What it is
Fluid Attacks’ workflow combines a proprietary candidate-ranking model, specialized code-navigation agents, and human security analysts. The analysts validate reachability and exploitability, remove false positives and duplicates, and coordinate public disclosure.
What is verified
Fluid’s affected-project advisories explicitly credit its AI SAST Scanner. This makes the attribution direct under Bugflation’s primary-research-source rule while preserving the material human triage in the workflow.
The first indexed wave contains three August CVEs. Thirty older exact CVEs are documented as a separate reconciliation queue rather than silently absorbed into the headline count.