Feature-centric deep incremental security review harness for Git-backed code changes, with autonomous, agents, and hybrid execution modes.
Optional graph-context enrichment for feature-centric incremental security review using CodeGraph or code-review-graph when available.
Pre-report finding verification contract. Re-checks whether each vulnerability has a real external Source, reachable Sink, bypassable or missing sanitization, and practical exploitability before final reporting.
Sink chain deep tracing methodology with graded code output templates (Critical full-chain / High-Medium key-nodes), reverse tracking rules, and per-hop Read verification.
Agent contract templates for R1 and R2+ rounds, including output format, token budget management, truncation defense, and auto-injection prompt templates.
Jalor internal Spring framework audit extension for endpoint operation authorization and service audit logging coverage.
Two-layer checklist architecture with D1-D10 security coverage matrix and language-specific semantic prompts for gap verification after free audit.
Structured security audit report template focused on exploit narrative, root cause, verified source-to-sink data flow, key code analysis, PoC, and minimal remediation notes.