AI Vulnerability Scanning Harness
Budget / Salary$250–300
TypeFreelance project
LocationRemote
Posted1 hour ago
I need an AI-driven security harness whose single focus is vulnerability scanning. The agent should automatically inspect my codebase, exposed and internal APIs, as well as the cloud configuration that supports them, then flag weaknesses with clear, actionable findings.
Here is what matters most to me:
• A self-contained module or set of scripts that can be dropped into an existing CI/CD pipeline and triggered on every commit or on demand.
• AI-assisted detection that goes beyond simple signature matching—think pattern recognition and contextual reasoning to uncover insecure coding practices, misconfigured permissions, or outdated components.
• Coverage across three layers: the repository itself (static code analysis), live or staged endpoints (API interrogation), and infrastructure-as-code / cloud posture (config review).
• A concise report, preferably in both JSON and human-readable HTML/Markdown, ranking each issue by severity and suggesting remediation steps.
• Straightforward setup: environment requirements, installation commands, and an example project so I can verify results immediately.
If you plan to tap into tools such as Python, Node, OpenAI functions, or established scanners like Bandit, Semgrep, or Trivy, just outline how they fit into the overall workflow—the end product must still feel like one cohesive harness rather than a loose bundle of scripts. Unit tests and clear documentation will be part of the hand-off.
Once delivered, I will run the harness against a sample repository; acceptance is based on its ability to detect deliberately seeded flaws across code, API definitions, and Terraform-style cloud configs without producing excessive false positives.
Let me know your approach, the high-level architecture you envision, and any assumptions you’ll need from my side before we get started.
Here is what matters most to me:
• A self-contained module or set of scripts that can be dropped into an existing CI/CD pipeline and triggered on every commit or on demand.
• AI-assisted detection that goes beyond simple signature matching—think pattern recognition and contextual reasoning to uncover insecure coding practices, misconfigured permissions, or outdated components.
• Coverage across three layers: the repository itself (static code analysis), live or staged endpoints (API interrogation), and infrastructure-as-code / cloud posture (config review).
• A concise report, preferably in both JSON and human-readable HTML/Markdown, ranking each issue by severity and suggesting remediation steps.
• Straightforward setup: environment requirements, installation commands, and an example project so I can verify results immediately.
If you plan to tap into tools such as Python, Node, OpenAI functions, or established scanners like Bandit, Semgrep, or Trivy, just outline how they fit into the overall workflow—the end product must still feel like one cohesive harness rather than a loose bundle of scripts. Unit tests and clear documentation will be part of the hand-off.
Once delivered, I will run the harness against a sample repository; acceptance is based on its ability to detect deliberately seeded flaws across code, API definitions, and Terraform-style cloud configs without producing excessive false positives.
Let me know your approach, the high-level architecture you envision, and any assumptions you’ll need from my side before we get started.
Apply on Freelancer →
Project sourced from Freelancer.com. Applications happen directly on the original platform — we never collect your data.