SecuSense — Security Scan Triage and Explanation
Project Description
A team project in AI20K at VinUni where I was responsible for application development: a FastAPI backend and a React/TypeScript interface that connect Semgrep findings to a two-step LLM analysis — classifying results as true/false positive/uncertain, then generating explanations and remediation suggestions.
Overview
A team project in AI20K at VinUni; I was responsible for application development. SecuSense connects Semgrep findings to a two-step LLM analysis: (1) classify each result as true positive, false positive or uncertain; (2) generate an explanation and remediation suggestions, helping security practitioners triage scan results faster and more consistently.
Architecture & Technical Decisions
The FastAPI backend separates finding ingestion from the LLM analysis flow; the React/TypeScript interface shows each finding alongside its verdict and confidence. LLM calls go through LiteLLM; verdicts and confidence levels are normalized, and invalid JSON output is handled so the pipeline does not break mid-run.
Key Features
- Automatic triage of Semgrep findings: true positive / false positive / uncertain
- LLM-generated explanations and remediation suggestions per finding
- Normalized verdicts and confidence levels; invalid JSON output handled
- FastAPI backend with an intuitive React/TypeScript interface
Status
A team project of AI20K cohort 2 (C2-Team-001) at VinUni, completed on 2026-07-13; I was responsible for application development. There is no production deployment — the product is available only via the AI20K Cohort 2 showcase link and the GitHub repository. The repo README also mentions multi-tenancy, PayOS and MCP, but those are not verified contributions of mine and are therefore not claimed here.