Cycode Adds Agentic Code Scanning to Control AI Review Costs
Cycode’s Agentic Code Scanning routes code review between AI and rule-based engines, with benchmark claims covering six CVEs, authorization flaws and MLflow detection volume.

Cycode has added Agentic Code Scanning to its application-security platform, DeveloperTech reported, using AI routing and attack-path analysis to decide when code review needs a reasoning model instead of a cheaper rule-based scan.
The launch targets a cost and coverage problem created by AI-assisted software security.
Security teams have to choose which model reviews each commit, whether every repository deserves continuous scanning and how to explain to auditors which engine produced a finding.
Cycode’s answer is not a single model, but a system that selects the scanning method for the code path and risk signal in front of it.
The company presents the feature as a fourth dimension of its code-defense approach, alongside three scanning methods already running in production.
All four dimensions examine the same code and reconcile their results into one risk view, with Agentic Code Scanning used where rule matching alone may miss a multi-step vulnerability.
The product builds a cross-file attack chain around related findings instead of treating each alert as isolated.
Cycode’s Context Intelligence Graph adds code-call links, ownership details and reachability data, then directs remediation toward the lowest-cost change that can break the exploit chain.
Those exploitability-qualified findings can also trigger Cycode’s Agentic Workflows.
Teams define the event trigger, action sequence, confidence threshold and control boundary once, after which the workflow routes the issue to the engineer who wrote the code and returns fixes as pull requests validated against the original finding.
Each run leaves an audit trail showing what triggered the agent, what it did and which boundary applied.
Benchmark claims form the most specific part of the launch.
Cycode says the evaluation covered ten repositories and six programming languages, with every repository fixed to the vulnerable commit under test.
The set included six published-CVE applications and four deliberately vulnerable applications with answer keys that the company says were not used for engine tuning.
Cycode says rival tools in the test produced no valid catches across the six published CVEs.
Its deterministic engine found three injection or traversal bugs out of six, while Agentic Code Scanning found all six.
Two of the missed cases were authorization flaws in Gitea and Next.js that no rule engine in the test caught, including Cycode’s own.
The MLflow arbitrary file-read case showed the difference between detection volume and root cause.
A taint rule fired 573 times in that repository, with two hits in the actual CVE file and total findings ranging from 173 to 701 per repository.
Agentic Code Scanning returned one validated, root-caused finding for each CVE.
The test corpus and configurations are being published for reproduction, which gives customers a way to examine the claim beyond a closed vendor benchmark.
The open question for security teams is narrower than whether AI should review code at all: the buying test becomes whether agentic review can catch authorization and path-based vulnerabilities without turning every commit into an unmanaged model-cost event.
These are company-reported benchmark results.
Whether the same detection rate holds across a broader range of repositories, languages or vulnerability classes remains untested in the material released so far.




















