Today, Knostic is releasing Auto Patcher for OpenAnt, our open-source vulnerability discovery and remediation harness.
Generating a patch isn't good enough. What we need is trust.
- How do you know the patch actually fixes the vulnerability?
- Did it fix the root cause, or just the symptom?
- What else did it change?
- Could it introduce a new security or regression risk?
- What did we actually verify - and what is still unknown?
OpenAnt investigates the vulnerability and the repository, generates a candidate fix, challenges its own conclusions, collects evidence around the patch, and produces a Trust Report.
A patch + evidence + a recommendation.
While imperfect, we believe we've built something important here:
An evidence infrastructure for AI-generated code.
Try it. Break it. Run it on real vulnerabilities. Challenge the trust model. Add evidence sources. Show us where we're wrong.
Autonomous patching has a long way to go.
Let's create the trust layer it needs to get there.
Thank you Ela Avrahami for all the work on making this happen!
At Knostic. we're building a world-class AI security company, from securing your agents to securing the AI-native development lifecycle. And, we believe this only gets better by building it with the community.