Factory launches Automated Security Review in Droid
Factory has introduced Automated Security Review for Droid, its AI-native software development agent, to automatically perform STRIDE-based reviews on all pull requests and post inline comments on code diffs. Developers can also trigger these security audits on-demand for their entire repository or current diff using the "/security-review" command.
Embedding security threat modeling directly into AI developer agents shifts security reviews from a post-development gatekeeper to a continuous, real-time participant in the development lifecycle.
- –Structured methodology: Utilizing the STRIDE framework ensures that coding agents cover a comprehensive range of threats, including privilege escalation and information disclosure.
- –Interactive audits: The ability to invoke audits on-demand via slash commands enables developers to secure their work prior to opening a PR.
- –Production validation: Successfully identifying and disclosing a WorkOS Node SDK vulnerability validates the tool's real-world bug-hunting capability.
DISCOVERED
50d ago
2026-06-11
PUBLISHED
50d ago
2026-06-11
RELEVANCE
AUTHOR
FactoryAI