Security fixes
Patch vulnerabilities without handing out keys
Point agents at dependency and code-scanning alerts. Each fix happens in an isolated microVM with only the access it needs, and lands as a pull request with an audit trail your security team can export.
Least privilege
Each agent reaches only the repositories and registries its badge names.
No keys in the sandbox
Secrets stay in the vault; agents get short-lived keys instead.
On the record
Every action lands in an audit log you can export to your own tools.
Read more
An agent set up for this
agent/patcher
Fixes security alerts
Claude SonnetOwner
Priya Nair
Security
- Repositories
- billing-serviceweb
- Network
- github.comregistry.npmjs.orgEverything else is blocked.
- Secrets, from the vault
- None
- Questions go to
- #security
Recent activity, as agent/patcher
- 11:20read dependency alert on billing-service
- 11:22pnpm update --latest the affected package
- 11:25open pull request #491
Give your agents badges, not keys
Kosem is in early access with a small group of engineering teams. Tell us about yours.