Fall 2026 Projects - SPAR

· SPAR

1 min read Original article ↗

Towards Automated Vulnerability Discovery and Repair with Safety-Governed AI Agents

Yige Li · Singapore Management University

This project aims to build the foundations for safe and reliable AI agents that automate code vulnerability discovery, verification, and repair. The agents will interact with real code repositories, security tools, sandboxed environments, and human experts to identify vulnerabilities, validate findings, generate patches, and test remediation outcomes. We will develop an expert-in-the-loop safety harness to govern agent permissions, tool use, and high-risk actions, together with a security data engine that captures complete expert–agent–tool trajectories, including successes, failures, corrections, evidence, and repair outcomes. In summary, this project develops safe and reliable AI agents for automated code vulnerability discovery, verification, and repair through three main components: - 1. Automated Vulnerability-Research Agent: Build an AI agent that interacts with code repositories, security tools, and sandboxed environments to identify vulnerabilities, reproduce findings, generate patches, and test repairs. - 2. Expert-in-the-Loop Safety Harness: Develop a control layer for agent permissions, tool use, high-risk actions, evidence requirements, audit logging, and human approval. - 3. Security Data Engine: Capture complete expert–agent–tool trajectories—including successful findings, failed attempts, expert corrections, validation evidence, and repair outcomes—to support agent training, evaluation, and continuous improvement.