Skip to content
SecHelixv3 alpha
GitHub
PlatformWorkbenchBenchmarksDocsContributeGitHub

Evidence-first AppSec · Apache-2.0

Security findings are claims.SecHelix proves them.

Scanners discover. Agents investigate. SecHelix turns every signal into an auditable evidence path, challenges the claim independently, fixes the root cause, and proves the release decision.

structured hypothesesstable coverage IDs
546
security familiesAUTH → AI/MCP
21
analysis lensesper hypothesis
26
specialist rolesone evidence contract
17
JSON contractsmachine-checkable
15
tool adapterssignals, not verdicts
9
canonical fixture / evidence console live ui
SHX-AUTHZ-L02-DEMO

Seller boundary omission

A missing seller identity widened the repository query beyond the caller ownership boundary.

VERIFIEDHIGH
HypothesisEvidenceVerifyRoot causeFixRegressionRelease
  • Attacker controlObserved
  • ReachabilityObserved
  • Boundary failureObserved
  • Independent verifierConfirmed
  • RegressionPASS
  • Release gatePASS
Evidence state is primary. Severity never substitutes for proof.Inspect lineage
Signals in. Verdicts earned.
SemgrepCodeQLOSVGitleaksTrivyPlaywrightZAPNucleiSARIFSemgrepCodeQLOSVGitleaksTrivyPlaywrightZAPNucleiSARIF
// the standard

A scanner alert is not a vulnerability.A model suspicion is not a vulnerability.Two models agreeing is not independent proof.

Verify before you accuse.

One operating model

AppSec that behaves like an investigation, not an alert feed.

Each layer changes the confidence state. Nothing jumps from “scanner said so” to “Critical” without a traceable reason.

  1. 01

    Map

    Understand the system before you test it.

    Build identities, entrypoints, stores, trust boundaries, role-object actions, and state transitions before loading security hypotheses.
  2. 02

    Investigate

    Convert noisy signals into evidence.

    Specialist lanes trace attacker control, reachability, failed boundaries, second-order paths, business invariants, and variants.
  3. 03

    Challenge

    Make a neutral verifier try to break the claim.

    High-impact candidates are reconstructed from scratch. Missing attacker control or a compensating control can kill the finding.
  4. 04

    Prove

    Fix the invariant and prove the regression.

    Root-cause remediation, variant search, regression proof, and release policy live on the same evidence lineage.

Security intelligence surface

See the system the way the verifier sees it.

The interface exposes the security model itself: boundaries, identities, object access, state changes, variants, and evidence provenance.

Model + Tool Meshmodel-agnostic

Different lanes. One evidence contract.

Models and scanners contribute observations; none can promote their own output to truth.

Release Gatefail closed

The release decision is an artifact, not a mood.

Unknown integrity-critical coverage can never silently become a green check.

Knowledge Graphprovenance first

Research stays attached to definitions, versions, and rights.

Canonical mappings, live research, lesson cards, and source trust are separate from local vulnerability proof.

The Evidence Workbench

A finding is a journey, not a red card.

Follow the exact transition from hypothesis to observed evidence, independent verdict, root-cause repair, regression, and gate decision.

Open the canonical finding
Evidence / SHX-AUTHZ-L02-DEMO
VerifiedHigh
01 / Hypothesis

Can a seller read listings outside their ownership boundary?

Selected by applicability engine
02 / Evidence
  • attacker control
  • reachability
  • boundary failure
  • root cause
Missing seller identity widened the repository query.
03 / Verification
Independent verdictVERIFIED

Regression PASS · Release PASS

Truth has a schema

No benchmark theater.

The public aggregate remains NOT_MEASURED until a reproducible run records inputs, configuration, outputs, and evidence. The interface shows the absence of measurement instead of manufacturing confidence.

Open Benchmark Lab
evaluation aggregateNOT_MEASURED
Precisionawaiting reproducible run
Recallawaiting reproducible run
Verified precisionawaiting reproducible run
False-positive rateawaiting reproducible run
Signed inputs Reproducible runner Evidence outputs Publish measurement

Open intelligence, governed quality

Extend the security knowledge. Keep the evidence bar.

ProposeGold Pack, adapter, fixture, or researchValidateSchemas, tests, provenance, and safe controlsReviewSecurity and maintainer quality gatesPublishVersioned official capability

Open Agent Skill

Put verification discipline inside the tools you already use.

Install the portable SecHelix skill, authorize the repository or environment, and start from system understanding—not from a pile of alerts.

terminalSecHelix installer
npx skills@latest add omarmohelal/SecHelix --skill sechelix
model-agnostic · local-first · evidence-first