The problem

Small engineering teams are drowning in vulnerability alerts. Most CVE and vendor advisories are noise for any given stack, so real, exploitable risk gets missed — and patching lags attackers by weeks. Attackers now automate exploitation within hours of disclosure, while small teams lack dedicated security staff.

The idea

Sentinel, an AI agent that turns raw advisories into a prioritized, actionable patch plan. It ingests advisories for the team's stack, filters out non-applicable ones by matching dependency manifests and reachability, scores what remains by exploitability and business impact, and drafts patch steps and runbooks — with human approval gates before any change. It ships as a chat-first assistant integrated with Slack and GitHub.

Why it matters

Faster, focused patching for the teams least equipped to do it today. Cutting through alert noise means critical vulnerabilities get fixed first, reducing breach risk for small businesses and startups.

How I would start

NVD and CISA KEV feeds plus a dependency manifest parser; a RAG layer over vendor advisories for context; an agentic planner that drafts remediation steps. Skills I bring: software engineering at Cybs Innovations, with experience building LLM-powered tools and integrations.

Note: this is a Round 1 idea submission — no finished product yet, per the round requirements.

Built With

Share this project:

Updates

Submission history