Moolé scans what your team writes and only flags flaws an attacker can actually reach.
This endpoint fetches an invoice by id with no ownership check. It runs fine, and it lets any logged-in user read anyone else's invoice.
Any scanner can flag this line. The trouble is the thousand it flags beside it that no attacker can reach.
Moolé follows untrusted input across functions and files, from the request that carries it to the query or shell call it reaches.
A finding fires only when the input travels the whole way. Real path, real finding.
A pattern scanner flags the query blind. Moolé proves the path first, then blocks the merge and shows the fix.
Moolé runs on the diff, where it is still cheap to fix. That is most of where the 70% of noise goes.
Old SAST flags a pattern.
Moolé proves a path.