vakt
Intro
Install vakt and use DOM-0.8B to rank code for security review locally.
What is vakt?
vakt is a local code-security scanner. It extracts functions from a repository, scores them with DOM-0.8B, and ranks them for further investigation. Each function receives a severity score and scores for 18 CWE families.
Use it to triage an unfamiliar codebase, focus a code review, check changes in CI, or give a coding agent a security check through MCP. It does not generate patches or prove that a vulnerability is exploitable. Review flagged code in context; a clean report is not a guarantee that code is secure.
Source code is scored on your machine using Metal on Apple Silicon, CUDA 13 on supported NVIDIA hardware, or a Linux CPU.
Requirements
- macOS on Apple Silicon, or Linux on amd64/arm64 with glibc 2.35 or newer.
- Access to the gated DOM-0.8B model on Hugging Face. Request access on the model page before downloading.
- A Hugging Face token or an existing
hf auth loginsession for the model download.
vakt is a native binary. Node.js and npx are not required. See the source repository for licensing and release details.
Install
The installer selects the backend for your machine:
curl -fsSL https://get.vaktex.com/oss-vakt | sh The default installation directory is ~/.local/bin. Make sure it is on your PATH if your shell cannot find vakt.
Download the model
If you have the Hugging Face CLI installed, sign in and download the model:
hf auth login
vakt summon Alternatively, supply HF_TOKEN through your environment before running vakt summon. The model download is approximately 1.5 GB. Hugging Face credentials are for downloading the weights; scanning runs locally.
First scan
Run from your project directory:
vakt . Or pass a path explicitly:
vakt patrol ./repo The report ranks functions at or above the severity threshold, which defaults to 0.5. To save a JSON report and then inspect its first finding:
vakt . --format both
vakt show 1 A completed scan exits with 1 when a function meets the failure threshold. This indicates a finding, not a scanner error. See CLI usage for output formats and exit codes.
Next steps
- CLI usage: scan scope, thresholds, reports, and exit codes.
- Configuration: model downloads, cache, and device selection.
- Coding agents: let an agent inspect findings through MCP.
- Integrations: MCP configuration and GitHub Actions.
- Vex: the separate security workflow language and module reference.