tokens&
For enterprises
tokens&

Find tools, check provider offers, save a build plan, and share your work when you’re ready.

For buildersFor enterprises

For builders

  • Startup credits and perks
  • Agent Skills
  • Publish a project

For enterprises

  • Start free company workspace
  • Submit a tool, product, or perk

Community

  • Community
  • Newsletter
  • Events
Xin

© 2026 tokensand, LLC. All rights reserved.

  • Terms
  • Privacy
  • Security
  • Data Processing
  • Status
  1. Hackathon
  2. Project gallery
  3. gtmsos-personal
skinemtowinemabout 2 hours agoContributorJudging locked: Event build

gtmsos-personal

Agentic Development Lifecycle (ADL) – Autonomous DevSecOps Engine

Review the project

Start with the source code, then open the demo or video if available.

View GitHub repository
Watch demo video
Demo video
Watch demo video
Project description
The Problem: Static analysis scanners like Semgrep flag vulnerabilities in seconds, but developers suffer from alert fatigue, leaving critical security flaws exposed during long manual remediation cycles.The Solution: Our ADL pipeline integrates Semgrep 2.7 and Codex CLI directly inside a ChromeOS Linux terminal. When Semgrep flags a vulnerability (such as a CWE-78 Command Injection flaw in vulnerable_service.py), our agent calls AWS Bedrock (Claude 3.5 Sonnet) to generate a secure code patch without shell=True. It re-executes Semgrep to confirm zero findings and indexes the pattern into ClickHouse on AWS for real-time lesson retrieval.Tech Stack: ChromeOS Linux Container, Codex CLI, Semgrep 2.7, AWS Bedrock (Claude 3.5 Sonnet), ClickHouse on AWS, AWS S3.
Tools used
  • ClickHouse logoClickHouse
  • SSemgrep
Project gallery
Project links
  • GitHub repository
  • Demo video
Tools used
  • ClickHouse logoClickHouse
  • SSemgrep