← Founder Notes
Archive

Google just inverted the security review pipeline. on september 18 it disclosed agentic code…

Yethikrishna ROriginal on Threads

google just inverted the security review pipeline. on september 18 it disclosed agentic code security, which replaces late repository-wide sweeps with narrow reviews triggered by each individual code change.

the gate moved from release time to change time.

Context

The Google Cloud post Changing the game: Using agentic AI to secure infrastructure code, dated 18 September 2026 by the aggregators, was read only through a mirror on roboticcontent.com that tags itself as AI generated content and an analysis on keganquimby.com of 21 September 2026; the original Google URL was not fetched. The mirror describes pre-submit scanning of each code check-in with AI agents, the open-source multi-agent review harness Mantis with localized threat models, a two-step validation of a quick scan then a structural triage agent, and a bug-fix agent that submits fixes for human review. The analysis reports three outcomes, hundreds of vulnerabilities prevented per month, false positives as low as 3 percent in some cases and triage precision of more than 92 percent, and notes the post gives no independent evaluation dataset or denominator.

How it compares

Everything here comes from a secondary mirror and an analysis, so the claims and the numbers are unverified against Google's own text. It is Google's account of its own infrastructure code and company-reported, not an independent benchmark. Mantis itself was announced earlier in September per a snippet. Google's August post on its agentic vulnerability discovery harness sweeps source code, while this work places a scan at each check-in. That the gate moved from release time to change time is the author's thesis.

Watch next

  • Google's original post for the metric definitions and any third-party reproduction.

Sources

  1. Changing the game: Using agentic AI to secure infrastructure code (mirror, 19 Sep 2026)roboticcontent.com
  2. Google Mantis agentic security analysis (Kegan Quimby, 21 Sep 2026)keganquimby.com
  3. Security Feed listing of the Google post (18 Sep 2026)securityfeed.link

Provenance

The note above is reproduced unedited from the original post, first published on Threads on 20 September 2026 at 11:18 IST. Sources are the papers and datasets the note draws on.

View the original post
Embed this note
<iframe src="https://founder.myndlabs.tech/notes/embed/google-just-inverted-the-security-review-pipeline-on-Ddf3wavCPNW" width="480" height="420" style="border:0;max-width:100%" loading="lazy" title="Google just inverted the security review pipeline. on september 18 it disclosed agentic code…"></iframe>

More notes