正在加载视频...
视频加载失败
Introducing Devin Security Swarm A more cost effective and accurate way to find security vulnerabilities in complex codebases, based on a new architecture: Agentic MapReduce.
37 条评论

In testing, Devin Security Swarm found 36 of 50 real-world GHSA vulnerabilities at 30% lower cost per finding than the next most accurate alternative.

We built a new architecture for whole-codebase reasoning that we’re calling Agentic MapReduce. Security scanning is different from most coding tasks: a report is only trustworthy if the whole codebase is considered. But most agentic systems struggle to scale reasoning across large repos. Devin maps relevant signals across the repo, fans out focused agents over bounded shards, reduces their findings into one report, then verifies serious vulnerabilities in isolated sandboxes before marking them confirmed.

The result is simultaneously more efficient and more accurate than other tools. We evaluated a variety of security scanning tools on a dataset of 50 GHSA vulnerabilities across 14 languages including Go, Rust, Python, Ruby, Java, C#, JavaScript, C, Swift, Dart, and Elixir. The dataset spans opens source repos of various sizes and of many software categories. Beyond excelling on our eval, Devin Security Swarm also found critical vulnerabilities that other tools missed, like a PHP sandbox bypass via template injection, an argument injection through metadata value parsing, and an overly broad deserialization surface.

Security Swarm is a new pillar of Devin for Security: a suite of tools to help you find vulnerabilities, validate their exploitability at runtime, and ship remediation PRs. Learn more and try it today at:

We’re also publishing extensive documentation and technical materials about Agentic MapReduce, including a deep-dive on our evals. Read our announcement: Learn about Agentic MapReduce: Check out the evals:

@ido_pesok and Angela are goated Amazing launch!! Let's go

Super cool

the best team! 🤝 @ido_pesok @angelacareylin @(nick wong)

the most GOATED TEAM!!

I know that guy

Nice work! System seems aligned with what I shared in my article for @RampLabs last month - have y'all had the chance to read it? Would love to share ideas and excited to see what Cog ships next 🙂

Devin is cooking

@RonMiasnik Dream team

Very excited to try this after having used Codex security already, another pass should be useful! How do we use/invoke this?

The interesting part isn't the vuln-finding, it's that every confirmed finding gets reproduced in an isolated sandbox before Devin opens the PR. That's the difference between a scanner that flags noise and one whose output you can actually trust to auto-merge.

Awesome guys, but finding what's already in the codebase is one problem the other one is what the coding agent does while it's writing that code like pulling a poisoned package, running a shell command it shouldn't, acting on a prompt injection buried in a file @prismor_dev watches the agent's tool calls in real time and stops it there :)

@stevenkplus1 the best! 🙌🙌 @ido_pesok @angelacareylin

🙌🏻🙌🏻

@devmchheda Background agents becoming mainstream

Looks cool! you guys should share the list of vulns or the full benchmark at this point in time to contribute to open source and let others compare.

agentic MapReduce is just 'we sent a lot of interns' with better branding

IDO 🖤🐐

🚀🚀🚀

Agentic MapReduce for finding security vulnerabilities sounds like a smart way to scale code review across huge codebases.

MapReduce helps bound the reasoning scope but the final verification sandbox still has to catch every false positive the fan out agents introduced. That last mile remains the expensive part in production.

@ember_arlynx

@Adhyyan security is becoming more and more important, Devin Security Swarm allows you to catch vulnerabilities at scale for less cost. one of the most important launches for the company imo

dope concept guys

Hey @grok kendi modellerimi

Reproducing actual exploits in a sandbox to filter down to only real vulnerabilities feels genuinely production-grade. In security ops drowning in false positives, auto-opening the fix PR too could make backlog burndown dramatically faster.

congrats on this achievement

agent swarms for code security is the right direction, scaling verification without humans in the loop is how this actually gets solved.

Wow

sick idea! We launched this to find bugs in applications with @getlark exactly 2 months before

为什么未来我们绝对需要 100 倍以上的 AI 推理算力?AI 算力的真正吞噬者并不是人类在和 ChatGPT 聊天,而是正在席卷各行各业的“Agentic MapReduce”

The bounded shard part is what makes this believable. Security review needs broad coverage, but every finding still has to collapse back to a reproducible exploit or failing check.

Applying a mapreduce framework to agentic workflows is a brilliant solution to context window limits in large repositories. This architectural change significantly lowers false positive rates, making automated scanning far more actionable for development teams.


