Skip to content

Hackathon, Nov 2025

Dependency Watcher

An LLM that queries live CVE data, so vulnerability checks happen in context.

Recognised

At the JellyFaaS AI Hackathon, November 2025

Problem

Dependency vulnerability checks usually run out of band, in a separate scanner that a developer has to read. An LLM that can query live advisory data can answer the question in context.

Approach

  • A serverless Python microservice runs on JellyFaaS.
  • The LLM calls function tools that query the OSV API for live CVE data.
  • Function-calling workflows let the agent chain lookups to detect vulnerabilities without a human steering each step.

Architecture

  • Serverless Python microservice on JellyFaaS.
  • Agentic workflow using function calling against the OSV API.

Limitations

  • Built in a hackathon timeframe. It has not been benchmarked for detection accuracy against an established scanner.
  • Its vulnerability data comes from the OSV API.

Stack

  • Python
  • Tool use and function calling