Team Ai
Apppublic

NamanTiwari/AppSec-Agent

sourceHugging Faceupdated 6mo agoView on Hugging Face
0likes
App README

AI Security Code Reviewer — AppSec Agent RL Environment

A production-grade Reinforcement Learning environment built on the OpenEnv framework that simulates a real-world Application Security (AppSec) code-review pipeline.

An AI agent analyses code snippets flagged by static-analysis tooling and decides the optimal response for each finding:

ActionMeaning
ignoreFalse positive — no action needed
flagReal issue — needs developer attention
fixReal issue — can be auto-remediated safely
escalateCritical issue — requires human security expert

Rewards penalise over-flagging, missed critical vulnerabilities, repetitive (loop) behaviour, and reward efficient, accurate triage.


📁 Project Structure

openev-project/
├── Dockerfile              # Slim Docker image for deployment
├── README.md               # This file
├── pyproject.toml          # Project metadata & dependencies (PEP 621)
├── uv.lock                 # Pinned dependency lock file (uv)
├── openenv.yaml            # OpenEnv environment specification
├── models.py               # Pydantic models: Observation, Action, Reward
├── inference.py            # LLM-powered inference loop (HuggingFace router)
├── client.py               # Typed Python client (OpenEnv EnvClient)
├── __init__.py             # Root package marker
├── server/
│   ├── __init__.py         # Server package marker
│   ├── app.py              # FastAPI application (OpenEnv HTTP server)
│   ├── environment.py      # Core RL environment logic & reward table
│   └── requirements.txt    # Pinned pip dependencies for the server
└── tasks/
    ├── easy.json           # 3 unambiguous scenarios
    ├── medium.json         # 5 mixed scenarios with false positives
    └── hard.json           # 7 highly ambiguous scenarios

⚡ Quick Start

Prerequisites

  • —Python ≥ 3.10
  • —uv (recommended) or pip + venv
  • —A HuggingFace API token (HF_TOKEN)

1. Clone & Install

bash
git clone <repo-url> openev-project && cd openev-project

# Option A — uv (recommended)
uv venv && uv pip install -e ".[dev]"

# Option B — pip
python -m venv venv && source venv/bin/activate   # Windows: venv\Scripts\activate
pip install -e ".[dev]"

2. Set Environment Variables

bash
export HF_TOKEN="hf_your_token_here"

# Optional overrides
export API_BASE_URL="https://router.huggingface.co/v1"
export MODEL_NAME="Qwen/Qwen2.5-7B-Instruct"
export TASK_DIFFICULTY="easy"     # easy | medium | hard

3. Run the Environment Server

bash
# Using uv
uv run server

# Using uvicorn directly
uvicorn server.app:app --host 0.0.0.0 --port 7860

# Or directly
python -m server.app --port 7860

4. Run Inference

bash
python inference.py

The inference script runs all three difficulty tiers (easy → medium → hard) and prints structured logs in the strict OpenEnv format:

[START]
# task=appsec-code-review-easy env=appsec-openenv-v1 model=Qwen/Qwen2.5-7B-Instruct
[STEP] step=1 action=fix reward=0.8500 done=false error=null
[STEP] step=2 action=escalate reward=0.9999 done=false error=null
[STEP] step=3 action=ignore reward=0.9999 done=true error=null
[END] success=true steps=3 score=0.9499 rewards=0.8500,0.9999,0.9999

🐳 Docker

bash
# Build
docker build -t appsec-env:latest .

# Run
docker run --rm -e HF_TOKEN="hf_..." appsec-env:latest

# Run the server instead of inference
docker run --rm -p 7860:7860 -e HF_TOKEN="hf_..." appsec-env:latest \
    uvicorn server.app:app --host 0.0.0.0 --port 7860

🧩 Environment Details

Observation Schema

FieldTypeDescription
code_snippetstringThe code block under review
detected_issuestringStatic analysis finding / vulnerability desc.
severitystringlow \medium \high \critical
contextstringDeployment context, exposure, risk amplifiers
step_countintCurrent step within the episode

Action Schema

FieldTypeDescription
actionstringignore \flag \fix \escalate

Reward Schema

FieldTypeDescription
valuefloatNormalised reward in [0.0, 1.0]
reasoningstringDeterministic explanation of the reward

Task Tiers

TierScenariosMax StepsDescription
easy33Unambiguous, textbook vulnerabilities
medium55Mixed real + false positives
hard77Highly ambiguous, conflicting signals

🧪 Testing

bash
# Run all tests
pytest -v

# With coverage
pytest --cov=server --cov=models -v

📝 Environment Variables

VariableRequiredDefaultDescription
HF_TOKEN✅ Yes—HuggingFace API token
API_BASE_URLNohttps://router.huggingface.co/v1OpenAI-compatible endpoint
MODEL_NAMENoQwen/Qwen2.5-7B-InstructLLM model identifier
TASK_DIFFICULTYNoeasyTask tier: easy / medium / hard

📄 License

This project was developed for the Meta OpenEnv Hackathon 2026.