ai-deep-sast

Sources: GitHub — cisco-open/ai-deep-sast · OSS AI Security Harness Comparison.

Identity and role

ai-deep-sast is an open-source SAST+LLM hybrid vulnerability scanner published under Cisco’s Cisco Open program. In Semgrep’s July 2026 survey of open-source AI code-security harnesses, the project held about 50 GitHub stars and an Apache 2.0 licence, the smallest following of the nine projects compared.1 Semgrep places it in the SAST+LLM hybrid category: tools that use deterministic program analysis to narrow an LLM’s search space before the model reasons over what remains.

Mechanism

Semgrep’s LLM-generated summary of the repository describes a hybrid SAST tool written in Python.2 The Semgrep engine performs fast, rule-based detection; a large language model then triages each finding behind an “evidence gate” meant to surface only true positives. A fast-scan mode can run entirely on a local, security-tuned 8B-parameter model, Foundation-Sec-8B, so no code leaves the machine. A deep-scan mode instead hands function-level context to a frontier model, unnamed in the source. The same summary calls the optional fully local mode a genuine privacy differentiator and notes the project is brand new, at v1.0.0.

Output and capability matrix

Findings export as Markdown, JSON, or JUnit, with severity gates usable in CI.2 Semgrep’s capability-matrix table, also LLM-generated, scopes the tool to the OWASP/CWE Top 25, secrets, and AI/ML-specific findings across 30 or more languages.2 The matrix records ai-deep-sast’s isolation posture as “n/a (static)”: the tool performs no dynamic execution, so no execution sandbox applies, unlike the pipelines in the comparison that compile or run the code they analyze.2

Positioning

Semgrep names ai-deep-sast as the harness to reach for when the requirement is running fully local and offline. Of the nine projects compared, only ai-deep-sast can run entirely on-device, a choice Semgrep frames as trading depth and proof for breadth and speed. In the comparison’s “finding” table, an ai-deep-sast finding is a triaged static match; in the execution table, the tool neither executes code nor produces a proof of concept or a patch, offering advice only.

See Also

Footnotes

  1. Star count as reported by Semgrep in its July 2026 survey; a point-in-time figure.

  2. From Semgrep’s LLM-generated summary of the repository, not the survey’s human-written body. 2 3 4