TELUS AI Hackathon
Project · AI-assisted AppSec
An AI reviewer that reads each static-analysis finding, decides whether it is real, and proposes a fix that will not break the code.
- My role Builder
- Input Semgrep JSON + code context
- Output Verdict · reason · safe fix
- Guardrail A human approves every fix
Scanners flag; nobody has time to judge
SAST tools produce long lists without priority or context. Developers either ignore them or lose hours separating real issues from noise.
Triage first, then a fix that fits
Each Semgrep finding is sent to an LLM with the surrounding code. The model returns a verdict (valid or false positive) with its reasoning, then a remediation that keeps the function’s behaviour, so the fix does not introduce a new bug.
False positives are dismissed with a stated reason, not silently dropped.
Vulnerable code and the proposed fix sit side by side for review.
The model advises; a person merges
Nothing is applied automatically. The design keeps a human approval step inside the secure-SDLC workflow, which is where AI help belongs in code review.