SecureCode AI 1.0.0
First release: a local multi-agent security audit prototype (Auditor + Architect) covering the full course assignment.
Try it
python deploy/docker/quickstart.py --demo # Docker only
python deploy/docker/quickstart.py --demo --provider local # uv + Ollama (Qwen 2.5 Coder 7B Q4_K_M)Highlights
- Auditor → Architect demo completes on local Qwen Q4_K_M and on DeepSeek: CWE-89 found, parameterized-query patch validated in an ephemeral copy, OWASP Top 10 report (
security-report.md/.html). - Tools: AST/CST for Python, JS/TS and Go, hardcoded secrets, vulnerable dependencies via OSV, 30+ CWE scanners, patch validation; unified
Evidencecontract. - Executed notebook
notebooks/securecode_demo.ipynb. - 600-case CVEfixes benchmark: hybrid (scanners + DeepSeek) held-out recall 32.8% vs Semgrep 32.5% — on par, superiority not shown; deterministic recall 25.7% after fixing tree-sitter node comparisons.
- CI: ruff, mypy (Linux + Windows), 3292 tests, secret and dependency policy.
See the attached final report and benchmark PDF, and CHANGELOG for details and limitations.