frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Show HN: Autofix Bot – Hybrid static analysis and AI code review agent

14•sanketsaurav•17h ago
Hi there, HN! We’re Jai and Sanket from DeepSource (YC W20), and today we’re launching Autofix Bot, a hybrid static analysis + AI agent purpose-built for in-the-loop use with AI coding agents.

AI coding agents have made code generation nearly free, and they’ve shifted the bottleneck to code review. Static-only analysis with a fixed set of checkers isn’t enough. LLM-only review has several limitations: non-deterministic across runs, low recall on security issues, expensive at scale, and a tendency to get ‘distracted’.

We spent the last 6 years building a deterministic, static-analysis-only code review product. Earlier this year, we started thinking about this problem from the ground up and realized that static analysis solves key blind spots of LLM-only reviews. Over the past six months, we built a new ‘hybrid’ agent loop that uses static analysis and frontier AI agents together to outperform both static-only and LLM-only tools in finding and fixing code quality and security issues. Today, we’re opening it up publicly.

Here’s how the hybrid architecture works:

- Static pass: 5,000+ deterministic checkers (code quality, security, performance) establish a high-precision baseline. A sub-agent suppresses context-specific false positives.

- AI review: The agent reviews code with static findings as anchors. Has access to AST, data-flow graphs, control-flow, import graphs as tools, not just grep and usual shell commands.

- Remediation: Sub-agents generate fixes. Static harness validates all edits before emitting a clean git patch.

Static solves key LLM problems: non-determinism across runs, low recall on security issues (LLMs get distracted by style), and cost (static narrowing reduces prompt size and tool calls).

On the OpenSSF CVE Benchmark [1] (200+ real JS/TS vulnerabilities), we hit 81.2% accuracy and 80.0% F1; vs Cursor Bugbot (74.5% accuracy, 77.42% F1), Claude Code (71.5% accuracy, 62.99% F1), CodeRabbit (59.4% accuracy, 36.19% F1), and Semgrep CE (56.9% accuracy, 38.26% F1). On secrets detection, 92.8% F1; vs Gitleaks (75.6%), detect-secrets (64.1%), and TruffleHog (41.2%). We use our open-source classification model for this. [2]

Full methodology and how we evaluated each tool: https://autofix.bot/benchmarks

You can use Autofix Bot interactively on any repository using our TUI, as a plugin in Claude Code, or with our MCP on any compatible AI client (like OpenAI Codex).[3] We’re specifically building for AI coding agent-first workflows, so you can ask your agent to run Autofix Bot on every checkpoint autonomously.

Give us a shot today: https://autofix.bot. We’d love to hear any feedback!

---

[1] https://github.com/ossf-cve-benchmark/ossf-cve-benchmark

[2] https://huggingface.co/deepsource/Narada-3.2-3B-v1

[3] https://autofix.bot/manual/#terminal-ui

Comments

nickphx•36m ago
"shifted bottleneck to code review"... understatement of decade.

Koralm Railway

https://infrastruktur.oebb.at/en/projects-for-austria/railway-lines/southern-line-vienna-villach/...
229•fzeindl•3h ago•95 comments

SQLite JSON at Full Index Speed Using Generated Columns

https://www.dbpro.app/blog/sqlite-json-virtual-columns-indexing
33•upmostly•1h ago•4 comments

4 billion if statements (2023)

https://andreasjhkarlsson.github.io//jekyll/update/2023/12/27/4-billion-if-statements.html
211•damethos•5d ago•79 comments

From text to token: How tokenization pipelines work

https://www.paradedb.com/blog/when-tokenization-becomes-token
37•philippemnoel•23h ago•1 comments

The tiniest yet real telescope I've built

https://lucassifoni.info/blog/miniscope-tiny-telescope/
161•chantepierre•7h ago•37 comments

Fedora: Open-source repository for long-term digital preservation

https://fedorarepository.org/
17•cernocky•1h ago•11 comments

The Tor Project is switching to Rust

https://itsfoss.com/news/tor-rust-rewrite-progress/
130•giuliomagnifico•2h ago•63 comments

GPT-5.2

https://openai.com/index/introducing-gpt-5-2/
1070•atgctg•20h ago•936 comments

Show HN: Autofix Bot – Hybrid static analysis and AI code review agent

14•sanketsaurav•17h ago•1 comments

Nokia N900 Necromancy

https://yaky.dev/2025-12-11-nokia-n900-necromancy/
381•yaky•14h ago•140 comments

Google de-indexed Bear Blog and I don't know why

https://journal.james-zhan.com/google-de-indexed-my-entire-bear-blog-and-i-dont-know-why/
258•nafnlj•13h ago•106 comments

Guarding My Git Forge Against AI Scrapers

https://vulpinecitrus.info/blog/guarding-git-forge-ai-scrapers/
78•todsacerdoti•6h ago•46 comments

Show HN: Tripwire: A new anti evil maid defense

https://github.com/fr33-sh/Tripwire
21•DoctorFreeman•1d ago•14 comments

CRISPR fungus: Protein-packed, sustainable, and tastes like meat

https://www.isaaa.org/kc/cropbiotechupdate/article/default.asp?ID=21607
210•rguiscard•13h ago•121 comments

Training LLMs for Honesty via Confessions

https://arxiv.org/abs/2512.08093
18•arabello•4h ago•5 comments

He set out to walk around the world. After 27 years, his quest is nearly over

https://www.washingtonpost.com/lifestyle/2025/12/05/karl-bushby-walk-around-world/
155•wallflower•4d ago•119 comments

What folk can do

https://folk.computer/guides/what-folk-can-do
19•luu•4d ago•10 comments

Rivian Unveils Custom Silicon, R2 Lidar Roadmap, and Universal Hands Free

https://riviantrackr.com/news/rivian-unveils-custom-silicon-r2-lidar-roadmap-universal-hands-free...
334•doctoboggan•20h ago•455 comments

The highest quality codebase

https://gricha.dev/blog/the-highest-quality-codebase
585•Gricha•3d ago•365 comments

Denial of service and source code exposure in React Server Components

https://react.dev/blog/2025/12/11/denial-of-service-and-source-code-exposure-in-react-server-comp...
305•sangeeth96•17h ago•190 comments

Use Python for Scripting

https://hypirion.com/musings/use-python-for-scripting
5•birdculture•4d ago•6 comments

Octo: A Chip8 IDE

https://github.com/JohnEarnest/Octo
23•tosh•6d ago•2 comments

BehindTheMedspeak: A Spinal Tap

https://bookofjoe2.blogspot.com/2025/10/behindthemedspeak-this-is-spinal-tap.html
4•surprisetalk•5d ago•1 comments

Smartphone without a battery (2022)

https://yaky.dev/2022-09-06-smartphone-without-battery/
54•MYEUHD•7h ago•17 comments

Programmers and software developers lost the plot on naming their tools

https://larr.net/p/namings.html
342•todsacerdoti•20h ago•446 comments

An SVG is all you need

https://jon.recoil.org/blog/2025/12/an-svg-is-all-you-need.html
285•sadiq•19h ago•115 comments

Spirograph style Lego drawing machine

https://jkbrickworks.com/simple-drawing-machine/
30•ensocode•4d ago•5 comments

Auto-grading decade-old Hacker News discussions with hindsight

https://karpathy.bearblog.dev/auto-grade-hn/
629•__rito__•1d ago•259 comments

Why Isn't Online Age Verification Just Like Showing Your ID in Person?

https://www.eff.org/deeplinks/2025/12/why-isnt-online-age-verification-just-showing-your-id-person
13•hn_acker•1h ago•4 comments

Litestream VFS

https://fly.io/blog/litestream-vfs/
325•emschwartz•20h ago•78 comments