Trust boundaries become navigable evidence.
Entrypoints, identities, stores, providers, and privileged transitions stay connected to the findings that depend on them.
Evidence-first AppSec · Apache-2.0
Scanners discover. Agents investigate. SecHelix turns every signal into an auditable evidence path, challenges the claim independently, fixes the root cause, and proves the release decision.
SHX-AUTHZ-L02-DEMOA missing seller identity widened the repository query beyond the caller ownership boundary.
A scanner alert is not a vulnerability.A model suspicion is not a vulnerability.Two models agreeing is not independent proof.
Verify before you accuse.One operating model
Each layer changes the confidence state. Nothing jumps from “scanner said so” to “Critical” without a traceable reason.
Security intelligence surface
The interface exposes the security model itself: boundaries, identities, object access, state changes, variants, and evidence provenance.
Entrypoints, identities, stores, providers, and privileged transitions stay connected to the findings that depend on them.
Expected and observed permissions can be compared across identities and object ownership boundaries.
Verified root causes become focused variant searches instead of another broad scan.
Models and scanners contribute observations; none can promote their own output to truth.
Unknown integrity-critical coverage can never silently become a green check.
Canonical mappings, live research, lesson cards, and source trust are separate from local vulnerability proof.
The Evidence Workbench
Follow the exact transition from hypothesis to observed evidence, independent verdict, root-cause repair, regression, and gate decision.
Open the canonical findingRegression PASS · Release PASS
Truth has a schema
The public aggregate remains NOT_MEASURED until a reproducible run records inputs, configuration, outputs, and evidence. The interface shows the absence of measurement instead of manufacturing confidence.
Open intelligence, governed quality
Open Agent Skill
Install the portable SecHelix skill, authorize the repository or environment, and start from system understanding—not from a pile of alerts.
npx skills@latest add omarmohelal/SecHelix --skill sechelix