Sign in

Copper Sun Brass Coders

@coppersun.dev
20 followers 62 following 149 posts
PostsRepliesMedia
Copper Sun Brass Coders @coppersun.dev · 6m
Veracode: 45% of AI code ships an OWASP Top 10 flaw. CodeRabbit: 1.7x more issues per PR. USENIX: ~20% of AI-suggested packages don't exist. The data is clear. BrassCoders catches what AI coders miss before merge. Read more → brss.fyi/v2l5
brss.fyi
Is AI-Generated Code Buggier? The 2025-26 Data
Sourced: Veracode found 45% of AI code carries an OWASP Top 10 flaw, CodeRabbit measured 1.7x more issues per PR, and ~20% of AI-suggested packages don't exist.
000
Copper Sun Brass Coders @coppersun.dev · 02/10/2026
Vibe coding ships fast. So do the O(N²) loop, hardcoded secret, and hallucinated import. BrassCoders catches all four bug classes in 30 seconds. pip install brasscoders → brss.fyi/kdj2
brss.fyi
Vibe Coding Without the Regrets: The Safety Net
Vibe coding ships fast. The O(N²) loop, the hardcoded secret, the hallucinated import — they ship too. BrassCoders catches all four bug classes in 30 seconds.
000
Copper Sun Brass Coders @coppersun.dev · 30/09/2026
All 12 scanners run free. Paid ranks findings, not detects them. Stay free if 300 deduplicated findings fit your workflow. Upgrade to $12/dev/month when volume becomes the bottleneck. Start here → brss.fyi/8iv3
brss.fyi
BrassCoders OSS Core vs Paid: When to Upgrade
All 12 scanners are free in the OSS core; Paid adds ranking, not detection. The honest line on when free is enough and when $12/dev/month pays off.
001
Copper Sun Brass Coders @coppersun.dev · 28/09/2026
BrassCoders OSS finds all bugs; Paid ranks them. 12 scanners run free. A typical 1500+ raw findings becomes 300 after dedup, then 50-80 after ranking. $12/dev/month. Read more → brss.fyi/14vc
brss.fyi
What BrassCoders Paid's Enrichment Actually Does
The OSS core finds everything; the Paid plan ranks it. In one published case study, BrassCoders Paid took a scan from 2,470 raw findings to 217 after heuristic reduction to 22 after enrichment, for $12 per developer per month.
000
Copper Sun Brass Coders @coppersun.dev · 25/09/2026
AI writes as much JavaScript and TypeScript as Python. BrassCoders now scans .js/.ts/.jsx/.tsx files in the same pass—catching secrets and security patterns with a real Babel parser, not regexes. Mixed repos, one command. Read more → brss.fyi/1s8q
brss.fyi
Scanning AI-Generated JavaScript and TypeScript
BrassCoders runs a Babel-based JavaScript and TypeScript scanner on .js and .ts files automatically, catching secrets and security patterns alongside Python.
020
Copper Sun Brass Coders @coppersun.dev · 23/09/2026
AI assistants drop real names, emails, SSNs into test fixtures. Some synthetic, some memorized from training data. BrassCoders flags PII-shaped strings before they hit your repo. Redacted at scan time—safe to hand to Claude Code or Cursor. Read more → brss.fyi/twqq
brss.fyi
How BrassCoders Flags PII in AI-Generated Code
AI assistants drop real-looking names, emails, and SSNs into fixtures and stubs. BrassCoders flags PII-shaped strings in source before they reach a shared repo.
000
Copper Sun Brass Coders @coppersun.dev · 22/09/2026
1 in 5 AI-generated SQL snippets ships a SQL injection hole, per Veracode's 2025 test of 100+ models. A 2022 study put Copilot's rate at 37%. Bandit's B608 check catches string-built SQL before it merges, one of 12 scanners in brasscoders. Read more → brss.fyi/116u
brss.fyi
SQL Injection in AI-Generated Code, by the Numbers
Veracode found 1 in 5 AI-generated SQL snippets still vulnerable, and a 2022 study put Copilot's SQL injection rate at 37%. The numbers, and how to catch it.
000
Copper Sun Brass Coders @coppersun.dev · 22/09/2026
AI-generated tests can hit 80% coverage on toy benchmarks and under 2% on real code. Coverage counts execution, not verification. A test that asserts nothing raises coverage as much as one that checks everything. Catch what your AI coder misses → brss.fyi/1p0o
brss.fyi
Will Your AI Write Tests That Catch Real Bugs?
AI test generators hit 80% coverage on toy benchmarks and under 2% on real code. Coverage counts execution, not verification. The numbers, and the real check.
000
Copper Sun Brass Coders @coppersun.dev · 21/09/2026
BrassCoders bundles six open-source scanners — Bandit, Pylint, Pyre/Pysa, Semgrep, ast-grep, detect-secrets — and runs them in one pass. One install, one ranked YAML output, no config sprawl. brss.fyi/nlnj
brss.fyi
The Six OSS Scanners BrassCoders Runs in One Pass
BrassCoders bundles Bandit, Pylint, Pyre/Pysa, Semgrep, ast-grep, and detect-secrets into one scan: one install, one ranked YAML, no six-tool config.
000
Copper Sun Brass Coders @coppersun.dev · 18/09/2026
AI assistants hardcode realistic API keys into example code. BrassCoders bundles detect-secrets and adds custom patterns for 20+ credential types—OpenAI, Anthropic, SendGrid, and more. Redacted at scan time, never transmitted. pip install brasscoders → brss.fyi/10z3
brss.fyi
How BrassCoders Catches Hardcoded Secrets in AI Code
AI assistants hardcode realistic-looking API keys into example code. BrassCoders bundles detect-secrets and adds custom formats, covering 20+ credential types.
000
Copper Sun Brass Coders @coppersun.dev · 17/09/2026
BrassCoders now catches all 11 documented vulnerabilities in OWASP PyGoat, up from 7 in May. SQL injection, insecure deserialization, command injection, and eval() abuse all now flagged at the correct file and line. Pinned commit, reproducible scan. Read more → brss.fyi/16di
brss.fyi
What BrassCoders Catches in OWASP PyGoat
A real scan of OWASP's intentionally-vulnerable PyGoat app: BrassCoders now catches all 11 documented findings, including 4 gaps closed since the May baseline.
000
Copper Sun Brass Coders @coppersun.dev · 16/09/2026
AI assistants write O(N²) loops that pass tests and crawl at scale. BrassCoders flags four patterns—string concatenation, list.insert(0), nested-loop joins, unbounded reads—that Bandit and Semgrep miss. Deterministic, not profiled. Catches them before merge. Read more → brss.fyi/tpqt
brss.fyi
How BrassCoders Catches Slow AI-Generated Code
AI assistants write O(N²) loops that pass every test and crawl at scale. BrassCoders flags all four patterns where Bandit and Semgrep catch none.
000
Copper Sun Brass Coders @coppersun.dev · 14/09/2026
AI coders hallucinate imports. brasscoders scan --check-package-hallucination catches them before they ship. One flag flags packages that don't exist on PyPI—the only OSS check that calls the network. Typosquatters are waiting. Read more → brss.fyi/1d7u
brss.fyi
When AI Invents Libraries: Detecting Hallucinated Imports
AI coding assistants confidently generate imports of packages that don't exist on PyPI or npm. The pattern is documented, the supply-chain risk is real, and the detection is straightforward — here is how it works.
010
Copper Sun Brass Coders @coppersun.dev · 11/09/2026
BrassCoders OSS core makes zero network calls. Paid plan sends one request: redacted findings + project signature. Never raw source code. Verify it yourself. Read more → brss.fyi/qaeg
brss.fyi
What BrassCoders Sends to Its Servers (And What It Doesn't)
BrassCoders scans run entirely on your machine by default. The Paid plan adds one network call to our gateway with already-redacted findings, never raw source code. Here is every byte that leaves your machine.
000
Copper Sun Brass Coders @coppersun.dev · 09/09/2026
Scan a 500-line AI PR in 10 min. Run brasscoders locally, pipe the ranked YAML to Claude Code or Cursor, walk each finding to a diff. Reviewer time stays flat whether the PR is 100 or 1000 lines. Read more → brss.fyi/1jqy
brss.fyi
How to Triage a 500-Line AI Pull Request in 10 Minutes
A worked example of BrassCoders plus an AI assistant doing real PR review work. Scan locally, hand the ranked output to Claude Code or Cursor, walk each finding to a diff. Total reviewer time stays roughly constant regardless of diff size.
000
Copper Sun Brass Coders @coppersun.dev · 07/09/2026
AI assistants leak secrets in generated config files and test fixtures. BrassCoders detects 20+ canonical formats (AWS keys, GitHub tokens, OpenAI creds, PEM keys, etc.) plus high-entropy fallback. Catch what your AI coder misses → brss.fyi/80nq
brss.fyi
The Secrets Your AI Assistant Might Leak (And How to Catch Them)
AI coding assistants embed credentials in generated config files, example scripts, and test fixtures more often than developers expect. The detection pattern is entropy plus format matching — here is what BrassCoders scans for and why.
010
Copper Sun Brass Coders @coppersun.dev · 06/09/2026
An AI wrote (a+)+$ in half a second. That shape hung Cloudflare's whole network for 27 minutes in 2019, and it's already landed CVEs in ajv and minimatch. Semgrep catches it before merge. Copper Sun Brass bundles it as one of 12 scanners. Read more → brss.fyi/1f4d
brss.fyi
Will Your AI Write A Regex That Hangs Your Server?
Catastrophic backtracking turns one crafted input into a denial-of-service attack: real npm advisories and how to catch it before it ships.
000
Copper Sun Brass Coders @coppersun.dev · 05/09/2026
PyYAML's yaml.load carried a 9.8 CVSS CVE. PyTorch's torch.load(weights_only=True), called safe in its own docs, carried a 9.3 CVE in 2025. BrassCoders flags pickle.load and unsafe yaml.load on every scan. Read more → brss.fyi/11ia
brss.fyi
The CVE Record on Insecure Deserialization in AI Python Code
PyYAML's yaml.load carried a CVSS 9.8 CVE. PyTorch's torch.load carried one at 9.3, in 2025, in a flag documented as safe. Here is the actual track record.
000
Copper Sun Brass Coders @coppersun.dev · 05/09/2026
Your AI coding assistant can reproduce license-encumbered training data. GitHub's own data shows Copilot matches public code in under 1% of suggestions. A federal lawsuit over this exact question is still unresolved since 2022. Read more → brss.fyi/13at
brss.fyi
AI Code License Risk From Training-Data Memorization
AI coding assistants can reproduce license-encumbered training data. Here is what the memorization research, GitHub's own data, and an active lawsuit say.
000
Copper Sun Brass Coders @coppersun.dev · 05/09/2026
OWASP finds broken access control in 94% of tested apps. Its API-specific twin, BOLA, drives 27% of real attack traffic per Salt Labs. No scanner can verify an ownership check without knowing your data model. Here's what BrassCoders can actually flag. Read more → brss.fyi/1m4d
brss.fyi
IDOR and Access Control in AI APIs, by the Numbers
OWASP ranks broken access control the top web risk and BOLA the top API risk. Real prevalence and attack data, and what BrassCoders can honestly flag.
000
Copper Sun Brass Coders @coppersun.dev · 04/09/2026
BrassCoders Paid launches today. $12/dev/month adds AI-powered semantic dedup and relevance ranking—turns 1500+ raw findings into ~300 actionable ones. The OSS core (12 deterministic scanners) stays free forever. Read more → brss.fyi/xhkq
brss.fyi
BrassCoders Paid is live: $12/dev/month for AI-powered noise reduction
BrassCoders Paid is now generally available. $12/dev/month adds AI-powered semantic dedup, cluster sizing, and rank-by-relevance against your project signature. The OSS core stays free forever.
000
Copper Sun Brass Coders @coppersun.dev · 02/09/2026
BrassCoders CLI is now open source on GitHub under Apache 2.0. Audit 12 deterministic scanners, fork the detection logic, or contribute improvements. Full repo: CopperSunDev/brasscoders. pip install brasscoders → brss.fyi/9m5g
brss.fyi
BrassCoders Is Now Open Source on GitHub
The full BrassCoders CLI is open source on GitHub under Apache 2.0. 12 scanners, source-auditable detection, contributions welcome. Repo at CopperSunDev/brasscoders.
000
Copper Sun Brass Coders @coppersun.dev · 31/08/2026
AI-generated code drove 2.74× more CVEs in Q1 2026 (6 in January → 35 in March). The curve accelerates. Most teams' detection layers weren't built for this. Deterministic scanning catches what AI coders structurally miss. Read more → brss.fyi/1vdw
brss.fyi
The Q1 2026 AI-Code CVE Reckoning
AI-generated code drove a 2.74× CVE increase in Q1 2026 — from 6 AI-attributed CVEs in January to 35 in March alone. A reading of what the data says about where deterministic detection needs to go.
000
Copper Sun Brass Coders @coppersun.dev · 31/08/2026
Your AI assistant wrote the bug. Its own patch check isn't real verification: the same model can sample a false all-clear. BrassCoders scans deterministically, your assistant patches, then a re-scan confirms the pattern is gone. Read more → brss.fyi/wrkb
brss.fyi
Scan, Patch, Re-Scan: Verifying AI Bug Fixes
BrassCoders closes the loop on AI-written bugs: scan for the finding, hand it to your assistant for a patch, then re-scan to confirm the fix deterministically.
000
Copper Sun Brass Coders @coppersun.dev · 30/08/2026
96 package names, one frontier AI model, checked live against PyPI. 95 real. 1 invented, lowercase and hyphenated, indistinguishable from the rest until you query the registry. Published research puts the blended rate at 19.7% across 16 models. It's never zero. Read more → brss.fyi/cqsv
brss.fyi
AI Package Hallucination Rate: 96 Names Checked On PyPI
BrassCoders ran a first-party probe: 96 package names a frontier AI model suggested for Python tasks, checked live against PyPI. 95 existed; 1 didn't.
010
Copper Sun Brass Coders @coppersun.dev · 30/08/2026
Q3 2026 data point: 45% of AI-generated code samples ship an OWASP Top 10 flaw. AI-assisted PRs carry 1.7x more issues than human-only ones. Nearly 1 in 5 AI-recommended packages doesn't exist. BrassCoders catches the structural share before merge. Read more → brss.fyi/ot0t
brss.fyi
AI Code Defect Rates: The Q3 2026 Data Report
A dated, sourced snapshot of AI-generated-code defect and security rates for Q3 2026: 45% OWASP flaws, 1.7x issues per PR, 19.7% phantom packages. Refreshed quarterly.
000
Copper Sun Brass Coders @coppersun.dev · 30/08/2026
Wire a Claude Code hook to run brasscoders scan on every edit. .brass/ai_instructions.yaml stays current, Claude Code reads it as context, and you stop pasting scanner output into chat. One block in .claude/settings.json. Free, Apache 2.0 OSS core → brss.fyi/67hc
brss.fyi
Run BrassCoders Automatically in a Claude Code Hook
Wire a Claude Code hook to run brasscoders scan on every edit, so .brass/ai_instructions.yaml stays fresh and the assistant reads findings without copy-paste.
000
Copper Sun Brass Coders @coppersun.dev · 30/08/2026
A 2025 benchmark: LLM code reviewers hit 0.78-0.88 recall, beating static scanners. But precision sits at 0.72-0.78, all three models mislocate findings at the line level, and outputs vary run to run at temp zero. Great triage. Bad gate. Read more → brss.fyi/pyhp
brss.fyi
LLM Code Reviewer Reliability, by the Numbers
A 2025 benchmark puts LLM code-review recall at 0.78 to 0.88, yet the models mislocate findings and vary run to run — the numbers on why it's a weak gate.
000
Copper Sun Brass Coders @coppersun.dev · 28/08/2026
AI coding assistants reason within one file's context window. A SQL injection flowing across lib/db.ts, routes/api.ts, and lib/util/strings.ts stays invisible to the LLM. The taint path never reconstructs. The bug ships. Read more → brss.fyi/qx3z
brss.fyi
The Regression That Shouldn't Have Shipped
AI coding assistants reason within a single file's context window and miss bugs whose taint flows across three or more files. The category that ships past AI-assisted review.
000
Copper Sun Brass Coders @coppersun.dev · 26/08/2026
AI coding assistants catch logic bugs. BrassCoders catches what they miss: cross-file taint, hardcoded secrets, hallucinated imports, performance anti-patterns. Run both layers. They're complementary, not competitors. Read more → brss.fyi/4rvd
brss.fyi
Copilot Does X. BrassCoders Does Y.
AI code review and deterministic static analysis are complementary layers, not competitors. The math of running both, the hand-off prompt, and when replacing one with the other is wrong.
000
Copper Sun Brass Coders @coppersun.dev · 24/08/2026
1,500 findings = 0 findings. Nobody reads that report. Detection isn't the bottleneck—ranking is. Brasscoders ranks findings so developers fix the 30 that matter, not the 1,500 that pile up. Read more → brss.fyi/1018
brss.fyi
Your SAST Dashboard Has 1,500 Findings
A static-analysis report with 1,500 findings is functionally a report with zero findings — nobody reads it. The bottleneck is ranking, not detection.
000
Copper Sun Brass Coders @coppersun.dev · 21/08/2026
Auditors reject stochastic scanner output. They need deterministic, reproducible results tied to a commit. Brasscoders runs 12 deterministic scanners and emits audit-ready YAML your AI coding assistant can consume. Catch what your AI coder misses → brss.fyi/1az6
brss.fyi
What Your Auditor Wants From Your AI Codebase
Auditors do not accept stochastic scanner output. Deterministic, reproducible, citation-ready YAML — the audit posture an AI-augmented engineering team needs by 2026.
000
Copper Sun Brass Coders @coppersun.dev · 20/08/2026
BrassCoders has no daemon or watcher. It scans only when something calls it. Getting it on every commit means wiring it into CI on push or a git pre-commit hook, both explained here. It exits code 1 on CRITICAL findings, which is what actually gates the build. Read more → brss.fyi/1yui
brss.fyi
New Guide: Running BrassCoders on Every Commit
A new guide covers how to run BrassCoders on every commit — a CI step on push or a git pre-commit hook — and why there's no automatic watch mode. BrassCoders is a command-line scanner you invoke, not a background daemon.
000
Copper Sun Brass Coders @coppersun.dev · 19/08/2026
BrassCoders scans AI-generated code for bugs. But Copper Sun builds four other tools too: audio transcription, SEO audit, marketing campaign runner, goal coach. All five share one rule: do one job, stay out of your way, respect your data. Read more → brss.fyi/5xci
brss.fyi
The AI Tools Copper Sun Builds Besides BrassCoders
BrassCoders is one of five AI tools from Copper Sun Content and Creative. Here are the other four, and why an engineer might actually want them.
000
Copper Sun Brass Coders @coppersun.dev · 17/08/2026
Bandit caught 6 of 12 planted AI-coder bugs in our benchmark. All 6 were security issues. It caught zero performance anti-patterns. The gap isn't Bandit's fault — it's scope. Bandit finds security bugs. Performance patterns need different scanners. Read more → brss.fyi/1d5n
brss.fyi
Why Bandit Catches 50% of AI-Coder Bugs (and Which Half)
Bandit caught 6 of 12 planted bugs in BrassCoders's AI-coder benchmark — and 0 of the 4 performance anti-patterns AI coding assistants introduce most often. Here's why, and what to add alongside it.
000
Copper Sun Brass Coders @coppersun.dev · 14/08/2026
AI assistants invent package names 19.7% of the time. One hallucinated name drew 30k downloads when registered. BrassCoders flags unresolvable imports before pip install runs. Read more → brss.fyi/rk7p
brss.fyi
Catching Hallucinated Imports Before pip install
AI assistants invent package names that don't exist; one study found 19.7%. BrassCoders flags every unresolvable import before the install runs.
000
Copper Sun Brass Coders @coppersun.dev · 13/08/2026
AI models generate runnable examples with hardcoded keys. BrassCoders's SecretsScanner caught a HIGH-severity HMAC secret in AI-generated Python — confidence 0.85, impact 0.9. Two lines swapped it to os.environ.get(). Re-scan: zero credential findings. Read more → brss.fyi/9a30
brss.fyi
From HIGH to Clean: Removing a Hardcoded HMAC Key in AI-Generated Python
A real before-and-after: BrassCoders's SecretsScanner finds a hardcoded HMAC signing key in a corpus Python file. The environment variable fix, the re-scan, and why detect-secrets catches this where Bandit alone misses some cases.
000
Copper Sun Brass Coders @coppersun.dev · 12/08/2026
Static analysis catches SQL injection, misses missing auth. BrassCoders maps the exact boundary: structural patterns vs context-dependent bugs. SQL injection lives in source code; auth requirements live in specs. Neither layer replaces the other. Read more → brss.fyi/z78d
brss.fyi
What Static Analysis Cannot See: A Complete Map of the Limit
SQL injection: caught. Missing auth on a route: not caught. BrassCoders maps the precise boundary between what static analysis detects deterministically and what requires an AI assistant's context.
000
Copper Sun Brass Coders @coppersun.dev · 12/08/2026
AI coders ship the same four perf bugs daily: O(N²) concat, insert-at-zero loops, triple-nested joins, unbounded polls. BrassCoders catches all four. Bandit and Pylint catch zero. Read more → brss.fyi/jl7q
brss.fyi
Four Performance Bugs AI Coders Introduce Every Day
A walkthrough of the four AI-coder performance anti-patterns BrassCoders catches that Bandit, Pylint, and a frontier model reviewer all miss: O(N²) string concat, insert-at-zero loops, triple-nested joins, and unbounded polls.
000
Copper Sun Brass Coders @coppersun.dev · 12/08/2026
Claude Opus generated a Flask endpoint with SQL injection. BrassCoders caught it in one scan—two CRITICAL findings plus Bandit—all pointing to line 22. The fix: swap string formatting for parameterized queries. One re-scan shows both CRITICALs gone. Read more → brss.fyi/x1f5
brss.fyi
From SQL Injection to Clean: Fixing a B608 Finding in AI-Generated Flask Code
Before-and-after walkthrough: BrassCoders finds SQL injection in a corpus Flask endpoint, the parameterized fix, and what the re-scan shows — including the one Semgrep taint finding that remains.
000
Copper Sun Brass Coders @coppersun.dev · 12/08/2026
BrassCoders flags MD5 in a dedup script as CRITICAL — pattern match correct, context makes it false positive. MD5 for content fingerprinting isn't a security use. Add the file to .brassignore or use usedforsecurity=False in code you own. Read more → brss.fyi/1j3p
brss.fyi
Tuning .brassignore: Suppressing a False Positive in Three Steps
BrassCoders flags MD5 in a file-deduplication script as a CRITICAL security finding. The pattern match is correct — the context makes it a false positive. Here's the before scan, the .brassignore entry, and the after scan.
000
Copper Sun Brass Coders @coppersun.dev · 12/08/2026
SQL injection caught at commit time costs seconds. Caught in production, it costs weeks: log audit, credential rotation, compliance notification. BrassCoders catches Bandit B608 (string interpolation into SQL) at commit—free OSS core, zero network calls, under 1 second. brss.fyi/1ma6
brss.fyi
What's the Cost of a SQL Injection in AI-Generated Code?
Detection time, remediation effort, credential rotation, and incident response — framed in engineering hours, not dollar amounts. And what catching it at commit time costs instead.
000
Copper Sun Brass Coders @coppersun.dev · 11/08/2026
BrassCoders scans JavaScript and TypeScript via a Babel-based AST scanner and Semgrep. Catches eval(), innerHTML XSS, document.write(), hardcoded keys, and passwords across .js, .ts, .tsx, .mjs, .cjs files. brss.fyi/6pmk
brss.fyi
Does BrassCoders Scan Node.js and TypeScript Code?
Yes — via a dedicated Babel-based JavaScript/TypeScript scanner and Semgrep. Here's exactly what it catches and where the gap is versus the Python scanner.
000
Copper Sun Brass Coders @coppersun.dev · 11/08/2026
Two surfaces need separate questions. One: what the AI vendor does with your code (data handling). Two: what security bugs the AI generates (code output). Most evaluations cover only the first. brss.fyi/1qq6
brss.fyi
AI Coding Assistant Vendor Risk: What Your Security Team Should Ask
Evaluating an AI coding assistant for your team? Two separate surfaces require two separate question sets. Here's the checklist for both.
000
Copper Sun Brass Coders @coppersun.dev · 11/08/2026
BrassCoders catches structural race-condition markers: threading.Thread without locks, global mutable state in async functions. What it misses: asyncio races across await points with no threading call. Those need AI reasoning or asyncio-specific linters. Read more → brss.fyi/ccvo
brss.fyi
Can BrassCoders Catch Race Conditions in Async Python?
Partially. BrassCoders catches structural indicators — threading.Thread without locks, shared mutable state in async functions — but not asyncio races that leave no structural marker.
000
Copper Sun Brass Coders @coppersun.dev · 11/08/2026
brasscoders scan runs 12 static-analysis scanners on your Python project and writes findings to .brass/ai_instructions.yaml—ready for Claude Code or Cursor to read. Zero config, runs offline, no account needed. pip install brasscoders → brss.fyi/y8hd
brss.fyi
How to Run Your First BrassCoders Scan on AI-Generated Python
Step-by-step: install BrassCoders, run the scan, read the .brass/ai_instructions.yaml output, and understand what to do with the findings.
000
Copper Sun Brass Coders @coppersun.dev · 11/08/2026
AI generates code that satisfies the prompt, not the business rules it was never given. Static analysis can't catch what only your requirements document knows. Business logic bugs live above the structural layer—where tests belong. pip install brasscoders → brss.fyi/w6yu
brss.fyi
Business Logic Bugs Static Analysis Will Never Catch
AI generates code that satisfies the prompt — not the business rules it was never given. Static analysis can't catch what only your requirements document knows.
000
Copper Sun Brass Coders @coppersun.dev · 10/08/2026
AI coding assistants produce systematic blind spots—phantom imports, credential exposure, injection bugs—that conventional scanners miss. BrassCoders adds six custom detectors for these patterns. Runs in CI, free OSS core. Read more → brss.fyi/ph6m
brss.fyi
The Security Manager's Brief on AI-Generated Code Risk
A concise brief on what AI coding assistants do to your security surface, what conventional tooling misses, and what one CI step closes the gap.
000
Copper Sun Brass Coders @coppersun.dev · 10/08/2026
AI code review only works if you remember to ask. That's a conversation, not a gate. Deterministic scanners catch what your AI coder structurally misses—every build, every time. pip install brasscoders → brss.fyi/fmng
brss.fyi
An AI Reviewer Is Not a Pre-Merge Gate
Asking an AI to review your AI's code is not a quality control. It's a conversation. Here's why the distinction matters for anyone shipping AI-assisted software.
000
Copper Sun Brass Coders @coppersun.dev · 10/08/2026
Generic static analysis misses AI-generated bugs. Bandit catches 6 of 12 AI bug categories—the six it misses emerged after AI coding assistants went mainstream. Ask vendors: what's your AI-generated bug coverage in controlled testing? Can you share the methodology? brss.fyi/lmaw
brss.fyi
What to Ask a Static Analysis Vendor When Your Team Uses AI Code
Generic static analysis tools have a coverage gap specific to AI-generated code. These questions separate AI-aware tools from legacy scanners in a vendor evaluation.
000