Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
duo-agentflow-auditor — AI Code Security — four agents that catch what SAST misses in AI-generated code. Built on GitLab Duo Agent Platform. | Kitploit
Tools/GitLabGitLab/centisgood/duo-agentflow-auditor
Static AnalysisVulnerability ScannersCode AnalysisWeb SecurityDevSecOpsSecret DetectionSupply Chain SecurityMachine LearningLearning & EducationAI SecurityLabs & Practice
257 months agoNot yet reviewed
GitLab
centisgood/duo-agentflow-auditor

duo-agentflow-auditor

AI Code Security — four agents that catch what SAST misses in AI-generated code. Built on GitLab Duo Agent Platform.

View Repository

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Duo AgentFlow Auditor

AI Code Security — catching what SAST misses in AI-generated code Built on the GitLab Duo Agent Platform

License: MIT Platform AI Model Agents Detection Rules Semgrep Rules Tests Flow Schema Green Agent GitLab AI Hackathon


40-62% of AI-generated code contains security vulnerabilities. Traditional SAST catches CVEs. We catch what SAST misses — prompt injection, LLM output execution, unsafe ML deserialization.

Getting Started · Architecture · Detection Rules · Setup Guide · Implementation


The Problem

AI accelerates code generation but creates new security bottlenecks:

IssueImpact
Security reviews block MRs for hours or days7 hrs/week lost per team member
AI makes compliance management harder70% of teams report this
Compliance issues discovered after deployment76% of organizations
Traditional SAST tools miss AI-specific risksPrompt injection, LLM output-to-exec, unsafe ML deser
40-62% of AI-generated code has vulnerabilitiesNo existing tool detects AI-specific threat patterns

Source: GitLab 2025 Global DevSecOps Report

The Solution

AgentFlow Auditor — Four AI agents that catch security risks traditional SAST misses in AI-generated code. 41 detection rules including LLM prompt injection, output-to-exec, unsafe deserialization, SQL injection, SSRF, and path traversal. Posts scannable reports, generates fix patches, tracks risk drift. One @mention triggers everything.


Architecture

  Developer opens MR
        │
        ▼
  @duo-agentflow-auditor review this MR
        │
        ▼
┌───────────────────────────────────────────────────────┐
│                                                       │
│   ┌─────────────┐       ┌──────────────────┐         │
│   │   Scanner   │──────▶│    Reporter      │         │
│   │   Agent     │       │    Agent         │         │
│   │             │       │                  │         │
│   │ Read diffs  │       │ Grade risk       │         │
│   │ Match 34    │       │ Risk heatmap     │         │
│   │ rules       │       │ Post MR comment  │         │
│   │ Score risk  │       │ Create issue     │         │
│   └─────────────┘       └────────┬─────────┘         │
│                                  │                   │
│                          ┌───────┴────────┐          │
│                          │  SAFE?         │          │
│                          │  ├─ Yes ──────────────┐   │
│                          │  └─ No ───┐   │       │   │
│                          └───────────┘   │       │   │
│                                  │       │       │   │
│   ┌─────────────┐       ┌────────▼───────┘┐      │   │
│   │   Metrics   │◀──────│    Fixer        │      │   │
│   │   Agent     │       │    Agent        │      │   │
│   │             │◀──────────────────────────────┘   │
│   │ Baseline    │       │ Confidence-scored│         │
│   │ Cross-MR    │       │ patches         │         │
│   │ Green       │       │ Fix branch + MR │         │
│   │ Posture     │       │                 │         │
│   └─────────────┘       └─────────────────┘         │
│                                                       │
│            GitLab Duo Agent Platform (ambient)        │
│                                                       │
│   ┌───────────────────────────────────────────┐       │
│   │  External SAST Agent (CI/CD container)    │       │
│   │  bandit + semgrep + custom rules merge    │       │
│   └───────────────────────────────────────────┘       │
└───────────────────────────────────────────────────────┘

Agent Roster

AgentRoleToolsKey Capability
ScannerAnalyze MR diffs10 tools41 rules (26 regex + 15 Semgrep), AI-specific threat detection, vulnerability integration
ReporterPost audit reports7 toolsScannable in 10s (grade + heatmap + top 5), vulnerability linking, auto issue on DANGER
FixerGenerate code fixes8 toolsConfidence-scored patches (HIGH/MEDIUM/LOW), auto fix MR creation
MetricsTrack risk baseline6 toolsCross-MR learning, team posture, baseline drift, energy/carbon tracking
SAST ScannerExternal SASTCI/CDRuns bandit + semgrep, merges with custom rules via Python script

Features

Security Scanning

  • 41 Detection Rules — 26 regex + 15 Semgrep custom rules
  • 8 Risk Categories — From destructive commands to prompt injection
  • AI-Specific Detection — LLM prompt injection, output-to-exec, unsafe deserialization
  • Risk Scoring — 0-100 per finding (severity x context x category)
  • Grade System — SAFE / WARNING / DANGER

Automation

  • One-trigger activation — @mention or assign reviewer
  • Conditional routing — SAFE scans skip fixer, saving tokens
  • Structured MR comments — Risk tables, fix suggestions, collapsible details
  • Auto-fix generation — Code patches on a new branch
  • Issue creation — Automatic on DANGER grade

Baseline Tracking

  • Risk drift detection — Compare scans over time
  • Trend analysis — Improving / degrading / stable
  • Fix adoption rate — Track how many suggestions were applied
  • History log — JSONL append per scan

Green Metrics

  • Token tracking — Usage per scan
  • Energy estimation — kWh per scan
  • Carbon footprint — kg CO2 with real-world analogies
  • Optimization suggestions — Reduce scan scope, cache baselines

Detection Categories

Semgrep Custom Rules

15 production-grade Semgrep rules across 6 categories:

Download Tool