Dependabot sync
Continuously bring GitHub Dependabot alert data into the repository scope you configure.
Security Agent turns GitHub Dependabot alerts into actionable Security Findings, identifies reachable risk, opens remediation PRs, sends deadline notifications, and preserves audit-ready activity history.
One operational record
Dependabot provides the source alert. Security Agent creates the Security Finding your team uses to analyze risk, coordinate remediation, meet deadlines, and retain evidence.
Continuously bring GitHub Dependabot alert data into the repository scope you configure.
Use a fast, configurable model to assess advisory context and decide which findings need deeper investigation.
Run sandbox analysis against repository code to find usage locations, reachable paths, evidence, and suggested fixes.
Choose a separate model to prepare manual or automatic remediation attempts for eligible findings.
Automatically open remediation PRs at your chosen severity threshold, with controls for existing findings.
Dismiss findings automatically when your configured analysis policy establishes that they do not require action.
Send new-finding, SLA warning, and SLA breach emails based on severity thresholds and warning lead time.
Set deadlines by severity and keep approaching or breached findings visible to the teams responsible.
Report recorded Security Finding activity for selected periods, repositories, severities, and states. Reports do not reconstruct activity that predates recorded history.
Risk analysis
Separate models keep each job focused. AI triage evaluates alert context first; sandbox analysis adds codebase evidence only when the finding needs it.
Stage 1
Evaluate package, advisory, severity, and dependency context without opening the repository sandbox. Route the finding to dismiss, review, or deeper analysis.
Stage 2
Inspect actual repository usage, identify relevant files and code paths, capture evidence, and recommend a concrete next action or fix.
End-to-end workflow
Every decision stays attached to the Security Finding, including analysis, remediation attempts, state changes, deadlines, and notifications.
Security Agent syncs GitHub source data from the repositories you select.
Kilo creates a working record with state, severity, ownership, and SLA history.
A dedicated triage model evaluates advisory and dependency context quickly.
When needed, an analysis model inspects repository usage and reachable code paths.
Dismiss, review, or remediate manually or automatically with an AI-generated PR.
A PR alone does not close a finding. Dependabot must report it fixed, or a user must dismiss it.
Deadline notifications and audit reports preserve evidence of what happened and when.
A remediation PR is an attempt, not proof of resolution. The Security Finding remains open until Dependabot reports the alert fixed or a user explicitly dismisses the finding.
Configuration
Configure Security Agent across General, Automation, Notifications, and SLA settings instead of forcing every repository through one workflow.
Operational posture
Filter by repository, severity, analysis outcome, and SLA due date. Move directly from the queue to review, fix, retry, or dismiss the finding.
Audit-ready history
Generate period-based reports by repository, severity, and recorded state. Expand any finding to review its timeline, source alert, package, manifest, SLA status, and activity history.
Find reachable risk, remediate eligible findings, keep teams ahead of deadlines, and preserve the activity history auditors need.