Security / Tooling · 2026
scryer
A static analysis tool for Ruby and Rails codebases that surfaces common security issues — mass assignment, unsafe SQL interpolation, insecure deserialization — and ranks them by exploitability rather than dumping an undifferentiated list.
The problem
Existing Ruby security scanners often produce long reports with little prioritization, making it hard for a team to know what to fix first, especially on a large legacy codebase.
The solution
Built a scanner on top of Ruby’s AST that pattern-matches known-risky constructs, then scores each finding using a severity model that weighs exploitability and blast radius rather than treating every match as equally urgent.
Architecture
Source files are parsed into ASTs and walked by a set of composable rule checkers. Findings are aggregated, deduplicated, and scored before being emitted as a ranked report in terminal or JSON format for CI integration.
Results
- Adopted as a pre-merge CI check in internal Rails projects
- Surfaced several previously unknown mass-assignment vulnerabilities on first run
- Ranked output reduced triage time versus prior unranked scanners