AI coding tools

Catch vulnerable code before it ships

A lightweight probe reads a coding model's own activations and flags vulnerable output inline with generation — no second model, no decode-then-scan step.

68.8% F1
Matches published SOTA on Devign (fine-tuned classifiers)
13–16M
Probe parameters, under 0.2% of the base model's size
<1ms
Probe overhead vs. 50–500ms generation time

Near-zero latency

Runs concurrent with generation — effectively free, versus seconds for static analysis or a second LLM pass

No added infrastructure

No second GPU-backed model to host, scale, or pay inference for

Flags risk before it's fully emitted

Unlike a response filter that must wait for the whole output

Deployability ↓

Details below

CI / PR gate

A probe-based check on AI-generated diffs before merge — cheaper than a full static-analysis pass on every PR

IDE inline flag

Real-time "this generated function looks risky" signal as code is written, no round-trip to an external service

Probe SDK for model owners

Coding-tool vendors train a probe on their own model's activations, in-house — data and weights never leave their infrastructure

Per-CWE risk scoring

Tight, consistent accuracy (97.5–99.0%) across the five most common CWE types in our Big-Vul evaluation, suggesting a path to categorized risk output rather than a binary flag

Current results are on existing, human/CVE-labeled corpus code, not yet on live model-generated completions — a necessary but not sufficient step toward a model flagging its own forthcoming output. We also haven't yet run an adversarial-robustness or obfuscation-evasion check against the probe itself.

See it on your own model

Talk to us about running a pilot on your coding pipeline — no retraining, no model swap-out required.

Talk to us