๐ก Inspiration In today's fast-paced development cycles, security is often treated as an afterthought. Developers push code rapidly, and security teams struggle to keep up, leading to critical vulnerabilities slipping into production. Even when vulnerabilities are found, the output from traditional security tools is often dense, confusing, and lacks actionable steps for developers.
We wanted to bridge this gap. Our inspiration was to build a true DevSecOps platform that doesn't just "find" bugs, but actively helps developers fix them by visualizing the attack chain and using AI to write the patch code. We wanted to make enterprise-grade security accessible, automated, and developer-friendly.
๐ What it does Secura is an autonomous, AI-powered Web Security Auditor and CI/CD integration tool.
Comprehensive Scanning: It scans web applications for missing HTTP headers, SSL/TLS weaknesses, outdated tech-stack CVEs, and runs deep Nuclei templates. Interactive Attack Path: Instead of a boring list of bugs, Secura generates an interactive Node Graph (using ReactFlow) that visualizes the "Kill Chain"โshowing exactly how an attacker might chain vulnerabilities to compromise your system. AI-Powered Remediation (RAG + Gemini): We use ChromaDB to retrieve real OWASP documentation and feed it into Google's Gemini 1.5 Flash AI. It acts as your personal cybersecurity expert, providing exact copy-paste code to fix your issues. Automated CI/CD GitHub Action: Secura isn't just a dashboard. We built a custom GitHub Action that runs on Pull Requests. If a developer writes vulnerable code, Secura blocks the PR and automatically posts AI-generated fix suggestions as review comments! Export & Audit: It features robust PDF report generation and SQLAlchemy-backed database auditing for compliance.
โ๏ธ How we built it We adopted a modern, distributed microservices architecture:
Frontend: Built with React, TailwindCSS, and React-Router. We used reactflow for the interactive attack path graphs and html2pdf.js for on-the-fly report generation. Deployed on Vercel. Scan Orchestrator: A Node.js/Express backend that coordinates the various scanning engines and manages the history. AI Microservice: A Python FastAPI service that handles the heavy lifting for AI. We implemented a Retrieval-Augmented Generation (RAG) pipeline using ChromaDB to store security contexts. We integrated the Google Gemini API to process prompts and generate structured remediation JSONs. Deployed on Render. CLI & Automation: A custom Node.js CLI tool (secaudit.js) that runs inside our GitHub Actions workflow to parse local files, detect insecure code (like XSS or exposed secrets), and interact with the GitHub API to post automated PR comments.
๐ง Challenges we ran into Building a Reliable RAG Pipeline: Ensuring that Gemini returned strictly formatted JSON based on our OWASP context without hallucinating took a lot of prompt engineering and validation tweaking. Complex State Management for the Graph: Mapping flat vulnerability data into a logical, directed kill-chain graph in ReactFlow required careful data transformation and custom node styling. Cross-Environment Integration: Connecting the Node backend, the Python AI microservice, and the frontend while handling CORS, API limits, and seamless data flow across Vercel and Render was tricky. Scanner False Positives (Inception!): While building our own security scanner GitHub Action, the scanner actually flagged our own code (Unsafe DOM Manipulation & console log secrets) during development! We had to rewrite parts of our PDF generator to ensure we were following the exact security practices we were preaching.
๐ Accomplishments that we're proud of Successfully integrating a multi-language architecture (JavaScript + Python) in a short hackathon timeframe. Building a fully functional GitHub PR Automation tool. Seeing our bot block a bad PR and post a code fix in real-time felt like magic. The Visual Attack Path Graphโit takes intimidating security data and turns it into a visual map that any beginner developer can understand.
๐ What we learned Deep dive into DevSecOps practices and how to write custom GitHub Actions. Advanced prompt engineering and integrating the Gemini 1.5 Flash API for structured output generation. How to use Vector Databases (ChromaDB) for grounding LLM responses in factual documentation. The intricacies of securely manipulating the DOM in React to prevent XSS.
๐ฎ What's next for Secura One-Click Auto-Commits: Allowing developers to click an "Apply Fix" button in the dashboard that automatically pushes the AI's patched code directly to their GitHub branch. More Scanner Integrations: Expanding beyond web-scanning to include deep SAST (Static Application Security Testing) and DAST engines. VS Code Extension: Bringing Secura's AI remediation directly into the developer's IDE so they can fix vulnerabilities before they even commit. 16:55
Built With
- chromadb
- express.js
- fastapi
- github-actions
- google-gemini
- node.js
- python
- react.js
- reactflow
- render
- sqlalchemy
- tailwindcss
- vercel
Log in or sign up for Devpost to join the conversation.