Can a security-pattern grader replace a SAST scan?
No. A security-pattern grader reads the diff an agent’s turn just produced and checks it against known vulnerability patterns: SQL injection, cross-site scripting, hardcoded credentials. A SAST scan reads the whole repository, including every file the agent never touched. Running the grader on every agent change doesn’t remove the reason to run the scanner on the codebase it’s changing, because the two check different surfaces, not different depths of the same one.
The grader earns its place because it runs on exactly the code least likely to get a human line-by-line review: what an agent just wrote and a reviewer skimmed before merging. That’s also its limit. It has no view of how the new code interacts with a vulnerability that already existed three files away, which is exactly the class of issue a whole-repo scan is built to find.
Code that runs cleanly, passes the pattern grader, and still reintroduces a flaw elsewhere in the repo is a silent failure neither tool sees on its own. Catching it takes both running, not one replacing the other.