产品

Security Swarm 用并行 Devin 扫描代码库并修复漏洞

精选理由

Cognition 让一群 Devin 智能体并行给你的代码库找漏洞,沙箱里验证后直接提 PR 修复,跨文件的漏洞链也能抓到。

Cognition 推出 Security Swarm,让多个 Devin 智能体并行分析整个代码库。工作流程分四步:先建立威胁模型,再寻找可利用的真实漏洞(包括跨文件组合的漏洞链),然后在沙箱中验证漏洞可复现,最后以 pull request 形式提交修复补丁。产品定位是把安全审计从人工渗透测试变成多智能体自动化流程。

图片来源 · Windsurf
原文 · Windsurf

Security Swarm sends a swarm of parallel Devins through your codebase to build a threat model, hunt down real, exploitable vulnerabilities (even ones chained across files), prove them in a sandbox, and hand you the fix as a pull request. Here's how it works: Your browser does not support the video tag. 🔗 View on Twitter 💬 2 🔄 4 ❤️ 19 👀 799 📊 6 ⚡