Inspiration I lose hours of valuable focus every week to repetitive, high-friction production tasks—specifically triaging stack traces, isolating breaking code, writing defensive patches, running local test runners, and managing version control PRs. Inspired by the Agents for Humans Hackathon challenge to build autonomous agents that handle routine background workloads and only surface when human judgment is needed, I created DevSecOps Ghost. It acts as an autonomous reliability engineer operating quietly in the background to handle end-to-end incident remediation.

What it does DevSecOps Ghost is an autonomous reliability agent built for the Professional Agents track that executes a full, self-healing remediation loop with zero manual intervention:

Intercepts Crash Logs: Parses stack traces (e.g., KeyError, AttributeError) to pinpoint exact failure locations.

Inspects Source Code: Uses tool calls to read context around the bugged application logic.

Applies Defensive Patches: Rewrites faulty functions with clean, defensive code while preserving existing business logic.

Sandbox Unit Testing: Spawns an isolated Python subprocess runner to execute local test suites and verify exit code 0.

Automates Git Workflow: Opens a dedicated fix branch, commits the verified patch, and opens a GitHub Pull Request for final developer approval.

How I built it Agent Orchestration: Built on the Strands Agents SDK (strands-agents) using modular tool decorators (@tool) for structured ReAct (Reason + Act) loop execution.

LLM Engine: Powered by Google Gemini 3.6 Flash (google-genai SDK v1) for rapid tool calling and root-cause analysis.

Verification Runner: Developed a custom Python subprocess sandbox to isolate and execute test suites before pushing code.

Version Control Integration: Integrated PyGithub and custom SSH key routing for automated branch creation and Pull Request deployment.

Challenges I ran into SDK Model Aliases: Navigating API model transition updates across SDK versions to target gemini-3.6-flash reliably.

Rate Limit Handling: Managing API throughput limits gracefully by building fallback execution handling into the Strands Agent loop.

Workstation Auth Isolation: Configuring repository-isolated SSH keys on a shared machine to ensure git operations executed under the project identity without disturbing global workstation credentials.

Accomplishments that I'm proud of Achieving a 100% verified autonomous execution loop: moving from raw crash log ➡️ file inspection ➡️ defensive patch ➡️ sandbox test pass (exit code 0) ➡️ automated GitHub PR creation.

Designing a clean, modular tool architecture using the Strands Agents SDK that cleanly separates diagnosis, patching, verification, and deployment.

What I learned How to leverage the Strands Agents SDK to orchestrate multi-step autonomous tool loops effectively.

The importance of deterministic verification (sandbox execution) before allowing an AI agent to execute external side effects like git commits and PR creations.

How to manage multi-account Git and SSH configurations safely in automated developer workflows.

What's next for DevSecOps Ghost AWS Cloud Integration: Adding native webhooks for AWS CloudWatch alerts and integrating Amazon Bedrock / AgentCore for production deployment.

Automated Security Scanning: Incorporating static application security testing (SAST) tools into the sandbox verification step before creating PRs.

Interactive Approvals: Integrating Slack and Teams notification bots so human engineers can approve or reject generated PRs directly from chat.

What it does

How we built it

Challenges we ran into

Accomplishments that we're proud of

What we learned

What's next for DevSecOps Ghost

Built With

Share this project:

Updates

Submission history