Skip to content
CAI
Software that uses CAICheck a score

syntaxsecure-group/slackbot

52.0

Adequate · 22 September 2026

287

lines of production code

Python

primary language

6

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

GuardAgent is an autonomous security scanning tool that monitors GitLab for code changes and analyzes code diffs for vulnerabilities using an AI model. Built with FastAPI and the Slack Bolt SDK, it operates as a ChatOps agent that integrates with Slack to fetch code diffs and search Slack history. The system is containerized and includes a Model Context Protocol server to expose its scanning capabilities.

Features

Initial release of GuardAgent, an autonomous Slack-based security scanning tool

The repository introduces GuardAgent, a ChatOps security tool that monitors GitLab for code changes and uses an AI model (Gemini 2.5 Flash) to analyze code diffs for vulnerabilities. The application is built with FastAPI and the Slack Bolt SDK, featuring a Model Context Protocol (MCP) server that exposes tools for fetching code diffs and searching Slack history. The release includes the core application logic, a Dockerfile for containerization, and a comprehensive README detailing the system architecture and setup instructions.

(repo-wide) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 47 → 52 (+5.1)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 100 → 100 (+0.0)
  • Architecture 69 → 69 (+0.0)
  • Maturity 54 → 57 (+3.7)
  • Readiness 26 → 33 (+7.7)
  • Security 82 → 88 (+5.7)

Resolved (7)

  • Coverage not included — suite not readable by the collector
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • Medium IaC: CKV_DOCKER_3 (Dockerfile)
  • No exposed public API
  • Test reliability not included
  • early-stage repository — too little history to judge knowledge freshness
  • single-maintainer — knowledge-concentration (bus factor) risk

New (6)

  • Dependency hygiene PARTLY measured — Python dependencies read, no exact pin to grade for currency
  • Documentation: no installation or build instructions (README.md)
  • Documentation: no usage examples (README.md)
  • Medium IaC: WD-DOCKER-0003 (Dockerfile)
  • Medium IaC: WD-DOCKER-0010 (Dockerfile)
  • No ADRs found

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

syntaxsecure-group/slackbot was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 22 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 9fa708b365bd4bb8f3e0156291c81528c6ba0dbe — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-821afab8930d.