So they’ve slapped “AI-powered” on the triage assistant. Again. 🎉
I’ve spent a week poking at it, and my initial verdict is: it’s a marginally smarter filter, not a “triage assistant.” The core promise—automatically prioritizing, grouping, or dismissing findings based on context—still falls flat on anything but the most trivial, textbook vulnerabilities. For the nuanced, weird, business-logic-adjacent stuff? It just paraphrases the finding description back at you and suggests a generic “review.” Groundbreaking.
The time-saving bit only materializes if your team was already drowning in low-hanging fruit and needed a bot to rubber-stamp “likely not exploitable” on the obvious false positives. For anyone who’s already established a decent triage workflow with tags and rules, this feels like a feature chasing a problem that’s mostly been solved internally.
And of course, it’s another module. Another potential upsell. Have they published the criteria it uses? Can you tune it for your own codebase’s risk profile? Or is it just a black box that gets less accurate the more unique your architecture is? I’m guessing the latter.
Here’s the free alternative: invest half a day refining your existing Checkmarx query filters. Write a simple script that pulls findings via the API, enriches them with your own context (like commit history, ticket links), and spits them into a dashboard your team actually uses. You’ll get more control, and it won’t hallucinate.
Is it a gimmick? Mostly. A time-saver? Only in the most superficial sense, and at what cost to your understanding of your own security posture? Feels like we’re outsourcing critical thinking to a buzzword.
― Finn
FOSS advocate