About the Project — CodeRisk Cloud Inspiration Development teams merge code dozens of times a day, but security review still happens at release time — far too late. Finding a vulnerability in production costs 100x more than finding it during development. Yet most teams skip continuous security review because the tools are broken in one of two ways: Traditional SAST tools drown engineers in false positives (>70% is common). Alert fatigue kills security culture — developers simply stop trusting the scanner. Cloud-based LLM tools are smart but force you to upload proprietary source code to third-party servers. For regulated industries, that's a non-starter. We built CodeRisk Cloud to fix both: a security AI that's actually smart enough to explain its reasoning, and local enough to keep your source code inside your own infrastructure. What it does CodeRisk Cloud is a 4-Agent AI security pipeline exposed as a REST API. Submit a GitHub repo or ZIP, and four specialized agents work together:

Agent Role What it does Agent 1 — Static Analysis Foundation AST parsing, Semgrep rules, taint analysis. Finds the obvious issues fast. Agent 2 — Semantic Analysis Intelligence Runs an LLM on local AMD GPU to understand code context, call chains, and data flow — catching logic vulnerabilities that pattern matching misses. Agent 3 — Deep Verifier Quality Gate Cross-validates Agents 1 & 2, filters false positives, queries CVE databases, scans dependencies. Agent 4 — Report Generator Output Produces JSON (structured), SARIF 2.1 (IDE-standard), and a Nutrient DWS PDF with SHA-256 digital signature (compliance-ready). Average full pipeline time: 5.4 seconds. Zero config to try: docker-compose up and you're running. How we built it Architecture: FastAPI gateway (Bearer auth + rate limiting) → Celery + Redis async queue → 4-Agent engine → multi-format reports. Local AI: Agent 2 runs LLM inference via llama.cpp on an AMD ROCm GPU. Source code never leaves the server — no third-party data-processing agreements needed. Compliance-grade reports: Nutrient DWS converts our HTML templates (Summary → Findings → Details → Recommendations → Appendix) into professional PDFs, which we sign locally with SHA-256 for tamper evidence. Developer experience: Docker Compose single-command deployment (CPU or GPU mode), GitHub Actions workflow with PR-comment integration, SARIF output that drops straight into GitHub Advanced Security / VS Code. Challenges we faced CPU vs GPU orchestration — We had to carefully split the pipeline so static analysis (Agent 1) runs on CPU in parallel with semantic analysis (Agent 2) on the GPU, without blocking the async queue. Getting the Celery task topology right took several iterations. False positive filtering — The whole point is trust. We built Agent 3 as a cross-validator that compares semantic and static findings, drops contradictions, and only reports findings that survive verification. This is what makes the tool actually usable. Graceful degradation under no-config — The demo must work even without an API key or GPU. We made PDF generation and GPU inference optional: if no Nutrient key or no GPU is present, the pipeline still runs, just skips those outputs. This kept the "zero config" promise intact. API dependency churn — Early builds had CI/tooling conflicts (uvicorn reload memory limits, health-check 503s, OpenAI-compatible payload mismatches). We resolved these by removing the reload flag, making the GPU check optional, and unifying the LLM payload format. What we learned Explainability beats raw detection. Engineers ignore alerts they don't trust. Giving each finding a verifiable reasoning chain is what moves the needle, not adding more rules. Local-first is a product differentiator, not a constraint. Running AI on the user's own GPU isn't a compromise — it unlocks compliance use cases that cloud tools simply can't serve. Ambiguity in integration is the real cost. Most of our debugging time went to payload-format mismatches between agents, not to the security logic itself. Standardizing the internal contract early would have saved days.

Built With

Share this project:

Updates

Submission history