Mosca is a tool that checks code for poor security practices akin to using grep against it for static analysis.