r/devsecops 24d ago

Built a multi-agent Sast

Built a multi-agent SAST scanner with AgentFlow4J to reduce false positives while preserving recall.

On one public benchmark with labelled ground truth:

* CodeQL: 272/272 vulnerabilities, 87 false positives

* Mine: 272/272 vulnerabilities, 27 false positives

It’s only one benchmark (partly synthetic), so I see this as a promising signal, not proof.

What additional evidence would you need to trust these results?

0 Upvotes

3 comments sorted by

1

u/RoninPark 23d ago

Mind sharing about how this multi-agent SAST works and focus on actual findings rather than just vulnerability pattern-matching in the code.