Code Scanning · SAST

The code your team writes needs a second reader.

Moolé scans what your team writes and only flags flaws an attacker can actually reach.

70%
less SAST noise in week one
3.6×
faster triage
84%
of alerts cleared as noise
01 · The problem

Working code and safe code are not the same thing.

This endpoint fetches an invoice by id with no ownership check. It runs fine, and it lets any logged-in user read anyone else's invoice.

invoices.pywritten by a coding assistant · unguarded
# GET /invoices/{invoice_id} def get_invoice(invoice_id, current_user): invoice = db.query(Invoice).filter( Invoice.id == invoice_id # no owner check ).first() return invoice # any user reads any invoice

Any scanner can flag this line. The trouble is the thousand it flags beside it that no attacker can reach.

02 · It traces the real path

From where input enters to where it turns dangerous.

Moolé follows untrusted input across functions and files, from the request that carries it to the query or shell call it reaches.

source · untrusted
request param
?id= from the caller
step
handler()
passes it along, unchecked
step
build_query()
glues it into a string
sink · dangerous
db.execute()
runs it against the database

A finding fires only when the input travels the whole way. Real path, real finding.

03 · Verdict, side by side

The same line. Two very different answers.

A pattern scanner flags the query blind. Moolé proves the path first, then blocks the merge and shows the fix.

◍ pattern scanner flag, no context
# it sees a string query query = f"SELECT * FROM invoices WHERE id = {invoice_id}" ! flagged: possible sql injection no idea if input reaches it lands in a pile of 1,000 alerts
◍ Moolé path proven
# traced source to sink tainted input reaches sink: yes → real finding, blocked on PR # the fix it opens query = "SELECT * FROM invoices" " WHERE id = %s AND owner_id = %s" db.execute(query, (invoice_id, user.id)) ✓ parameterized · ownership enforced
04 · Built for pull requests

It reviews the change, not the whole history.

Moolé runs on the diff, where it is still cheap to fix. That is most of where the 70% of noise goes.

01

Scan the PR diff

Changed lines in, verdict on the PR out.
02

Trace real data flows

Source to sink, or it does not fire.
03

Prioritize by exploitability

Reachable first. Theoretical last.
04

Automated remediation PRs

The fix arrives with the finding.

Old SAST flags a pattern.
Moolé proves a path.