NamanTiwari/AppSec-Agent
0
AI Security Code Reviewer — AppSec Agent RL Environment
A production-grade Reinforcement Learning environment built on the OpenEnv framework that simulates a real-world Application Security (AppSec) code-review pipeline.
An AI agent analyses code snippets flagged by static-analysis tooling and decides the optimal response for each finding:
Rewards penalise over-flagging, missed critical vulnerabilities, repetitive (loop) behaviour, and reward efficient, accurate triage.
📁 Project Structure
openev-project/
├── Dockerfile # Slim Docker image for deployment
├── README.md # This file
├── pyproject.toml # Project metadata & dependencies (PEP 621)
├── uv.lock # Pinned dependency lock file (uv)
├── openenv.yaml # OpenEnv environment specification
├── models.py # Pydantic models: Observation, Action, Reward
├── inference.py # LLM-powered inference loop (HuggingFace router)
├── client.py # Typed Python client (OpenEnv EnvClient)
├── __init__.py # Root package marker
├── server/
│ ├── __init__.py # Server package marker
│ ├── app.py # FastAPI application (OpenEnv HTTP server)
│ ├── environment.py # Core RL environment logic & reward table
│ └── requirements.txt # Pinned pip dependencies for the server
└── tasks/
├── easy.json # 3 unambiguous scenarios
├── medium.json # 5 mixed scenarios with false positives
└── hard.json # 7 highly ambiguous scenarios⚡ Quick Start
Prerequisites
- Python ≥ 3.10
- uv (recommended) or pip + venv
- A HuggingFace API token (
HF_TOKEN)
1. Clone & Install
git clone <repo-url> openev-project && cd openev-project
# Option A — uv (recommended)
uv venv && uv pip install -e ".[dev]"
# Option B — pip
python -m venv venv && source venv/bin/activate # Windows: venv\Scripts\activate
pip install -e ".[dev]"2. Set Environment Variables
export HF_TOKEN="hf_your_token_here"
# Optional overrides
export API_BASE_URL="https://router.huggingface.co/v1"
export MODEL_NAME="Qwen/Qwen2.5-7B-Instruct"
export TASK_DIFFICULTY="easy" # easy | medium | hard3. Run the Environment Server
# Using uv
uv run server
# Using uvicorn directly
uvicorn server.app:app --host 0.0.0.0 --port 7860
# Or directly
python -m server.app --port 78604. Run Inference
python inference.pyThe inference script runs all three difficulty tiers (easy → medium → hard) and prints structured logs in the strict OpenEnv format:
[START]
# task=appsec-code-review-easy env=appsec-openenv-v1 model=Qwen/Qwen2.5-7B-Instruct
[STEP] step=1 action=fix reward=0.8500 done=false error=null
[STEP] step=2 action=escalate reward=0.9999 done=false error=null
[STEP] step=3 action=ignore reward=0.9999 done=true error=null
[END] success=true steps=3 score=0.9499 rewards=0.8500,0.9999,0.9999🐳 Docker
# Build
docker build -t appsec-env:latest .
# Run
docker run --rm -e HF_TOKEN="hf_..." appsec-env:latest
# Run the server instead of inference
docker run --rm -p 7860:7860 -e HF_TOKEN="hf_..." appsec-env:latest \
uvicorn server.app:app --host 0.0.0.0 --port 7860🧩 Environment Details
Observation Schema
Action Schema
Reward Schema
Task Tiers
🧪 Testing
# Run all tests
pytest -v
# With coverage
pytest --cov=server --cov=models -v📝 Environment Variables
📄 License
This project was developed for the Meta OpenEnv Hackathon 2026.
