TELUS AI Hackathon

Project · AI-assisted AppSec

An AI reviewer that reads each static-analysis finding, decides whether it is real, and proposes a fix that will not break the code.

Scanners flag; nobody has time to judge

SAST tools produce long lists without priority or context. Developers either ignore them or lose hours separating real issues from noise.

Triage first, then a fix that fits

Each Semgrep finding is sent to an LLM with the surrounding code. The model returns a verdict (valid or false positive) with its reasoning, then a remediation that keeps the function’s behaviour, so the fix does not introduce a new bug.

False positives are dismissed with a stated reason, not silently dropped.

Vulnerable code and the proposed fix sit side by side for review.

The model advises; a person merges

Nothing is applied automatically. The design keeps a human approval step inside the secure-SDLC workflow, which is where AI help belongs in code review.