Skip to content

OpenHack Assistant

Your AI security engineer, with the full picture. Ask anything about your company's security posture and get clear answers grounded in your projects, scans, and findings.

You: What did we find in Papermark?
OpenHack Assistant:
Reading scan findings

Authentication bypass in the upload handler

The finding affected authentication before uploads reached S3-compatible storage.

CVE-2026-36755 · Patched by Papermark.

You: What was the fix?
OpenHack Assistant:

Correct the session handling so authentication completes before the upload is accepted.

The patch was merged on March 2, 2026.

Read the published finding

How it works

OpenHack Assistant brings your security data into one conversation. It looks across connected projects, code scans, vulnerabilities, and supply chain findings to understand your organization's security posture. Ask a broad question, then follow up on the projects, packages, or findings that need your attention.

Get answers grounded in your organization's data, with the project names, scan references, and affected components behind each recommendation. Use the Assistant in OpenHack or ask it from Slack and Linear. Your team gets the context to make decisions and stays in control of the changes.

One conversation across your security stack

See your whole security posture

Ask how your company is doing without opening every project. OpenHack Assistant brings together code findings and dependency risks from across your organization, connects them to the repositories they affect, and gives you a clear picture of where to focus. Go from an organization-wide overview to a single finding in the same conversation.

Ask a question. Follow the evidence.

Which vulnerabilities are critical? Where is this package used? What did the latest scan find? Ask in plain language and keep digging. Answers reference the project, scan, finding, or package behind them, so your team can check the source and understand the reasoning.

Know what to fix first, and why

Turn a list of findings into an informed next step. The Assistant considers severity, known exploitation and EPSS signals for dependencies, and the projects affected. Ask it to compare risks, explain a recommendation, or find the available fixed version before your team starts remediation.

Your security engineer, right in Slack

Mention @OpenHack in a connected channel to ask about your security posture and get an answer in a thread. Use /openhack ask for a private response. It is the same Assistant, with the same organization context, so the conversation can happen where your team already works.

Bring the conversation into Linear

Ask OpenHack about a security issue from the Linear discussion around it. Understand why a finding matters, which projects are affected, and what to review next, with the context alongside the work.

What you get

  • A clear view across your organization's projects and security findings
  • Answers grounded in project, scan, finding, and package references
  • Remediation priorities with the reasoning behind them
  • The same security context in OpenHack, Slack, and Linear

Put your AI security engineer to work.

Ask your first question about your company's security posture. Give your team an AI security engineer that can connect the findings, explain the risks, and help decide what comes next.