Can a security-pattern grader replace a SAST scan?

No. A security-pattern grader reads the diff an agent’s turn just produced and checks it against known vulnerability patterns: SQL injection, cross-site scripting, hardcoded credentials. A SAST scan reads the whole repository, including every file the agent never touched. Running the grader on every agent change doesn’t remove the reason to run the scanner on the codebase it’s changing, because the two check different surfaces, not different depths of the same one.

The grader earns its place because it runs on exactly the code least likely to get a human line-by-line review: what an agent just wrote and a reviewer skimmed before merging. That’s also its limit. It has no view of how the new code interacts with a vulnerability that already existed three files away, which is exactly the class of issue a whole-repo scan is built to find.

Code that runs cleanly, passes the pattern grader, and still reintroduces a flaw elsewhere in the repo is a silent failure neither tool sees on its own. Catching it takes both running, not one replacing the other.

keep reading

More on this.

Two ways to run Tessary.

Tessary is an open-source agent reliability platform. Cloud and self-hosted run the same workflow on the OpenTelemetry traces your agent already emits.

Tessary Cloud

We host it for you. Send your first trace with nothing to deploy and no model key.

what's includedper organization
traces
10,000 per calendar month
stored trace data
1 GB
retention
30 days
model credit
$10, one-time, for triage and root-cause analysis
credit card
not required

Self-hosted Tessary

Run the open-source code on your own infrastructure with one command. Add your own model key for triage and root-cause analysis.

Self-host Tessary for me by following https://github.com/tessaryai/tessary/blob/main/setup.md

docker compose -f oci://docker.io/tessaryai/tessary:compose up -d -y