Minh TruongDieppe, NB, Canada

specht

Developer-first vulnerability management workbench: gathers security scans in one place, helps teams set pragmatic CI/CD rules, and lets developers query security status directly.

← All projects

Specht is an open-source security tool that brings reports from different security scanners into a single, clean workspace.

Instead of drowning developers in disconnected scanner outputs or constantly blocking deployments, Specht helps teams see what really changed, set temporary waivers for low-risk findings, and keep shipping software safely.

View the project on GitHub (minh-tg/specht) ↗

My role

Author & Lead Engineer

I started and maintain Specht as an open-source project:

  • Designed and built the Go backend, PostgreSQL data model, and developer CLI.
  • Created the normalization pipeline that maps different scanner outputs into a clean, unified schema.
  • Built the waiver rule engine so teams can grant temporary exceptions for low-risk findings without breaking builds.
  • Implemented a Model Context Protocol (MCP) server so AI coding assistants can query project security status directly from the editor.

Why I built this

The inspiration for Specht comes from my time at Accso - Accelerated Solutions GmbH, a fantastic team I had the privilege of working with in Germany. During my internship there in 2022, I worked on internal vulnerability tooling that we open-sourced as accso/SecureCheckPlus. Specht takes the lessons learned from that project and adapts them for modern CI/CD pipelines and AI coding assistants.

Modern software development uses lots of different automated security scanners. One scans code for bugs, another checks third-party packages, and another looks for accidentally committed secrets.

The problem is that every tool speaks its own format and dumps its own pile of alerts. Teams end up with alert fatigue. Either developers ignore security warnings because there are too many false alarms, or deployment pipelines fail repeatedly over minor issues that do not matter in practice.

I wanted a pragmatic tool that sits between security scanners and daily development, giving teams a clean inbox and sensible, time-bounded waiver rules.

What it does

  • One central inbox for scan results: Aggregates findings from code scanners, dependency checkers, container inspectors, and software bills of materials so teams have one source of truth.
  • Smart waivers with expiration dates: When an immediate fix is not possible or the risk is low, developers can request a time-bounded waiver (for example, 14 days) so work keeps moving while remediation is scheduled.
  • Automated checks in CI/CD: A lightweight tool runs during pull requests to verify that new code meets security policies before merging.
  • Built for AI coding assistants: Includes a native Model Context Protocol (MCP) bridge, so developers using AI assistants can ask questions like "Are there any critical issues in this repository?" directly from their editor.

Project status

Specht was started in 2026 and is an active open-source project licensed under AGPL-3.0. The core Go backend, command-line tools, database layer, and AI assistant bridge are fully functional, and a lightweight web dashboard is currently in development.

Explore the code and documentation on GitHub ↗