L3:ai-code-security-platform · AI Wing · Hero
AI Code Security Platform
Eight scanners on every pull request, AI triage people actually read, and a fix agent that opens guarded PRs.
- Role
- Creator, sole engineer and operator: designed, directed, reviewed and shipped it with AI coding agents
- Period
- Jun 2026 to Oct 2026
Results
8 engines
Scanning engines on every pull request across a 100+ repository organization
Production GitHub App running Semgrep, Bandit, Trivy, OSV-Scanner, Grype, Gitleaks, TruffleHog and Checkov.
Verified541 PRs
Pull requests reviewed with scan results across 22 repositories
Production activity through late September 2026; about 4.9k scans and 645k findings processed.
Verified31 fix PRs
Opened by the fix agent in 7 repositories, 8 merged after human review
Every fix PR goes through human review; no higher merge rate is claimed.
Verified~9 min
Outage window to cut production over to isolated scan jobs, closing the reproduced code-execution path
Part of the 14-item isolation hardening, delivered with Contributor-level cloud rights.
Verified
Problem
A GitHub organization with 100+ repositories needed consistent security scanning on every pull request, triage people would read, and fixes safe enough to merge.
What I did
- Integrated eight open-source engines through a GitHub App, with normalizers, exploit-likelihood and known-exploited enrichment, and stable finding identity.
- Added Azure OpenAI triage, executive summaries, a merge-gate check run and a security assistant chat over a vector index.
- Built a fix agent with token-budgeted code context, region-splice patches, package-manager-resolved upgrades that never downgrade, protected-path guards and rescan validation before publishing.
- After an internal audit reproduced untrusted repository code running next to production secrets, led a 14-item hardening that moved scans into isolated, autoscaled jobs with per-job scoped tokens.
- Added Prompt Shields, secret redaction in prompts and an offline prompt-injection suite, and shipped through staging, canary revisions and health gates (13 releases in 7 days).
Architecture
- HumanDevelopersOpen pull requests
- HumanSecurity teamNext.js dashboard, Entra ID
- ExternalGitHub AppWebhooks, check runs, fix PRs
- ServiceFastAPI control planeRepo-scoped tokens, no repo code
- ServiceService BusScan and fix queues
- AIAzure OpenAITriage, fixes, Prompt Shields
- ServiceContainer Apps Jobs8 engines, isolated, KEDA-scaled
- DataCosmos DBFindings and vector index
Data flow
- Developers to GitHub App (pull request)
- GitHub App to FastAPI control plane (webhook)
- Security team to FastAPI control plane (dashboard, chat)
- FastAPI control plane sends asynchronously to Service Bus (scan, fix jobs)
- Service Bus sends asynchronously to Container Apps Jobs (KEDA trigger)
- Container Apps Jobs sends asynchronously to FastAPI control plane (results)
- FastAPI control plane to Azure OpenAI (triage, fix patches)
- FastAPI control plane to Cosmos DB (findings)
- Container Apps Jobs to GitHub App (check runs, fix PRs)
Stack
- Next.js
- FastAPI
- Azure Container Apps
- Container Apps Jobs
- KEDA
- Service Bus
- Cosmos DB
- Azure OpenAI
- Azure AI Content Safety
- GitHub Apps
- Semgrep
- Bandit
- Trivy
- OSV-Scanner
- Grype
- Gitleaks
- TruffleHog
- Checkov
- Bicep
L2 · On the journeyTechnical Consultant, Software & AI · Metrodata (PT Mitra Integrasi Informatika)