Devin Review adds automated security audits
Cognition has added automated security reviews to Devin Review, enabling the AI agent to analyze entire codebases for complex logic flaws and chained vulnerabilities. For each finding, Devin classifies severity, tags a CWE ID, explains the issue, and drafts a merge-ready PR containing the fix.
Incorporating deep-reasoning security audits into pull requests is a major evolution from standard static analysis tools, though the utility hinges on the accuracy of the AI-generated fixes.
- –**Context-Aware Auditing:** Reasoning across the whole codebase allows Devin to catch complex business-logic flaws and chained exploits that siloed file scanners miss.
- –**Actionable Fixes:** Rather than just flagging issues, drafting merge-ready PRs significantly reduces developer overhead for security remediation.
- –**CWE Integration:** Categorizing findings with CWE IDs and severity rankings ensures standard vulnerability tracking and easier triaging.
- –**Trust Barrier:** Developers will still need to carefully review the AI's generated fixes to ensure they don't introduce regressions or security loopholes.
DISCOVERED
1h ago
2026-06-18
PUBLISHED
1h ago
2026-06-18
RELEVANCE
AUTHOR
cognition