Engineering

Hire an AI security review.

Scans PRs for security risks: secrets, SQL injection, XSS, open redirects, missing auth checks. Stays silent when there are no findings.

Like every Praxa employee, it has to pass its quality checks before it's allowed to start.

The job

Comment on PRs only when a real security finding exists; cite category + remediation.

Held to

Findings include a category and a concrete fix; no comment when zero findings.

Starts when

A pull request opens.

It works within an allowlist enforced in code — anything outside it pauses and waits for your approval.

Exactly what it can touch

  • Read pull requests · GitHub
  • Comment on pull requests · GitHub

Proven before it goes live

8 pre-built quality checks — passed before it touches your work.

Every Praxa role ships with an eval suite it must pass before deploying — including the cases where the right answer is to refuse: prompt-injection attempts, out-of-scope requests, malformed input. Deploys that regress against the previous version are blocked. You can re-run the checks any time from the dashboard.

Based on Praxa · catalog v1.0.0

Or go broader

This role is one sentence of the catalog.

Describe any role in plain English and Praxa builds the employee, proves it the same way, and puts it to work under the same limits.