Skip to content

← Back to the Labs

L3:ai-code-security-platform · AI Wing · Hero

AI Code Security Platform

Eight scanners on every pull request, AI triage people actually read, and a fix agent that opens guarded PRs.

Role
Creator, sole engineer and operator: designed, directed, reviewed and shipped it with AI coding agents
Period
Jun 2026 to Oct 2026

Results

  • 8 engines

    Scanning engines on every pull request across a 100+ repository organization

    Production GitHub App running Semgrep, Bandit, Trivy, OSV-Scanner, Grype, Gitleaks, TruffleHog and Checkov.

    Verified
  • 541 PRs

    Pull requests reviewed with scan results across 22 repositories

    Production activity through late September 2026; about 4.9k scans and 645k findings processed.

    Verified
  • 31 fix PRs

    Opened by the fix agent in 7 repositories, 8 merged after human review

    Every fix PR goes through human review; no higher merge rate is claimed.

    Verified
  • ~9 min

    Outage window to cut production over to isolated scan jobs, closing the reproduced code-execution path

    Part of the 14-item isolation hardening, delivered with Contributor-level cloud rights.

    Verified

Problem

A GitHub organization with 100+ repositories needed consistent security scanning on every pull request, triage people would read, and fixes safe enough to merge.

What I did

  • Integrated eight open-source engines through a GitHub App, with normalizers, exploit-likelihood and known-exploited enrichment, and stable finding identity.
  • Added Azure OpenAI triage, executive summaries, a merge-gate check run and a security assistant chat over a vector index.
  • Built a fix agent with token-budgeted code context, region-splice patches, package-manager-resolved upgrades that never downgrade, protected-path guards and rescan validation before publishing.
  • After an internal audit reproduced untrusted repository code running next to production secrets, led a 14-item hardening that moved scans into isolated, autoscaled jobs with per-job scoped tokens.
  • Added Prompt Shields, secret redaction in prompts and an offline prompt-injection suite, and shipped through staging, canary revisions and health gates (13 releases in 7 days).

Architecture

  1. HumanDevelopersOpen pull requests
  2. HumanSecurity teamNext.js dashboard, Entra ID
  3. ExternalGitHub AppWebhooks, check runs, fix PRs
  4. ServiceFastAPI control planeRepo-scoped tokens, no repo code
  5. ServiceService BusScan and fix queues
  6. AIAzure OpenAITriage, fixes, Prompt Shields
  7. ServiceContainer Apps Jobs8 engines, isolated, KEDA-scaled
  8. DataCosmos DBFindings and vector index

Data flow

  • Developers to GitHub App (pull request)
  • GitHub App to FastAPI control plane (webhook)
  • Security team to FastAPI control plane (dashboard, chat)
  • FastAPI control plane sends asynchronously to Service Bus (scan, fix jobs)
  • Service Bus sends asynchronously to Container Apps Jobs (KEDA trigger)
  • Container Apps Jobs sends asynchronously to FastAPI control plane (results)
  • FastAPI control plane to Azure OpenAI (triage, fix patches)
  • FastAPI control plane to Cosmos DB (findings)
  • Container Apps Jobs to GitHub App (check runs, fix PRs)

Stack

  • Next.js
  • FastAPI
  • Azure Container Apps
  • Container Apps Jobs
  • KEDA
  • Service Bus
  • Cosmos DB
  • Azure OpenAI
  • Azure AI Content Safety
  • GitHub Apps
  • Semgrep
  • Bandit
  • Trivy
  • OSV-Scanner
  • Grype
  • Gitleaks
  • TruffleHog
  • Checkov
  • Bicep

L2 · On the journeyTechnical Consultant, Software & AI · Metrodata (PT Mitra Integrasi Informatika)