All Categories

Qianxin officially launches its first code security agent - Qcode Agents

2026-09-17

Evidence generation: not only can risks be discovered, but also reproducible vulnerability triggering paths can be generated.
Practical verification has shown that Qcode Agents' performance in detecting business logic vulnerabilities has increased exponentially, truly filling the gap in this critical area of the industry.
Reshaping the Security Boundary of AI Application Supply Chain: From Model to MCP Full Factor Protection
Currently, the supply chain of AI applications has far exceeded the scope of traditional open source components - new elements such as model files, MCP (Model Context Protocol), Skill, etc. have become the focus of attack surface extension. Traditional SCA tools often suffer from serious false positives and false negatives when faced with these new objects due to a lack of detection, validation, or domain knowledge, resulting in the ultimate risk misjudgment.
Qcode Agents has built a detection capability that covers all elements of the AI supply chain, incorporating model dependencies, MCP tools, and Skill call links into the analysis perspective. Combining the profound domain knowledge base and accurate correlation modeling accumulated by Qianxin in the software supply chain field over the past 10 years, Qcode Agents can automatically generate software material lists for AI applications, clearly trace the use of open source models, accurately identify various "invisible dependencies" in AI applications, and make various supply chain security risks in AI applications nowhere to hide.
Strength verification: Reproduce known cases and discover potential vulnerabilities in mainstream projects
The detection capability of Qcode Agents has been perfectly validated in multiple tests, achieving unexpected performance:
Reproducing the industry benchmark: fully reproduce the three typical security vulnerabilities disclosed when Claude Code Security was released, accurately restore the vulnerability trigger conditions, utilization paths and potential hazard scenarios, and prove the progressiveness of its detection logic.
Deep testing of open source projects: Selecting well-known open source projects widely used such as apache-obiz, apache-log4j, libpng, gpac, etc., targeted deep testing was carried out, which not only successfully reproduced the corresponding CVE vulnerabilities, but also comprehensively investigated business logic defects and high-risk vulnerabilities such as stack overflow. For example, when detecting Apache OFBiz, Qcode Agents discovered a bypass vulnerability caused by an incomplete login verification mechanism, which is a semantic loophole that cannot be identified by traditional static analysis. And Qcode Agents, with their internalized practical experience, accurately understood the verification semantics of login scenarios and successfully captured this hidden flaw.
Major findings during the internal testing phase: Qcode Agents have identified over 10 potential security vulnerabilities in mainstream open source systems and frameworks such as OpenSSL, TensorFlow, OpenCV, Memcached, and RuoYi, and have completed preliminary validation and risk level assessment.
Ten years to sharpen a sword: actual combat is the only criterion for testing effectiveness
The outstanding performance of Qcode Agents is not a castle in the air, but built on the solid foundation of more than ten years of code security cultivation by Qianxin.
Deep accumulation: Qianxin is one of the earliest manufacturers in China to implement enterprise level SAST (Static Application Security Testing) productization. The flagship product "Code Defender" supports dozens of languages, covers thousands of vulnerability types, serves over 1000 large government and enterprise clients, and has accumulated tens of thousands of high-quality rules that have been verified through practical experience.
Benchmark verification: The "AI+Code Defender" released in early 2025 has been implemented among top financial clients such as Bank of Beijing and PICC Technology. Data shows that it has shortened the code audit cycle by over 83%, reduced labor costs to 1/6 of traditional models, and achieved a high-risk vulnerability interception rate of over 95%.
Closing Remarks
From "Code Defender" to "AI+Code Defender", and now to the "Qcode Agents" intelligent agent, every time is a continuous improvement and iteration closely related to practical needs. The release of Qcode Agents by Qianxin is not a simple upgrade of the product, but rather an integration of technical accumulation, attack and defense experience, and customer practice. It not only allows AI to "understand code", but also enables it to "understand business", "empower experience", and "handle closed loops", building a secure, efficient, and reliable code security system for enterprises.

About Us
Phone: 0518-80236699
Email: [email protected]
Address: Haizhou District, Lianyungang City, Jiangsu Province
Ministry of Industry and Information Technology Government Service Platform
Su ICP preparation 2025211914
Su Gongwang Security No. 32070602010184
Technical Support: Jiangsu Xiaola Technology Co., Ltd
Facebook Facebook
Facebook
WhatsApp WhatsApp
WhatsApp
qianxin officially launches its first code security agent   qcode agents-0