AuraRemed: Autonomous Security Engineering Report
Santiago Rodriguez Heras · Team AuraRemed
Submitted to The Secure Program Synthesis Hackathon. Sprint projects are early-stage work by participants, not Apart Research publications.
About AuraRemed is a local DevSecOps engine that automates software vulnerability remediation without data leakage. Its architecture couples Semgrep (Tier 2) for deterministic flaw detection with Qwen2.5-Coder (Tier 1) to apply surgical in-memory patches and security docstrings in a closed feedback loop until validation achieves a clean Code 0.
Reviews
Secure program synthesis opens new questions about what happens in CI. This sprint produced a CI method that automatically finds and fixes security issues. Some questions I'd have for next steps relate to what deployment and user experience would look like: would someone trust a low-cost LLM to substantially edit their code in CI? is there a way to check the patched code still works as expected -- maybe there's test CIs too but what if they fail? and would a sql injection attack really be a CI-fix or a major red flag?
Cite this project
@misc{heras2026auraremed,
title = {{AuraRemed: Autonomous Security Engineering Report}},
author = {Santiago Rodriguez Heras},
year = {2026},
month = may,
note = {Submitted to The Secure Program Synthesis Hackathon, an Apart Research Sprint},
howpublished = {\url{https://apartresearch.com/sprints/projects/auraremed-autonomous-security-engineering-report-biyb}},
url = {https://apartresearch.com/sprints/projects/auraremed-autonomous-security-engineering-report-biyb}
}More from The Secure Program Synthesis Hackathon
- View project: Vibe-Coding Specs: Eliciting, Editing, and Verifying Specifications for AI Coding Agents
Vibe-Coding Specs: Eliciting, Editing, and Verifying Specifications for AI Coding Agents
Lida Safety
Specifications for real systems do not exist as one-shot artifacts: the user's intent emerges as they discover edge cases, rewrite drafts, and react to failing tests. We present an iterative pipeline that takes this …
- View project: AgentSpecGap
AgentSpecGap
solo-team
This prototype extracts rules from system prompts, tool descriptions, and runtime config. Rules are classified into one of interface validation, authorization check, workflow ordering validation, runtime validation, …
- View project: SpecGap Arena
SpecGap Arena
Obligation Cartographers
SpecGap Arena is a benchmark and framework that exposes how incomplete specifications let plausible but incorrect code pass public tests. It synthesizes missing semantic obligations (security boundaries, invariants, …