Observed arrival · 2026-09-02
SecHelix Makes Security Findings Prove Themselves
An open-source AppSec agent skill that investigates security signals, independently challenges findings, and tests whether fixes hold.
Field notes
The workflow begins by modeling identities, entry points, stores, trust boundaries, and role-object actions rather than immediately ranking scanner output. Its evidence console distinguishes Verified, Refuted, and Incomplete states, while the example SHX-AUTHZ-L02-DEMO finding records a confirmed verifier, a passing regression, and a passing release gate. The page names 17 JSON contracts and 15 tool adapters, including Semgrep, CodeQL, Trivy, Playwright, ZAP, and Nuclei.
Observed signals
Read the marks
Editorial observations of this landing page, not a rating.
One card from the complete issue