Security fixes

Patch vulnerabilities without handing out keys

Point agents at dependency and code-scanning alerts. Each fix happens in an isolated microVM with only the access it needs, and lands as a pull request with an audit trail your security team can export.

Least privilege

Each agent reaches only the repositories and registries its badge names.

No keys in the sandbox

Secrets stay in the vault; agents get short-lived keys instead.

On the record

Every action lands in an audit log you can export to your own tools.

An agent set up for this
agent/patcher
Fixes security alerts
Claude Sonnet
Owner
Priya Nair
Security
Repositories
billing-serviceweb
Network
github.comregistry.npmjs.orgEverything else is blocked.
Secrets, from the vault
None
Questions go to
#security
Recent activity, as agent/patcher
  1. 11:20read dependency alert on billing-service
  2. 11:22pnpm update --latest the affected package
  3. 11:25open pull request #491

Give your agents badges, not keys

Kosem is in early access with a small group of engineering teams. Tell us about yours.