about
An Autonomous Agentic Secure Code Review for Immature Vulnerabilities Detection (arxiv.org)
2 points by wslh 187 days ago | hide | past | pdf | discuss on HN

In plain words: A code-review assistant that browses code like a developer and consults a built-in store of security knowledge to flag flaws before they appear. It produced at least 153% more comments correct in location, flaw type, and relevance than static AI reviewers and standard scanners.

Abstract · AgenticSCR: An Autonomous Agentic Secure Code Review for Immature Vulnerabilities Detection

Secure code review is critical during pre-integration, where Atlassian developers rely on lightweight analysis tools, while deep security assessment is deferred to later stages, delaying feedback and increasing remediation costs. Existing static analyzers are often noisy and struggle with context-dependent or partially manifested vulnerabilities, while static large language model (LLM) reviewers are constrained by context windows and lack tool interaction. Agentic AI, which combines LLMs with code navigation, shows promise; however, its effectiveness for early-stage secure code review remains underexplored. We present AgenticSCR, an agentic secure code reviewer augmented with security-focused semantic memory that grounds reasoning in structured security knowledge to detect vulnerabilities before they fully manifest. AgenticSCR achieves at least 153% relative improvement in generating comments with correct localization, vulnerability type, and relevance over static LLM baseline, multi-agent reviewer, and SAST tools. In a shadow deployment, 54% of its comments were validated by security engineers for developer reporting, demonstrating practical utility while underscoring the difficulty of the task. These findings position the security-focused semantic memory as a promising direction for agentic secure code review, enabling early-stage vulnerability identification. Our approach builds an important step toward reliable localization, detection, and explanation in shift-left security practices

Wachiraphan Charoenwet, Kla Tantithamthavorn, Patanamon Thongtanunam, Hong Yi Lin, Minwoo Jeong, Ming Wu
arXiv:2601.19138 · cs.CR, cs.AI, cs.LG, cs.SE · submitted Jan 27, 2026 · updated Aug 3, 2026
abstract · pdf · html · Accepted at the 41st IEEE/ACM International Conference on Automated Software Engineering (ASE'26 Industry-Track)

add comment on HN