We are testing Jev from @typesafeai at @chainloop_dev for security classification, and the results are better than I expected.
The task is simple to explain. Go through the full commit history of a repo and ask one question per commit: was this a security fix? Then classify the vulnerability and give a confidence score. This is how we build the AI Security Context for every connected repo at Chainloop.
Why is this useful? (more in our docs, linked in the comments)
1. Find regressions and first-party vulnerabilities with adversarial analysis. Your AI agents get this context when they write code, so they know where the codebase got burned before and can hunt for unpatched variants of old bugs.
2. Measure the security hygiene of a project over time. Every confirmed fix is dated and classified, so you get an honest record: how fast you patch, how long bugs stayed exposed, which classes keep coming back.
3. Audit evidence. That record holds up in audits and security reviews, and it is a good way to judge a codebase before you depend on it.
DM me if you want to try it.
ps. Policies are next. Most of our agentic policies are the same problem anyway: here is the evidence, here is the question, give me a verdict with a reason and a score.
We ran this with great tools from our friends at @strix_ai and IronCurtain, on top of @AnthropicAI Claude Code, with proof-of-concept runs on @Kimi_Moonshot second opinions from @Zai_org GLM. @claudflare audit skill and @nvidia SkillSpector both earned their place.
We spent a month targetting AI security agents at our own code.
We are a security company. Composition analysis, vulnerability scanning and secret detection already in CI.
The agents found high-severity bugs anyway.
And one run is not enough.
Our best single run found roughly half of what several runs found together.
Fan out parallel hunters. Fan in adversarial validators.
A month of AI-driven audits against @chainloop_dev’s codebase found serious bugs that had passed review, tests, and CI.
We fixed them and documented the experiment: bit.ly/3TcSEhh#AppSec#AISecurity
this is one of the reasons why cyber-security concerns around AI get it completely wrong
human-slop code is full of so many security problems its mind blowing... most people have no idea just how bad it is
the same LLMs that can be used to find them by bad guys can be used by vendors to patch them proactively and patch them before they're exploited
A month of AI-driven audits against @chainloop_dev’s codebase found serious bugs that had passed review, tests, and CI.
We fixed them and documented the experiment: bit.ly/3TcSEhh#AppSec#AISecurity
Meet the Chainloop founders @danlishka & @migmartri
at #BlackHat2026
Ask us for a demo! We will show you how we sandbox AI agents on-prem, govern AI coding sessions, and put vulnerability triage on autopilot: our AI agents assess the risk and open the fix PR, on your terms.
If you are interested in what we are building re AI-Governance at Chainloop take a look at this article. AI adoption visibility through AI Coding Sessions and Session Alignment Scoring, enforcement through policies, compliance through controls.
chainloop.dev/blog/ai-coding…
AI coding agents are writing your code. But who's governing them?
We just shipped support for AI agent configuration and session evidence. Every instruction file, tool invocation, model used, every file changed, captured, signed, and policy-enforceable.
chainloop.dev/blog/agentic-c…
Busy week for supply chain security. I know we're all busy building. But it's about time we stop for a moment and re-evaluate our security foundations. Supply chain security should be a first-class concern, not a post-mortem talking point.
chainloop.dev/blog/litellm-s…
Last week Trivy got compromised. A security scanner, one of the most trusted in the ecosystem, quietly turned into a credential stealer. Pipelines kept running like nothing happened. We wrote about it.
chainloop.dev/blog/trivy-sup…
Chainloop is joining @chainguard_dev Commercial Builds — hardened, zero CVEs, full provenance, FIPS-ready.
Enterprises shouldn't have to choose between shipping software and trusting what's beneath it.
chainloop.dev/blog/chainloop…
A new version of Chainloop just dropped
With a new UI/UX foundation for what's to come, agentic policies and workflows support, new guardrails and security features, all of that is packed in this release.
docs.chainloop.dev/changelog
1K Followers 3K FollowingDevOps, SecOps , AI Implementation AI is more than just intel, it's your new SysAdmin. Automating workflows, securing the stack, and redefining Red/Blue teaming
8K Followers 2K FollowingCEO of @themindcompany, makers of @elevateapp (Apple's App of the Year), @balanceapp (Google's App of the Year), and @playsparkapp (just launched!)
428 Followers 940 Following"As a platform engineer, I blend tech expertise with a love for hiking, homebrewing, and an ever-curious mindset. Let's explore together!"
167 Followers 148 FollowingPaula’s husband and proud dad to Biel and Laia.
Senior Manager Infrastructure & Software Engineering at https://t.co/DRqZ7DPPMY.