Hackathon, Nov 2025
Dependency Watcher
An LLM that queries live CVE data, so vulnerability checks happen in context.
Recognised
At the JellyFaaS AI Hackathon, November 2025
Problem
Dependency vulnerability checks usually run out of band, in a separate scanner that a developer has to read. An LLM that can query live advisory data can answer the question in context.
Approach
- A serverless Python microservice runs on JellyFaaS.
- The LLM calls function tools that query the OSV API for live CVE data.
- Function-calling workflows let the agent chain lookups to detect vulnerabilities without a human steering each step.
Architecture
- Serverless Python microservice on JellyFaaS.
- Agentic workflow using function calling against the OSV API.
Limitations
- Built in a hackathon timeframe. It has not been benchmarked for detection accuracy against an established scanner.
- Its vulnerability data comes from the OSV API.
Stack
- Python
- Tool use and function calling