Radar / Ideas / Shipgate: a merge queue that never…

Shipgate: a merge queue that never ships a bad agent PR

daily ideaambitiousJEV confidence 0.452026-10-06
OutcomeAI-generated pull requests can never ship exploitable code: every agent PR is red-teamed, safeguard-checked, and judgment-gated before it merges.

The problem

AI agents now write most new code and it ships vulnerabilities: Snyk's research across 4,800 customers found a 108% increase in newly introduced issues as AI-generated code scaled; a Plugin4Shell zero-click RCE hit Codex, Claude Code, Gemini CLI, and Copilot; Stanford research showed developers using AI assistants create more vulnerabilities. Scanners built for human PRs catch patterns but do not understand agent behavior, and the human review every agent PR gets does not scale.

The idea

A GitHub App merge gate built specifically for agent-authored PRs. On each PR: an attacker agent performs agentic vulnerability discovery on the diff (VVAH-style), cyber-safeguard checks run against the shared standards the labs just released, and a Jev-class typed judgment layer renders approve/queue/block verdicts with reasons. Blocked PRs get auto-fix suggestions, and a clean record builds a reputation score per agent identity so trusted agents merge faster over time.

Why now

This week's unprecedented joint cyber-safety release from OpenAI, Anthropic, and Google DeepMind created the first shared baseline of cyber safeguards to check against; Visa open-sourced VVAH (agentic vulnerability discovery) on Sept 30; and Snyk Evo's 81.5% month-over-month growth proves enterprises are already paying for agent-native security.

What it combines

Joint-lab cyber safeguards (security/compliance) plus Visa VVAH agentic discovery (security) plus Jev-Omni typed judgments (models/decision): static scanning finds patterns, an attacker agent finds exploitable paths, and typed judgments turn findings into enforceable merge decisions. Together they form a full gate, not another scanner.

MVP

GitHub App for one language (Python): run static rules plus an attacker-agent pass on the diff and post a judgment verdict as a merge check. Deliberately skip auto-fix in v1, reputation scoring, and multi-language support.

Distribution

B2B2C: ship as a GitHub/GitLab marketplace app where developers already merge, then upsell to the platforms (GitHub Advanced Security, GitLab Ultimate) as their agent-PR gate.

Why it wins

Semgrep, Snyk, and Checkmarx scan artifacts after the fact; Snyk Evo adds agent supply-chain scanning but not per-PR adversarial discovery combined with a typed approval gate. Nobody puts agentic red-teaming and a judgment verdict inside the merge queue itself.

Risks

False positives block velocity and teams disable the gate. De-risk with a warn-only mode first, measuring precision on real PRs before ever enforcing.

Build it with

Repo to start from

shipgate - a GitHub App that gates agent-authored PRs: agentic vulnerability discovery plus cyber-safeguard checks plus typed judgment verdicts as merge checks.

Evidence

Get the week's best AI launches, plus 3 ideas worth building

One email every Saturday. Ranked by traction, not hype. Free.