1
1 Comment

Built MunaTrust to catch risky AI-generated code before it ships

I built MunaTrust because AI-generated code can look perfectly reasonable while still hiding risky mistakes.

The goal is simple: give developers a trust gate before code ships.

MunaTrust scans generated or fast-moving codebases for things like:

- exposed secrets

- suspicious browser-reachable routes

- auth gaps

- risky release blockers

- untrustworthy generated code patterns

It’s local-first, built for developer workflows, and currently available here:

https://open-vsx.org/extension/munatrust/munatrust

Also on npm:

https://www.npmjs.com/package/munatrust

Source:

https://github.com/balkanbrs/munatrust

I’d love feedback on three things:

1. Does “AI code trust” feel like a painful enough problem?

2. Is the positioning clearer as a trust scanner or as a release gate?

3. What workflow would make this most useful for you: local scan, PR review, or deploy decision?

posted toAvatar for product MunaTrust
MunaTrust
  1. 1

    “AI code trust” is a real problem, but I think “trust scanner” sounds a bit too passive.

    The sharper positioning is probably closer to a release gate for AI-generated code.

    Developers do not just need another scanner telling them something might be risky. They need a clear stop/go layer before AI-written or fast-moving code reaches production.

    The workflow I’d test first is probably local scan plus PR review, not deploy decision yet.

    Local scan gives the individual developer fast feedback. PR review makes it visible to the team before risky code gets merged. Deploy decision comes later once the tool earns enough trust to block releases.

    The strongest buyer pain is not “AI code may be bad.” It is:

    “AI-generated code can look safe enough to merge while quietly creating security and auth risk.”

    That makes MunaTrust feel less like a generic code checker and more like a safety layer for teams shipping with AI.

    Happy to put a tighter version in writing if useful. I’d map the positioning, best first developer segment, PR workflow angle, and a simple 7-day test plan.