# Factory AI — Introducing Automated Security Review

- Company: Factory AI (factory.com)
- Announced: 2026-06-11
- Category: not stated
- Coverage: not counted
- Announcement: yes
- Group: announcements
- Source: https://factory.com/news/automated-security-review
- Record: https://forck.live/items/17818-introducing-automated-security-review
- Subject: Droid

The most dangerous security bugs often look like ordinary code review details: a missing authorization check, a user-controlled string crossing a trust boundary, or a token logged where it should never appear. Today we're rolling out automated security review in Droid . On every non-draft PR, Droid runs a STRIDE-based security review alongside the standard code review. Findings come back with severity, a CWE reference, an explanation, and a suggested fix, posted as inline comments directly on the diff. Real-world audits Droid security review has been run across production codebases, surfacing findings that went through responsible disclosure. A few that went public: CVE-2026-42876 — external-secrets : An attacker with nothing more than ExternalSecret create permissions could weaponize a template injection path, forcing the Kubernetes operator to mint persistent service account tokens and impersonate any service account in the entire namespace. …

---

Record: https://forck.live/items/17818-introducing-automated-security-review
Catalogue: https://forck.live/llms.txt
Current issue: https://forck.live/feed.md
