CodeDrift
static analysis for AI-generated code
Details
- External ID
- 47260551
- Source
- HN
- Company
- —
- Product
- CodeDrift
- Website domain
- npmjs.com
- Launched
- March 5, 2026
- Cohort
- —
- Upvotes
- 5
- Upvotes percentile
- 0.1070110701107011
- Tags
- —
- Fetched at
- Sept. 7, 2026, 9:26 p.m.
- Updated at
- Sept. 7, 2026, 9:26 p.m.
Description
Hi HN,I built *CodeDrift*, a CLI tool that detects bugs commonly introduced by AI coding assistants like Copilot, Cursor and ChatGPT.Over the last year I noticed that AI tools often generate code that compiles correctly, passes linting and looks reasonable in code review but still contains subtle issues.Some common examples I kept seeing:* async `forEach` loops that never await promises * missing authorization checks (IDOR) * hallucinated dependencies that don’t exist * stack traces leaking sensitive information * request data used without validationThese bugs often slip past ESLint, TypeScript and even human reviewers because the code looks correct.CodeDrift parses the code using the TypeScript compiler API and runs a set of detectors looking for these patterns.Example:``` async function syncProducts(items) { items.forEach(async (item) => { await updateStock(item.id); }); } ```CodeDrift output:``` CRITICAL: async forEach does not await promises Fix: use Promise.all or a for...of loop ```Another example it detects:``` Database query using user-supplied ID without authorization check → potential IDOR vulnerability ```The goal isn’t to replace tools like ESLint or TypeScript, or security scanners like Snyk. It’s meant to act as a safety layer for code generated with AI assistants.The tool runs locally, requires no cloud access, and can be tried with:``` npx codedrift ```I’d love feedback from developers who are using AI coding tools in production.
Enrichment
- Theme
- browser automation and scraping for AI
- Vertical
- Horizontal
- Function
- Dev tools
- Audience
- Developer
- AI stance
- AI feature
- Project type
- Commercial product
- Normalized one-liner
- static analysis for ai-generated code
- Manually corrected
- False
Could you build this?
Partial Basic lint rules or AST checks are easy to scaffold, but building a high-signal static analysis tool that reliably catches subtle hallucinations without high false-positive rates demands deep static analysis and compiler knowledge.
What it would actually take: Requires an AST and control-flow analysis engine (using Tree-sitter or language-specific compiler APIs in Rust or Go) paired with semantic taint tracking to detect missing error checks or invalid assumptions. Developing precise heuristic rules that differentiate genuine developer patterns from subtle AI hallucinations requires seasoned static analysis engineers.
Discussion
4 comments analyzed.
Competitors mentioned: ESLint
Competitors
Other products that read as similar to this one — 212 launches clear the similarity bar, closest 8 shown.
Attention rank: #196 of 213 (itself plus its competitors, highest first — normalized so YC and Product Hunt are compared fairly).
Launched 124 days after the earliest competitor.
- Vibecheck · hn · 2026-03-16 · 7 upvotes · similarity 0.55
- SharpTS · hn · 2026-01-09 · 6 upvotes · similarity 0.49
- Pure Effect · hn · 2026-06-21 · 58 upvotes · similarity 0.48
- I wrote a book · hn · 2025-12-08 · 53 upvotes · similarity 0.46
- Fallow · ph · 2026-09-18 · 2 upvotes · similarity 0.45
- Sloppylint · hn · 2025-12-05 · 19 upvotes · similarity 0.45
- Remy, an AI agent that compiles annotated Markdown into full-stack apps · hn · 2026-04-13 · 5 upvotes · similarity 0.44
- jev-code · github · 2026-09-17 · 19 upvotes · similarity 0.44
Other launches for this product
- No other launches for this product.
Same idea, different domain
Nobody's really built a dev tools tool for Sales yet.