ESAA-Security: An Event-Sourced, Verifiable Architecture for Agent-Assisted Security Audits of AI-Generated Code
Elzo Brito dos Santos Filho

TL;DR
ESAA-Security introduces an event-sourced, verifiable architecture for agent-assisted security audits of AI-generated code, ensuring reproducibility, traceability, and structured reporting in software security assessments.
Contribution
It presents a novel, governance-based framework that separates heuristic agent cognition from deterministic state mutation, enabling structured, reproducible security audits for AI-generated software.
Findings
Structured audit process with 26 tasks and 95 checks
Produces comprehensive, traceable security reports
Ensures reproducibility and verifiability through event sourcing
Abstract
AI-assisted software generation has increased development speed, but it has also amplified a persistent engineering problem: systems that are functionally correct may still be structurally insecure. In practice, prompt-based security review with large language models often suffers from uneven coverage, weak reproducibility, unsupported findings, and the absence of an immutable audit trail. The ESAA architecture addresses a related governance problem in agentic software engineering by separating heuristic agent cognition from deterministic state mutation through append-only events, constrained outputs, and replay-based verification. This paper presents ESAA-Security, a domain-specific specialization of ESAA for agent-assisted security auditing of software repositories, with particular emphasis on AI-generated or AI-modified code. ESAA-Security structures auditing as a governed execution…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsAdvanced Software Engineering Methodologies · Multi-Agent Systems and Negotiation · Access Control and Trust
