Introducing Automated Security Review
Blog post from Factory
Factory has introduced automated security review in Droid, which performs STRIDE-based assessments on every non-draft pull request alongside standard code review and posts validated findings as inline comments with severity levels, CWE references, explanations, and suggested fixes. The system targets threats including spoofing, tampering, information disclosure, denial of service, privilege escalation, OWASP Top 10 and LLM Top 10 issues, injection, authentication weaknesses, and secrets exposed in logs. Droid creates a lightweight threat model of changed code, scans for vulnerabilities, validates potential issues against the diff to reduce false positives, and provides a deduplicated PR summary. The company cites production audits that led to responsibly disclosed findings, including CVE-2026-42876 in external-secrets and a webhook signature verification issue in the WorkOS Node SDK. Users can install the feature through Droid’s code-review setup, run on-demand repository or diff audits with a CLI command, and use deeper multi-agent full-repository audits through GitHub Actions or Droid Missions; the capability is available on all plans.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| Secrets Management | 3 | 2,539 | 400 | 136 | +9% |
| LLM | 2 | 6,292 | 1,205 | 252 | -36% |
| Kubernetes | 1 | 2,083 | 321 | 111 | +3% |
| Multi-agent systems | 1 | 556 | 175 | 81 | -7% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.