Skip to content
RY

Security / Tooling · 2026

scryer

A static analysis tool for Ruby and Rails codebases that surfaces common security issues — mass assignment, unsafe SQL interpolation, insecure deserialization — and ranks them by exploitability rather than dumping an undifferentiated list.

RubyAST ParsingStatic Analysis

The problem

Existing Ruby security scanners often produce long reports with little prioritization, making it hard for a team to know what to fix first, especially on a large legacy codebase.

The solution

Built a scanner on top of Ruby’s AST that pattern-matches known-risky constructs, then scores each finding using a severity model that weighs exploitability and blast radius rather than treating every match as equally urgent.

Architecture

Source files are parsed into ASTs and walked by a set of composable rule checkers. Findings are aggregated, deduplicated, and scored before being emitted as a ranked report in terminal or JSON format for CI integration.

Results

  • Adopted as a pre-merge CI check in internal Rails projects
  • Surfaced several previously unknown mass-assignment vulnerabilities on first run
  • Ranked output reduced triage time versus prior unranked scanners