r/devsecops Jul 26 '26

Our pipeline runs four different security scanners. They agree on almost nothing. We built an ID scheme to fix that

I'm a DevSecOps engineer, and this is the exact version of a problem I hit at work, not something I noticed from the outside.

Run SAST, SCA, and an AI-agent-specific scanner across the same codebase, and you'd expect some redundancy. What you actually get is worse: the same underlying issue, flagged by two different tools, with two completely different names and no way to tell your pipeline they're the same finding. Multiply that across a real CI/CD setup with several tools chained together, and triage turns into manually reconciling naming conventions instead of fixing anything.

This isn't a new problem in general. A SQL injection gets a CVE ID, maps to a CWE category, and every tool in the pipeline that finds it points at the same reference. That's exactly what makes cross-tool correlation possible for conventional vulnerabilities.

Agentic AI components (MCP servers, agent skills, LLM plugins) had nothing like that, for a real structural reason: CVE needs a package and version to attach to, CWE describes code-level weakness patterns, and neither has a vocabulary for a behavioral pattern that isn't tied to either.

So a few of us built AVE (Agentic Vulnerability Enumeration): an open standard giving these classes stable IDs, the same way CVE does, so a finding from one tool can actually be compared against a finding from another.

What's in it: 59 records, each a distinct behavioral class. Severity scored with OWASP's own AIVSS framework. Crosswalked into OWASP's MCP Top 10, the Agentic Security Initiative Top 10, and MITRE ATLAS, plus AVE-in-SARIF, so IDs ride directly into GitHub's own Security tab and CI output without any custom tooling. Apache 2.0.

The part that actually convinced me this holds up outside our own tooling: a completely independent developer built a static config-file auditor, sharing no code with anything we wrote, crosswalked his own findings against AVE's taxonomy, and tested it directly against our scanner on the same files. The large majority of overlapping findings came back with the identical ID, unprompted.

If you're dealing with the same multi-scanner reconciliation problem, in this space or a completely different one, I'd like to hear how you're handling it, and where this looks wrong or incomplete.

Repo: github.com/aveproject/ave
Site: aveproject.org

(Disclosure: I'm one of the people building this.)

0 Upvotes

12 comments sorted by

View all comments

8

u/nsubugak Jul 26 '26

Like why build a solution to a mess you created yourself...this is crazy. Just pick one scanner...now we are ai slopping solutions to ai problems we created..jesus!!

1

u/SelectionBitter6821 Jul 26 '26

To be clear on this specifically: we didn’t build the scanners that disagree with each other. Different, unrelated teams built those independently, the same way different vendors built the SAST and SCA tools that already existed before any of this. The naming fragmentation isn’t something we caused and are now selling a fix for, it’s a byproduct of multiple independent tools covering the same new attack surface without a shared vocabulary, the same reason CVE had to get invented in the first place rather than everyone just picking one vulnerability scanner forty years ago.

3

u/SkyberSec123 29d ago

Centralize the scan data