AI Code Security — four agents that catch what SAST misses in AI-generated code. Built on GitLab Duo Agent Platform.
AI Code Security — catching what SAST misses in AI-generated code Built on the GitLab Duo Agent Platform
40-62% of AI-generated code contains security vulnerabilities. Traditional SAST catches CVEs. We catch what SAST misses — prompt injection, LLM output execution, unsafe ML deserialization.
Getting Started · Architecture · Detection Rules · Setup Guide · Implementation
AI accelerates code generation but creates new security bottlenecks:
| Issue | Impact |
|---|---|
| Security reviews block MRs for hours or days | 7 hrs/week lost per team member |
| AI makes compliance management harder | 70% of teams report this |
| Compliance issues discovered after deployment | 76% of organizations |
| Traditional SAST tools miss AI-specific risks | Prompt injection, LLM output-to-exec, unsafe ML deser |
| 40-62% of AI-generated code has vulnerabilities | No existing tool detects AI-specific threat patterns |
Source: GitLab 2025 Global DevSecOps Report
AgentFlow Auditor — Four AI agents that catch security risks traditional SAST misses in AI-generated code. 41 detection rules including LLM prompt injection, output-to-exec, unsafe deserialization, SQL injection, SSRF, and path traversal. Posts scannable reports, generates fix patches, tracks risk drift. One @mention triggers everything.
Developer opens MR
│
▼
@duo-agentflow-auditor review this MR
│
▼
┌───────────────────────────────────────────────────────┐
│ │
│ ┌─────────────┐ ┌──────────────────┐ │
│ │ Scanner │──────▶│ Reporter │ │
│ │ Agent │ │ Agent │ │
│ │ │ │ │ │
│ │ Read diffs │ │ Grade risk │ │
│ │ Match 34 │ │ Risk heatmap │ │
│ │ rules │ │ Post MR comment │ │
│ │ Score risk │ │ Create issue │ │
│ └─────────────┘ └────────┬─────────┘ │
│ │ │
│ ┌───────┴────────┐ │
│ │ SAFE? │ │
│ │ ├─ Yes ──────────────┐ │
│ │ └─ No ───┐ │ │ │
│ └───────────┘ │ │ │
│ │ │ │ │
│ ┌─────────────┐ ┌────────▼───────┘┐ │ │
│ │ Metrics │◀──────│ Fixer │ │ │
│ │ Agent │ │ Agent │ │ │
│ │ │◀──────────────────────────────┘ │
│ │ Baseline │ │ Confidence-scored│ │
│ │ Cross-MR │ │ patches │ │
│ │ Green │ │ Fix branch + MR │ │
│ │ Posture │ │ │ │
│ └─────────────┘ └─────────────────┘ │
│ │
│ GitLab Duo Agent Platform (ambient) │
│ │
│ ┌───────────────────────────────────────────┐ │
│ │ External SAST Agent (CI/CD container) │ │
│ │ bandit + semgrep + custom rules merge │ │
│ └───────────────────────────────────────────┘ │
└───────────────────────────────────────────────────────┘
| Agent | Role | Tools | Key Capability |
|---|---|---|---|
| Scanner | Analyze MR diffs | 10 tools | 41 rules (26 regex + 15 Semgrep), AI-specific threat detection, vulnerability integration |
| Reporter | Post audit reports | 7 tools | Scannable in 10s (grade + heatmap + top 5), vulnerability linking, auto issue on DANGER |
| Fixer | Generate code fixes | 8 tools | Confidence-scored patches (HIGH/MEDIUM/LOW), auto fix MR creation |
| Metrics | Track risk baseline | 6 tools | Cross-MR learning, team posture, baseline drift, energy/carbon tracking |
| SAST Scanner | External SAST | CI/CD | Runs bandit + semgrep, merges with custom rules via Python script |
Security Scanning
|
Automation
|
Baseline Tracking
|
Green Metrics
|
15 production-grade Semgrep rules across 6 categories: