惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

V
Visual Studio Blog
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
G
Google Developers Blog
J
Java Code Geeks
爱范儿
爱范儿
Microsoft Azure Blog
Microsoft Azure Blog
美团技术团队
人人都是产品经理
人人都是产品经理
Martin Fowler
Martin Fowler
IT之家
IT之家
博客园_首页
B
Blog RSS Feed
Google DeepMind News
Google DeepMind News
B
Blog
U
Unit 42
Apple Machine Learning Research
Apple Machine Learning Research
L
LangChain Blog
Stack Overflow Blog
Stack Overflow Blog
罗磊的独立博客
N
Netflix TechBlog - Medium
T
Tailwind CSS Blog
博客园 - 聂微东
腾讯CDC
A
About on SuperTechFans

DEV Community

Authentication Security Deep Dive: From Brute Force to Salted Hashing (With Java Examples) Why AI Systems Don’t Fail — They Drift Spilling beans for how i learn for exam😁"Reinforcement Learning Cheat Sheet" I Replaced Chrome with Safari for AI Browser Automation. Here's What Broke (and What Finally Worked) How Python Borrows Other People's Work The $40 Architecture: Processing 1 Billion API Requests with 99.99% Uptime Vibe Coding: A Workflow Guide (From Zero to SaaS) Most webhook security guides protect the wrong side. The scary part is delivery. Headless CMS for TanStack Start: Build a Blog with Cosmic EU Age Verification App "Hacked in 2 Minutes" — What Actually Happened Comfy Cloud’s delete function does not actually remove files Running AI Models on GPU Cloud Servers: A Beginner Guide Event-driven media intelligence with AWS Step Functions and Bedrock I scored 500 AI prompts across 8 quality dimensions — here's what broke How to Call Google Gemini API from Next.js (Free Tier, No Backend Needed) The Portal Protocol: Reclaiming Human Connection in the Age of AI How to Fix Your Team's Scattered Knowledge Problem With a Self-Hosted Forum Intro to tc Cloud Functors: A Graph-First Mental Model for the Modern Cloud Designing Multi-Tenant Backends With Both Ownership and Team Access I Built a Neumorphic CSS Library with 77+ Components — Here's What I Learned PostgreSQL Performance Optimization: Why Connection Pooling Is Critical at Scale Cómo construí un SaaS multi-rubro para gestionar expensas en Argentina con FastAPI + Vue 3 🚀 I Built an Ethical Hacking Scanner Tool – Open Source Project I Replaced /usage and /context in Claude Code With a Single Statusline A Pythonic Way to Handle Emails (IMAP/SMTP) with Auto-Discovery and AI-Ready Design I Collected 8.9 Million Polymarket Price Points — Here's What I Found About How Markets Really Move EcoTrack AI — Carbon Footprint Tracker & Dashboard Everyone's Using AI. No One Agrees How. 5 self-hosted ebook managers worth trying in 2026 Building Your First AI Agent with LangChain: From Chatbot to Autonomous Assistant
Angel on Your Shoulder
Nicholas Bur · 2026-05-17 · via DEV Community
Cover image for Angel on Your Shoulder

Nicholas Burnette

Gemma 4 Challenge: Build With Gemma 4 Submission

This is a submission for the Gemma 4 Challenge: Build with Gemma 4

What I Built

AOYS is a Visual Studio Code Extension created to leverage the power of a local Gemma 4 model to scan your code and return issues. Gemma is passed a directive to act as a security scanning tool, supercharged with language specific SAST rules, and instructed to view the code from an attacker's mindset to only return exploitable issues. This keeps the returned problems lean and generally free of false positives or unexploitable issues.

The extension by default connects to any Gemma model on localhost, but can be configured to run on any URL just as long as it's served by Ollama. In my demo and my recommendation, I run Gemma on another device on my local network. This way it stays local but the computations are done off your working rig. The Full Scan mode is the first time it runs on the repo which will gather all the files to scan. This takes by far the longest, however, after a full scan is complete, a cache is made of scanned files so only changed files are scanned for new or fixed problems.

The idea driving this is how do we make an easy to use scanning tool that presents problems in a way Developers want? My preference, as a developer, is:

  1. ollama run gemma4:31b
  2. install AOYS and configure the URL
  3. click Full Scan

Now it runs in the background and drops the issues into the Problems tab. Problems are how VS Code handles errors, warnings, and other info already making this the familiar interface for developers. Also, this gives you the opportunity to see the problems and click auto fix to have GH Copilot fix them for you. This keeps you in the loop on what is a security issue and how to fix it.

AOYS is an excellent entry for developers who may be new to security scans, or developers that want to get ahead of issues before pushing their code up. From what I've seen personally, Gemma does a great job at finding real issues and already has a leg up on some of the industry leading tools on the market today.

Demo

Code

AOYS — Angel on Your Shoulder

A fully local AI security scanner for VS Code. No cloud. No telemetry. No API keys. Just a local Ollama model watching your code for real exploitable vulnerabilities — while you work.

VS Code License Local Only


Support Development

Buy me a coffeehttps://buymeacoffee.com/nily


What It Does

AOYS runs your code through a local LLM (Gemma 4 by default) with an attacker's mindset. It doesn't just run pattern matching — it reasons about your code the way a red-teamer would, catching design-level vulnerabilities that static rules cannot.

It augments LLM reasoning with Semgrep's public security rule packs, giving you the best of both: rules-based precision and AI-powered depth.

Results appear directly in VS Code's Problems panel with file and line numbers — no separate dashboard, no context switching.


Features

🔒 Attacker-Mindset Analysis

Goes beyond traditional SAST. Finds exploitable vulnerabilities across categories:

  • Injection — SQL, command…

How I Used Gemma 4

I used Gemma 4 31B Dense right out of the box as well as a few of the smaller ones. If you're running this on the same machine you develop on, then I would recommend a smaller model. One of the cool things about this extension is it auto detects the strongest Gemma model running, but you can hover over the AOYS badge in the lower right and select whichever model you want to use. I did not see any difference at all between 31B and E4B for the small repo I tested it on, but results will likely be noticeable on larger, more complex code bases.