Autofix Bot
Hybrid static analysis and AI code review agent
Details
- External ID
- 46237358
- Source
- HN
- Company
- —
- Product
- —
- Website domain
- —
- Launched
- Dec. 11, 2025
- Cohort
- —
- Upvotes
- 37
- Upvotes percentile
- 0.7690839694656488
- Tags
- —
- Fetched at
- Sept. 7, 2026, 9:25 p.m.
- Updated at
- Sept. 7, 2026, 9:25 p.m.
Description
Hi there, HN! We’re Jai and Sanket from DeepSource (YC W20), and today we’re launching Autofix Bot, a hybrid static analysis + AI agent purpose-built for in-the-loop use with AI coding agents.AI coding agents have made code generation nearly free, and they’ve shifted the bottleneck to code review. Static-only analysis with a fixed set of checkers isn’t enough. LLM-only review has several limitations: non-deterministic across runs, low recall on security issues, expensive at scale, and a tendency to get ‘distracted’.We spent the last 6 years building a deterministic, static-analysis-only code review product. Earlier this year, we started thinking about this problem from the ground up and realized that static analysis solves key blind spots of LLM-only reviews. Over the past six months, we built a new ‘hybrid’ agent loop that uses static analysis and frontier AI agents together to outperform both static-only and LLM-only tools in finding and fixing code quality and security issues. Today, we’re opening it up publicly.Here’s how the hybrid architecture works:- Static pass: 5,000+ deterministic checkers (code quality, security, performance) establish a high-precision baseline. A sub-agent suppresses context-specific false positives.- AI review: The agent reviews code with static findings as anchors. Has access to AST, data-flow graphs, control-flow, import graphs as tools, not just grep and usual shell commands.- Remediation: Sub-agents generate fixes. Static harness validates all edits before emitting a clean git patch.Static solves key LLM problems: non-determinism across runs, low recall on security issues (LLMs get distracted by style), and cost (static narrowing reduces prompt size and tool calls).On the OpenSSF CVE Benchmark [1] (200+ real JS/TS vulnerabilities), we hit 81.2% accuracy and 80.0% F1; vs Cursor Bugbot (74.5% accuracy, 77.42% F1), Claude Code (71.5% accuracy, 62.99% F1), CodeRabbit (59.4% accuracy, 36.19% F1), and Semgrep CE (56.9% accuracy, 38.26% F1). On secrets detection, 92.8% F1; vs Gitleaks (75.6%), detect-secrets (64.1%), and TruffleHog (41.2%). We use our open-source classification model for this. [2]Full methodology and how we evaluated each tool: https://autofix.bot/benchmarksYou can use Autofix Bot interactively on any repository using our TUI, as a plugin in Claude Code, or with our MCP on any compatible AI client (like OpenAI Codex).[3] We’re specifically building for AI coding agent-first workflows, so you can ask your agent to run Autofix Bot on every checkpoint autonomously.Give us a shot today: https://autofix.bot. We’d love to hear any feedback!---[1] https://github.com/ossf-cve-benchmark/ossf-cve-benchmark[2] https://huggingface.co/deepsource/Narada-3.2-3B-v1[3] https://autofix.bot/manual/#terminal-ui
Enrichment
- Theme
- AI agent frameworks and developer tools
- Vertical
- Horizontal
- Function
- Agent / copilot
- Audience
- Developer
- AI stance
- AI-native
- Project type
- Commercial product
- Normalized one-liner
- code review agent with static analysis
- Manually corrected
- False
Could you build this?
Partial While an AI PR-review wrapper is trivial to build, writing accurate, high-fidelity static analysis engines with automated AST-safe code rewrite rules requires serious AST compiler expertise.
What it would actually take: A real version requires building language-specific AST parsers and control-flow/data-flow analyzers (using tools like Tree-sitter or compiler frontends) paired with deterministic autofix rewrite rules, orchestrated alongside LLM verification agents. Building reliable rule engines without introducing regressions demands dedicated compilers and program analysis engineers.
Discussion
13 comments analyzed.
Competitors mentioned: Claude Code, Cursor Bugbot, Gemini Code Assist, Semgrep CE
Concerns raised: Pricing ($8/100k LoC) potentially high for iterative development/frequent runs, Unclear charging model for moved/deleted/test files, High false positive rate compared to static analysis tools, Developer adoption risk if requires frequent local execution, AI-generated code tends to be verbose and tangled
Feature requests: Custom coding guidelines definition, Code complexity detection, AGENTS.md support/respect, Gemini Code Assist and Gemini CLI benchmarking, OSS scanning
Competitors
Other products that read as similar to this one — 1005 launches clear the similarity bar, closest 8 shown.
Attention rank: #209 of 1006 (itself plus its competitors, highest first — normalized so YC and Product Hunt are compared fairly).
Launched 43 days after the earliest competitor.
- sloppy · github · 2026-09-10 · 13 upvotes · similarity 0.55
- agenteval · hn · 2026-04-03 · 7 upvotes · similarity 0.54
- Spec27 · hn · 2026-04-30 · 13 upvotes · similarity 0.54
- Multi-Agent Code Review · hn · 2025-11-04 · 5 upvotes · similarity 0.52
- Mini-coder · hn · 2026-03-02 · 6 upvotes · similarity 0.51
- Morph Reflexes · hn · 2026-06-30 · 20 upvotes · similarity 0.50
- Remy, an AI agent that compiles annotated Markdown into full-stack apps · hn · 2026-04-13 · 5 upvotes · similarity 0.50
- LLM agents that write Python to analyze execution traces at scale · hn · 2026-03-07 · 5 upvotes · similarity 0.50
Other launches for this product
- No other launches for this product.
Same idea, different domain
Nobody's really built a agent / copilot tool for Agriculture yet.