AI-Enhanced Static Code Analyzer for Secure Coding Support
DOI:
https://doi.org/10.56532/mjsat.v6i3.729Keywords:
Static Code Analysis, Artificial Intelligence (AI), Secure Coding Education, Large Language Models, Explainable AI (XAI)Abstract
Many industrial security scanners including the popular Bandit tool discover security flaws; however, the information they give to the user is frequently technical and difficult to understand for those who are new to security. The goal of this project is to improve educational tools for secure programming that novice programmers can use by making static code checks easier to comprehend. A browser-based software tool called AegisCode was created using advanced mathematical techniques for counting and combinations. This tool makes use of Google's Gemini Large Language Model. While the current version utilizes a client-side simulation to provide immediate feedback, the proposed architecture details a Python Flask backend designed to run actual Bandit rule-based scanning to replace non-deterministic AI interpretations. The testing of the proof of concept showed it was performing well, and the whole analysis process was normally finished within five seconds. This process was also very accurate in producing well formatted JSON output which can be used by the user interface. This paper is innovative in its two-process theory, the conceptual underpinning for the translation of the technical diagnostics into the rich narrative stories for an education audience. Junior developers are provided with key security advice by the system so they can avoid security pitfalls. Learning how to programme using a tool such as this teaches developers good coding practices and appropriate methods of coding. It aids in promoting acceptable code practices. Future work will prioritize the transition to a deterministic backend and the integration of the Semgrep engine to expand language support beyond Python to include C++ and Java, ensuring compliance with OWASP and CWE standards.
References
I. Kabanov and S. E. Madnick, “A Systematic Study of the Control Failures in the Equifax Cybersecurity Incident,” SSRN Electronic Journal, 2020, doi: https://doi.org/10.2139/ssrn.3957272.
B. K. Kaithe, “Shift Left Security: A Paradigm Shift in Software Development Security Integration,” Eur. J. Comput. Sci. Inf. Technol., vol. 13, no. 24, pp. 96–102, Apr. 2025. doi: https://doi.org/10.37745/ejcsit.2013/vol13n2496102.
J. Smith, B. Johnson, E. Murphy-Hill, B. Chu, and H. R. Lipford, “Questions developers ask while diagnosing potential security vulnerabilities with static analysis,” in Proc. 10th Joint Meeting Eur. Softw. Eng. Conf. ACM SIGSOFT Symp. Foundat. Softw. Eng. (ESEC/FSE), 2015, pp. 248–259. doi: https://doi.org/10.1145/2786805.2786812.
F. Schuckert, B. Katt, and H. Langweg, “Difficult SQLi Code Patterns for Static Code Analysis Tools.” Available: www.cvedetails.com.
A. Nance, K. Hay, and B. Bishop, “Secure Coding Education: Are We Making Progress?” Available: https://escholarship.org/uc/item/6nc7r0c9.
“Malaysia - Cyber Security Strategy (2020-2024),” 2020. Available: https://regulations.ai/regulations/RAI-MY-NA-MCSS2XX-2020.
F. Yamaguchi, N. Golde, D. Arp, and K. Rieck, “Modeling and discovering vulnerabilities with code property graphs,” in Proc. IEEE Symp. Security and Privacy, 2014, pp. 590–604. doi: https://doi.org/10.1109/SP.2014.44.
A. Shrestha, A. Cater-Steel, M. Toleman, and T. Rout, “The role of international standards to corroborate artefact development and evaluation: Experiences from a design science research project in process assessment,” Commun. Comput. Inf. Sci., pp. 438–451, 2017. doi: https://doi.org/10.1007/978-3-319-67383-7_32.
V. Aware, A. Pimparkar, C. Unavane, A. Wagh, P. Pandit, and A. Yenkikar, “AI Agent for Scientific Paper Analysis,” in Proc. IEEE Int. Conf. Intelligent Signal Process. Effective Commun. Technol. (INSPECT), 2025, pp. 1–7. doi: https://doi.org/10.1109/INSPECT67393.2025.11350774.
“OWASP Top Ten Web Application Security Risks.” Available: https://owasp.org/www-project-top-ten/.
P. Kishore and M. B. M, “Evolution of client-side rendering over server-side rendering.” Recent Trends in Information Technology and its Application, vol. 3 Issue 2.
B. London and T. Joachims, “Control variate diagnostics for detecting problems in logged bandit feedback,” 2022.
W. E. Roberts, “The use of cues in multimedia instructions in technology as a way to reduce cognitive load,” Journal of educational multimedia and hypermedia, vol. 26, no. 4, pp. 373–412, Oct. 2017.
S. Kalyuga, P. Chandler, and J. Sweller, “When redundant on-screen text in multimedia technical instruction can interfere with learning,” Hum. Factors, vol. 46, no. 3, pp. 567–581, 2004.
H. Pearce, B. Ahmad, B. Tan, B. Dolan-Gavitt, and R. Karri, “Asleep at the keyboard? Assessing the security of GitHub Copilot’s code contributions,” Dec. 2021. Available: http://arxiv.org/abs/2108.09293.
J. Escribano-Barreno, J. García-Muñoz, and M. García-Valls, “Integrated metrics handling in open source software quality management platforms,” in Advances in Intelligent Systems and Computing, pp. 509–518, 2016. doi: https://doi.org/10.1007/978-3-319-32467-8_45.
C. Lohest and A. Legay, “Improving security analysis rule set by relationship identification,” in Proc. IEEE Int. Conf. Softw. Test. Verif. Valid. Workshops (ICSTW), pp. 297–300, 2024. doi: https://doi.org/10.1109/ICSTW60967.2024.00059.
L. M. Cruz, G. Castelblanco, and P. D. Antonenko, “LLM-based System for Technical Writing Real-time Review in Urban Construction and Technology,” EPiC series in built environment, May 2024, doi: https://doi.org/10.29007/d9j3.
S. Riazi and P. Rooshenas, “LLM-driven feedback for enhancing conceptual design learning in database systems courses,” in Proc. 56th ACM Tech. Symp. Comput. Sci. Educ. (SIGCSE TS), pp. 1001–1007, Feb. 2025. doi: https://doi.org/10.1145/3641554.3701940.
M. Miao, A. Mordahl, D. Soles, A. Beideck, and S. Wei, “An extensive empirical study of nondeterministic behavior in static analysis tools,” in Proc. Int. Conf. Softw. Eng. (ICSE), pp. 1064–1076, 2025. doi: https://doi.org/10.1109/ICSE55347.2025.00125.
S. Abdelnabi, K. Greshake, S. Mishra, C. Endres, T. Holz, and M. Fritz, “Not what you’ve signed up for: Compromising real-world LLM-integrated applications with indirect prompt injection,” in Proc. 16th ACM Workshop Artif. Intell. Secur. (AISec), pp. 79–90, Nov. 2023. doi: https://doi.org/10.1145/3605764.3623985.
L. Cohen, L. Manion, and K. Morrison, Research Methods in Education. Routledge, 2013.
Downloads
Published
Issue
Section
License
Copyright (c) 2026 Hor Jia Jie, Maisarah Mansor, Ranjit Singh Sarban Singh

This work is licensed under a Creative Commons Attribution-NonCommercial 4.0 International License.
