Vedant-DTU/kernel-env
0
AppSecEnv — Application Security Vulnerability Auto-Patcher
AppSecEnv is a real-world OpenEnv environment where an agent receives vulnerable Python code and must patch it while preserving business logic. The grader is dual-objective:
- Functional correctness (normal input still works)
- Exploit resistance (malicious input is safely blocked)
Final reward:
reward = 0.5 * functional_score + 0.5 * security_score
This design prevents trivial reward hacks like deleting functionality just to block exploits.
Why this is real-world
This mirrors an actual enterprise AppSec workflow:
- Triage vulnerable code
- Apply a secure fix
- Verify no regression in product behavior
- Validate exploit payloads are neutralized
OpenEnv Interface
Action
AppSecAction.code: strFull patched function implementation submitted by the agent.
Observation
task_id,task_description,difficultyvulnerability_type,cwe_idvulnerable_code,function_signaturefunctional_tests_passed,functional_tests_totalsecurity_tests_passed,security_tests_totalfunctional_score,security_scoretest_summary,test_feedbackstdout,stderrattempts_used,attempts_remaining
State
episode_id,step_counttask_id,difficultymax_attempts,best_score
Task Bank (15 tasks, easy → medium → hard)
Easy
e1_xss_escapee2_path_traversale3_ssrf_validatee4_header_injectione5_insecure_random
Medium
m1_command_injectionm2_insecure_deserializem3_idor_accessm4_open_redirectm5_log_injection
Hard
h1_jwt_bypassh2_redos_preventionh3_template_injectionh4_config_pollutionh5_multi_vuln
Each task includes deterministic functional and exploit tests with a normalized score in [0.0, 1.0].
Reward Design
- Partial credit is provided throughout the trajectory
- Both objective components must be high to get high reward
- Small non-zero fallback reward (
0.02) for safely executing code with no tests passed - Efficiency bonus when all tests pass in fewer attempts
Local Validation
cd kernel_env
.venv/bin/openenv validateLocal Run
cd kernel_env
.venv/bin/uvicorn server.app:app --host 0.0.0.0 --port 8000Docker
cd kernel_env
docker build -t kernel_env:latest -f server/Dockerfile .
docker run -p 8000:8000 kernel_env:latestRequired Inference File
- Root-level
inference.pyis included - Uses OpenAI client and reads:
API_BASE_URLMODEL_NAMEHF_TOKENLOCAL_IMAGE_NAME- Emits required
[START],[STEP],[END]log lines
Deploy to Hugging Face Spaces
cd kernel_env
.venv/bin/openenv push --repo-id <username>/kernel-env