existing hf auth login session for the model download.

vakt is a native binary. Node.js and npx are not required. See the source repository for licensing and release details.

Install

The installer selects the backend for your machine:

curl -fsSL https://get.vaktex.com/oss-vakt | sh

The default installation directory is ~/.local/bin. Make sure it is on your PATH if your shell cannot find vakt.

Download the model

If you have the Hugging Face CLI installed, sign in and download the model:

hf auth login
vakt summon

Alternatively, supply HF_TOKEN through your environment before running vakt summon. The model download is approximately 1.5 GB. Hugging Face credentials are for downloading the weights; scanning runs locally.

First scan

Run from your project directory:

vakt .

Or pass a path explicitly:

vakt patrol ./repo

The report ranks functions at or above the severity threshold, which defaults to 0.5. To save a JSON report and then inspect its first finding:

vakt . --format both
vakt show 1

A completed scan exits with 1 when a function meets the failure threshold. This indicates a finding, not a scanner error. See CLI usage for output formats and exit codes.

Next steps

  • CLI usage: scan scope, thresholds, reports, and exit codes.
  • Configuration: model downloads, cache, and device selection.
  • Coding agents: let an agent inspect findings through MCP.
  • Integrations: MCP configuration and GitHub Actions.
  • Vex: the separate security workflow language and module reference.

Improve team velocity with
better security and privacy.