A visual builder for AI workflows, built by a former CISO to show security designed in, not bolted on.
A TopFlow workflow that checks a repository's dependencies against the OSV.dev vulnerability database and explains what to upgrade.
| Checks | Doesn't check |
|---|---|
| Known vulnerabilities in npm, PyPI, Go and Rust dependencies, with CVE (or advisory) ID, severity and fixed version | Your own source code (no injection, XSS or authentication analysis) |
Whether the repo has a SECURITY.md and a Dependabot config |
Compliance (GDPR, SOC 2, HIPAA) |
| A 0–100 score from a fixed formula | Test coverage, CI setup or code quality |
- Findings come from OSV.dev and the score is computed in code (
lib/osv/scanner.ts). An LLM, using your own key, only writes the explanation, and it can't change the findings (why). - Runs show sample results by default. Turn on Run a real scan in the run dialog for live data. Public repos work without a key; a GitHub token raises GitHub's rate limit and allows private repos.
- No AI spending unless you ask. The report is built from the scan data. An LLM report (your own key and quota) runs only when you switch on Write the report with my AI key for that run; saved keys never turn it on.
The scanner runs on TopFlow — a privacy-first AI workflow platform built with enterprise-grade security architecture.
| Zero server-side storage | Workflows and API keys are stored only in your browser. When you run a workflow, it's sent over HTTPS to our server, used in memory for that request, and never stored or logged. |
| BYOK model | Bring your own AI provider keys, or use demo mode without any keys at all. |
| 5-layer defense | Input sanitization → HTTPS/HSTS → rate limiting → SSRF prevention → restricted code execution (built-in template code only; isolate planned) |
| Open source | MIT licensed. Audit the code, fork it, own it. |
How TopFlow compares:
| TopFlow | Other platforms | |
|---|---|---|
| Data storage | None (localStorage only) | Cloud databases |
| API keys | Your own (BYOK) | Platform-managed |
| Code export | Production TypeScript | JSON/config only |
| Vendor lock-in | None | Proprietary formats |
| Cost | Free | Monthly subscriptions |
| Built by | Former CISO | SaaS companies |
The dependency scanner is one of nine ready-to-run security workflows (plus four general-purpose ones):
All templates include demo mode, TypeScript export, and a visual workflow editor.
Try instantly (no install):
https://www.topflow.dev/builder?template=github-security-scanner&repo=YOUR_USERNAME/YOUR_REPO
Run locally:
git clone https://github.com/csupenn/topflow.git
cd topflow && pnpm install && pnpm dev
# Open http://localhost:3000Next.js 15 · React 19 · TypeScript · TailwindCSS v4 · ReactFlow · Vercel AI SDK v5 · shadcn/ui · Zustand
AI providers: OpenAI · Anthropic · Google · Groq
- Architecture Overview — System design & security model
- Security Docs — Threat model & controls
- Node Reference — All 12 node types
- AI Security Tutorials — Hands-on case studies from real hardening work (SSRF, encryption, rate limiting, LLM constraints); published at topflow.dev/blog
Security improvements, compliance workflows, new node types, and test coverage are especially welcome. See CONTRIBUTING.md.
Found a vulnerability? Please report it privately; see SECURITY.md.
License: MIT — use, modify, fork, and distribute freely.
📧 charlie@charliesu.com · 💼 LinkedIn · Issues · Discussions