The Problem: Static analysis scanners like Semgrep flag vulnerabilities in seconds, but developers suffer from alert fatigue, leaving critical security flaws exposed during long manual remediation cycles.The Solution: Our ADL pipeline integrates Semgrep 2.7 and Codex CLI directly inside a ChromeOS Linux terminal. When Semgrep flags a vulnerability (such as a CWE-78 Command Injection flaw in vulnerable_service.py), our agent calls AWS Bedrock (Claude 3.5 Sonnet) to generate a secure code patch without shell=True. It re-executes Semgrep to confirm zero findings and indexes the pattern into ClickHouse on AWS for real-time lesson retrieval.Tech Stack: ChromeOS Linux Container, Codex CLI, Semgrep 2.7, AWS Bedrock (Claude 3.5 Sonnet), ClickHouse on AWS, AWS S3.