What problem does it solve?
Bridges the gap between discovering findings and implementing fixes by enabling cross-pipeline remediation: red team, audit, review, UI, and external reports produce tracked tickets, dispatched stateless implementer/reviewer agents, and verified fixes.
Core Features & Use Cases
- Uniform Artifact Model: all sources produce identical records with fields like ID, SEVERITY, CONFIDENCE, LOCATION, CATEGORY, DESCRIPTION, IMPACT, REMEDIATION, EFFORT, VERIFICATION_DOMAIN.
- Ticket-driven context store: agents read and write only by ticket reference, enabling stateless orchestration.
- End-to-end process: triage, ticket creation, plan, execution, and verification across multiple source types.
- Verification strategies: per-source re-runs (redteam purple, audit sector, review re-run, ui-review), ensuring fixes are validated before closure.
- Atomic fixes: one finding per commit with clear rollbacks and traceability.
- Non-intentional flags: support for INTENTIONAL markings and non_negotiable decisions to suppress auto-issue creation when needed.
Use cases: applicable to security findings, compliance gaps, or quality issues across pipelines.
Quick Start
Provide triage output to remediation to kick off ticket creation, assignment, and automated verification.