frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Show HN: Autofix Bot – Hybrid static analysis and AI code review agent

21•sanketsaurav•1h ago
Hi there, HN! We’re Jai and Sanket from DeepSource (YC W20), and today we’re launching Autofix Bot, a hybrid static analysis + AI agent purpose-built for in-the-loop use with AI coding agents.

AI coding agents have made code generation nearly free, and they’ve shifted the bottleneck to code review. Static-only analysis with a fixed set of checkers isn’t enough. LLM-only review has several limitations: non-deterministic across runs, low recall on security issues, expensive at scale, and a tendency to get ‘distracted’.

We spent the last 6 years building a deterministic, static-analysis-only code review product. Earlier this year, we started thinking about this problem from the ground up and realized that static analysis solves key blind spots of LLM-only reviews. Over the past six months, we built a new ‘hybrid’ agent loop that uses static analysis and frontier AI agents together to outperform both static-only and LLM-only tools in finding and fixing code quality and security issues. Today, we’re opening it up publicly.

Here’s how the hybrid architecture works:

- Static pass: 5,000+ deterministic checkers (code quality, security, performance) establish a high-precision baseline. A sub-agent suppresses context-specific false positives.

- AI review: The agent reviews code with static findings as anchors. Has access to AST, data-flow graphs, control-flow, import graphs as tools, not just grep and usual shell commands.

- Remediation: Sub-agents generate fixes. Static harness validates all edits before emitting a clean git patch.

Static solves key LLM problems: non-determinism across runs, low recall on security issues (LLMs get distracted by style), and cost (static narrowing reduces prompt size and tool calls).

On the OpenSSF CVE Benchmark [1] (200+ real JS/TS vulnerabilities), we hit 81.2% accuracy and 80.0% F1; vs Cursor Bugbot (74.5% accuracy, 77.42% F1), Claude Code (71.5% accuracy, 62.99% F1), CodeRabbit (59.4% accuracy, 36.19% F1), and Semgrep CE (56.9% accuracy, 38.26% F1). On secrets detection, 92.8% F1; vs Gitleaks (75.6%), detect-secrets (64.1%), and TruffleHog (41.2%). We use our open-source classification model for this. [2]

Full methodology and how we evaluated each tool: https://autofix.bot/benchmarks

You can use Autofix Bot interactively on any repository using our TUI, as a plugin in Claude Code, or with our MCP on any compatible AI client (like OpenAI Codex).[3] We’re specifically building for AI coding agent-first workflows, so you can ask your agent to run Autofix Bot on every checkpoint autonomously.

Give us a shot today: https://autofix.bot. We’d love to hear any feedback!

---

[1] https://github.com/ossf-cve-benchmark/ossf-cve-benchmark

[2] https://huggingface.co/deepsource/Narada-3.2-3B-v1

[3] https://autofix.bot/manual/#terminal-ui

"My self-awareness of my limitations is limited."

1•niklai•36s ago•0 comments

How People Use AI at Work

https://dejan.ai/blog/report-ai-workplace/
1•gmays•1m ago•0 comments

Cobalt: Rust static site generator with Liquid templates, runs on iPadOS via iSH

https://cobalt-org.github.io/
1•transpute•1m ago•0 comments

Show HN: Chefs.Video – A marketplace where you pay freelancers $0.005/second

https://chefs.video
1•ufvy•1m ago•1 comments

Stage Manager in Mac OS

https://blog.kowalczyk.info/til-stage-manager-in-mac-os.html
1•ericdanielski•1m ago•0 comments

You used to be able to just create a Native GUI App in 10 seconds

https://twitter.com/tsoding/status/1998403967718400376
2•Ezhik•2m ago•0 comments

Iksemel Rusted

https://thinkerf.blogspot.com/2025/12/iksemel-rusted.html
1•ciferkey•2m ago•0 comments

The moment the earliest known man-made fire was uncovered

https://www.bbc.co.uk/news/resources/idt-b9da7a6d-165b-492a-8785-235cd10e2e8e
2•fredley•2m ago•0 comments

A Journalist Reported from Palestine. YouTube Deleted His Account

https://theintercept.com/2025/12/07/youtube-deleted-journalist-israel-palestine-censorship/
1•upofadown•3m ago•0 comments

Show HN: Automate Windows Using Lua

https://lowkpro.com/
1•publicdebates•3m ago•0 comments

Monado 25.1.0: Enabling tomorrow's OpenXR experiences

https://www.collabora.com/news-and-blog/news-and-events/monado-25-1-0-enabling-tomorrows-openxr-e...
1•mfilion•3m ago•0 comments

Show HN: Vocation: AI Career Coach for Mid-Career Transitions

https://www.joinvocation.com/
1•cliffcmaxwell•4m ago•0 comments

Closing the Agent Loop

https://www.sawyerhood.com/blog/closing-the-agent-loop
2•sawyerjhood•5m ago•0 comments

Mandatory social media sharing and use of ETSA mobile app for entry to US

https://www.federalregister.gov/documents/2025/12/10/2025-22461/agency-information-collection-act...
1•beedeebeedee•6m ago•0 comments

Microsoft Scales Back AI Goals Because Almost Nobody Is Using Copilot

https://www.extremetech.com/computing/microsoft-scales-back-ai-goals-because-almost-nobody-is-usi...
2•mtdewcmu•7m ago•0 comments

MacKenzie Scott donated $7.16B in the last one year

https://yieldgiving.com/essays/we-are-the-ones-we-ve-been-waiting-for/
1•nani98•9m ago•0 comments

Super-Flat ASTs

https://jhwlr.io/super-flat-ast/
1•birdculture•9m ago•0 comments

Empromptu ($2M pre-seed): AI application builder with Self-Managing Context

1•anaempromptu•9m ago•0 comments

Realism Invictus 3.8 Released

https://www.moddb.com/mods/realism-invictus/news/realism-invictus-38-released-20-year-anniversary...
1•midzer•12m ago•0 comments

Show HN: Boring Pattern with Unnecessary Dynamics

https://number-garden.netlify.app/?16966954957793m
1•cpuXguy•12m ago•0 comments

RSL (Really Simple Licensing) 1.0 standard for content on AI-First Internet

https://rslstandard.org/press/rsl-1-specification-2025
1•ChrisArchitect•13m ago•0 comments

Interview with Hacker Gummo – Privacy, Hacking, and Quantum Computing

https://www.fattonys.net/episodes/gummo-hacking
1•Incerto•13m ago•0 comments

How I discovered pigeons sabotaging my project with Kafka

https://hughevans.dev/how-i-discovered-pigeons-sabotaging-my-project-with-aiven-free-tier-kafka/
1•HughEvansDev•14m ago•0 comments

Pando (Tree)

https://en.wikipedia.org/wiki/Pando_(tree)
1•kblissett•15m ago•0 comments

Extracting Nintendo Switch "Play Activity" Using Python and OCR

https://sethmlarson.dev/nintendo-switch-play-activity-ocr
1•SethMLarson•17m ago•0 comments

Meta's New A.I. Superstars Are Chafing Against the Rest of the Company

https://www.nytimes.com/2025/12/10/technology/meta-ai-tbd-lab-friction.html
2•furcyd•17m ago•1 comments

Authors retract Nature paper projecting high costs of climate change

https://retractionwatch.com/2025/12/03/authors-retract-nature-paper-projecting-high-costs-of-clim...
1•bookofjoe•19m ago•0 comments

Axial Flux Motor Powers Supercars to New Heights

https://spectrum.ieee.org/axial-flux-motor-yasa
1•leecoursey•19m ago•1 comments

Show HN: Transactional Email for Developers

https://ahasend.com
10•farhadhf•19m ago•0 comments

Chemical modulation of gut bacterial metabolism extends the lifespan of hosts

https://journals.plos.org/plosbiology/article?id=10.1371/journal.pbio.3002749
1•PaulHoule•21m ago•0 comments