Nicheloom

Market intelligence for builders — see what's gaining traction before it's crowded.

CodeDrift

static analysis for AI-generated code

Details

External ID
47260551
Source
HN
Company
—
Product
CodeDrift
Website domain
npmjs.com
Launched
March 5, 2026
Cohort
—
Upvotes
5
Upvotes percentile
0.1070110701107011
Tags
—
Fetched at
Sept. 7, 2026, 9:26 p.m.
Updated at
Sept. 7, 2026, 9:26 p.m.

Description

Hi HN,I built *CodeDrift*, a CLI tool that detects bugs commonly introduced by AI coding assistants like Copilot, Cursor and ChatGPT.Over the last year I noticed that AI tools often generate code that compiles correctly, passes linting and looks reasonable in code review but still contains subtle issues.Some common examples I kept seeing:* async `forEach` loops that never await promises * missing authorization checks (IDOR) * hallucinated dependencies that don’t exist * stack traces leaking sensitive information * request data used without validationThese bugs often slip past ESLint, TypeScript and even human reviewers because the code looks correct.CodeDrift parses the code using the TypeScript compiler API and runs a set of detectors looking for these patterns.Example:``` async function syncProducts(items) { items.forEach(async (item) => { await updateStock(item.id); }); } ```CodeDrift output:``` CRITICAL: async forEach does not await promises Fix: use Promise.all or a for...of loop ```Another example it detects:``` Database query using user-supplied ID without authorization check → potential IDOR vulnerability ```The goal isn’t to replace tools like ESLint or TypeScript, or security scanners like Snyk. It’s meant to act as a safety layer for code generated with AI assistants.The tool runs locally, requires no cloud access, and can be tried with:``` npx codedrift ```I’d love feedback from developers who are using AI coding tools in production.

Enrichment

Theme
browser automation and scraping for AI
Vertical
Horizontal
Function
Dev tools
Audience
Developer
AI stance
AI feature
Project type
Commercial product
Normalized one-liner
static analysis for ai-generated code
Manually corrected
False

Could you build this?

Partial Basic lint rules or AST checks are easy to scaffold, but building a high-signal static analysis tool that reliably catches subtle hallucinations without high false-positive rates demands deep static analysis and compiler knowledge.

What it would actually take: Requires an AST and control-flow analysis engine (using Tree-sitter or language-specific compiler APIs in Rust or Go) paired with semantic taint tracking to detect missing error checks or invalid assumptions. Developing precise heuristic rules that differentiate genuine developer patterns from subtle AI hallucinations requires seasoned static analysis engineers.

Discussion

4 comments analyzed.

Competitors mentioned: ESLint

Competitors

Other products that read as similar to this one — 212 launches clear the similarity bar, closest 8 shown.

Attention rank: #196 of 213 (itself plus its competitors, highest first — normalized so YC and Product Hunt are compared fairly).

Launched 124 days after the earliest competitor.

Other launches for this product

Same idea, different domain

Nobody's really built a dev tools tool for Sales yet.