Fix · SAST Auto-fix

Vulnerable code, fixed. Deterministically.

Finding the SQL injection is the easy part. Heeler writes the fix, proves it in your build, and opens a merge-ready pull request. A computed code change, not a model’s prediction.

Why not just use an LLM? ↓
Automated workflow · 24/7 · no human in the loop
Remediate SQL injection in orders/query.py
Autotriage
Urgent · fix now
Tier 1 · Production
Entry point: HTTP handler
Internet accessible
No authentication
Touches PII
CWE-89 · CWE Top 25
Mitigated: No
Deterministic fix
Parameterize · effort low
Decided at scan time, not LLM reasoned
Traced source to sink, cross-file
Strategy matched to the weakness
Before-and-after change
F-string rewritten to a bound parameter
Agent validation
Merge-ready PR #612 created
Built in a sandbox with your toolchain
Adapted to the surrounding code
CI: 1 failure repaired · 38 green
Developer comment addressed
Cursor Bugbot feedback integrated
Your conventions applied from memories
Every step auditable
✓ Developer merges · SQL injection closed
How it works

Heeler calculates what to fix first and the exact code change, then proves it builds. Your CI signs off.

AGENTIC VALIDATION · SANDBOX, THEN YOUR CIAutotriageUrgent · Plan · DeferCalculate fixdeterministic · SCA · SASTSandbox buildremediation harnessPR openedwith detailed contextRepair loopCI · comments · botsMerge-readyall checks greenRepair on redpushes a fix commit · CI re-runsAgent memoriesread before each run, written back after1234writes backwhat it learned
1

Decide what to fix first

  • Urgent, Plan or Defer, by real exposure
  • Exposure judged from the path, not the service
  • Re-evaluated as your environment changes
  • Automated SLO management
Autotriage →
2

Deterministic code fixes

  • Decided during the scan, not predicted by a model
  • Strategy matched to the weakness
  • Checked against the traced tainted values
  • No diff unless it clears the confidence bar
3

Proven by the fix agent

  • Never review a fix that won’t build
  • Builds the way your repo builds
  • Adapts the fix to the surrounding code
  • Unproven fixes arrive as drafts
4

Repair loop

  • Edits your code to clear failures
  • Developers comment; it revises
  • Takes feedback from review bots
  • Merge-ready when every check is green
Autotriage

The most dangerous get fixed first. Then the rest burn down.

A deterministic decision tree traces each flow from entry point to sink and uses context from code to cloud to decide what is real risk. Consistent, auditable, and re-evaluated as your environment changes.

Business impact
Tier
Environment
Exposure · judged from the path
Network entry point
Internet accessible
No authentication
Not mitigated
Blast radius
Sensitive data
Chaining
Weakness threat
Indicator of compromise
Known-exploited weakness class
CWE Top 25
Urgent

A dangerous weakness on an exposed, high-value service.

Auto-fix now
Plan

Real risk, but lower exposure or a lower-tier service.

Scheduled
Defer

Not exposed, with nothing sensitive or chainable in reach.

Burned down on a clock
What it fixes

Five strategies, each matched to the weakness.

Each fix addresses the root cause, not the symptom. Findings that need an architectural change get written remediation guidance instead of a risky pull request.

SQL, NoSQL and GraphQL injection

Parameterize

Rewrites the query to use safe parameter binding instead of string interpolation.

XSS, command and log injection

Escape

Applies the correct escaping for the output context: HTML, shell, logs, headers and so on.

Path traversal

Path normalize

Resolves and validates file paths so input cannot climb out of the intended directory.

SSRF, open redirects and IDOR

Allowlist

Checks the value against a known-safe set of hosts, targets or identifiers before it reaches the sink.

Weak crypto and insecure defaults

Replace

Swaps the unsafe call for a safe one: MD5 to SHA-256, insecure random to a secure source, == to a constant-time compare.

The deterministic fix

The code fix is calculated, not predicted.

Heeler traces untrusted input to the sink during the scan and matches a fix strategy to the weakness. Same finding, same fix, every run.

routeAnchored to the traced source-to-sink path
targetStrategy matched to the weakness
differenceThe exact before-and-after change
verifiedChecked to touch the traced tainted values
edit_noteGuidance instead of a diff when a fix needs redesign
account_treePicked by your context: trace, weakness, code
SQL injection · CWE-89 · Urgentacme/orders
Source to sink, traced at scan time
public
Sourceapi/orders.py:41request.args["status"]
arrow_forward
swap_horiz
Passed throughorders/service.py:63list_orders(status)
arrow_forward
database
Sinkorders/query.py:88cursor.execute(f"…")
Strategy matched to the weakness
check_circleParameterizeEscapePath normalizeAllowlistReplace
The calculated change
−cursor.execute(f"SELECT * FROM orders WHERE status = '{status}'")
+cursor.execute("SELECT * FROM orders WHERE status = %s", (status,))
checkTouches the traced tainted valuecheckConfidence high: ships as a diffFit to your code, provided to the fix agent
The agent loop

The fix agent proves it in your build.

The fix agent, on the best model for each task, applies the calculated fix and keeps going until every check is green.

deployed_codeBuilds in a sandbox with your toolchain
ruleFollows your conventions: lockfiles, test command
codeAdapts the fix to the surrounding code
syncRepairs CI failures in a bounded loop
forumAddresses developer and review-bot feedback
receipt_longRecords every step, hands off when it can’t finish
psychology
It learns your reposMemories are read before every run and written back after, so each fix starts where the last one left off.
hubHeeler’s harness + the best model for each task
Agent executionSQL injection · orders/query.py · PR #612
Merge-ready
downloadLearn
Memories read
queries use db.fetch_all helperpytest -m "not slow"ruff format
deployed_codeBuild
Sandbox: Python 3.11 · Poetrypassed
cursor.execute(…, (status,))arrow_forwarddb.fetch_all("… WHERE status = %(status)s", {"status": status})
Same parameterized query, written the way this repo writes queries
syncProve
PR #612 opened, then your CI
closeCI run 1 · 1 failedarrow_forwardbuildRepair commitarrow_forwardcheckCI run 2 · 38 green
forumReview
BugbotAdd a test for the status filterDeveloperKeep the query in one line
forum2 commentsarrow_forwardbuildRevision commitarrow_forwardcheckCI run 3 · 38 green
uploadRemember
Memory written
orders: status filter tests live in tests/test_query.py
front_handCan’t finish cleanly? Hands off with a commentreceipt_longEvery step logged in Heeler
After the merge

Merge isn’t the finish line. Deployed is.

Heeler correlates your running deployments back to source, so a fix closes only when the corrected code is seen running. No runtime agent, no tagging, no sign-off.

Active
The vulnerable path is running.
Fixed
The change merged. An assumption about production.
Deployed
The corrected code is seen running, everywhere it ran.
orders/query.py fix · deployed share
3 of 3 running deployments
orders-api · prod-us
orders-api · prod-eu
orders-worker · prod
Three ways a fix starts

Start a fix from the app, a pull request or a workflow.

In the app
SQL injection · orders/query.py:88 · parameterize
Fix Now
Path traversal · files/export.py:41 · normalize
Fix Now

Fix Now from the finding

The before-and-after change is already on the finding, with its strategy and confidence. One click starts the run.

On the pull request
✗ Heeler · SAST Guardrail
PR #612
new SQL injection · api/search.py:52
Apply suggestion

Fix it where it fired

A guardrail flags the change on a developer’s PR and Heeler offers the fix there. One click, and the check flips to passing.

Automatically
New SAST finding
→
Fix with Heeler Agent
→
Ticket assigned
PR opened

Fixing as policy

A workflow turns fixing into policy. A new fixable finding appears, the agent fixes it, the PR lands ready to review.

Between runs

Every run learns. Every run is on the record.

Memories

Short facts the agent keeps between runs, written by you and by the agent. The pattern a module uses for handling input, the suite that has to pass. It stops rediscovering your repos.

Agent Executions

Code fixes recorded alongside dependency fixes: the finding, the files changed, every CI iteration, and where the pull request stands.

Heeler vs. an LLM agent

Why not just use an LLM to fix it?

Pointing an LLM agent at a finding, or building your own harness around one, asks a model to find the fix, so the answer changes every run and every step costs tokens. Heeler gives you the best of both: it decides the fix deterministically from your context, then uses the latest models, the best one for each task, to validate it, repair CI and address review feedback.

Frontier modelsthe same for bothMODEL CAPABILITY →FIXES YOU CAN MERGE →Heelercalculates the fix, then proves itAn LLM alonethe model attempts to reason its way to a fixCoderepos, dependencies, APIsRuntimewhat is deployedCloudexposure, datastoresBusinesstiers 1 to 4Ownershipteams, CODEOWNERSThreat intelKEV, EPSS, malwareSource-to-sink traceacross files, at scan timeService modelwhat runs, who owns itAutotriagereal exposureFix calculationthe exact change, no modelModel choicebest model per taskMemoriesyour conventions, rememberedSandboxyour real toolchainCode fitchecked against your codeCI repair loopuntil every check is greenEvery step recordeda full audit trailYour contextfrom theContext EngineCalculatedby Heelerdecides the fix,no model guessingThe Heelerfix agenton the best models:validate, repair CIFrontier modelsthe same for bothMODEL CAPABILITY →FIXES YOU CAN MERGE →Heelercalculates the fix, then proves itAn LLM alonethe model attempts to reason its way to a fix
The Heeler fix agent, on the best models
Every step recordeda full audit trail
CI repair loopuntil every check is green
Code fitchecked against your code
Sandboxyour real toolchain
Memoriesyour conventions, remembered
Model choicebest model per task
Calculated by Heeler
Fix calculationthe exact change, no model
Autotriagereal exposure
Service modelwhat runs, who owns it
Source-to-sink traceacross files, at scan time
Your context, from the Context Engine
Threat intelKEV, EPSS, malware
Ownershipteams, CODEOWNERS
Businesstiers 1 to 4
Cloudexposure, datastores
Runtimewhat is deployed
Coderepos, dependencies, APIs
Cost per step
data_arrayTokensscheduleDeveloper time
LLM agent alone

Asks a model to find the fix

Based on its training dataA different fix each runNot auditableMay not be the right fixRelies on one-off developer effort
Heeler Auto-fix

Calculates the fix, then proves it

Based on your environmentSame finding, same fixEvery step recordedAutomated end to endNo developer time until review
Trace the data flow

data_arrayTokensReasons about it from what fits in its context window

checkNo costTraced at scan time, source to sink, across files

Pick the fix

data_arrayTokensPicks a fix, differently each run

checkNo costStrategy matched to the weakness, decided at scan time

Write the change

data_arrayTokensRewrites the code

checkNo costThe exact before-and-after change, checked against the traced values

Learn your build

data_arrayTokensRelearns it every session

checkNo costRemembered from past runs

Start and steer it

scheduleDev timeA developer prompts, checks and reruns it

checkNo costRuns automatically, the same way for every team

Build and CI

scheduleDev timeFailures land on the developer

checkNo costSandbox build, CI repaired until green

Merge

scheduleDev timeA developer reviews and merges

scheduleDev timeA developer reviews and merges

Per fix
$7.16model API, the token cost
+ dev timeon top, not in the $7.16
$0of your tokens
+ reviewdev time at merge
Bars are illustrative.
Estimate it for your team

Model API cost is $7.16 per fix, the blended SCA and SAST average, on the lower-priced of two frontier models at public pricing as of July 31, 2026, with 20% cached input and 35% agent overhead, and excludes infrastructure and labor.

Also in Fix · SCA Auto-fix

Heeler also fixes vulnerable open source dependencies.

Heeler calculates the safest upgrade across your full dependency graph, proves it builds and opens a merge-ready pull request.

See SCA Auto-fix →
PURPOSE-BUILT FOR THE AI SDLC

See Heeler fix your code.