Qoder Security: Three Layers of Code Protection Inside the Session — a First in China with Same-Session Fixes

·Toolin Editorial Team

Alibaba's Qoder ships China's first three-layer in-session code security guard — vulnerability detection up 60%, false positives down 80%, enabled in 3 steps.

Qoder Security: Three Layers of Code Protection Inside the Session — a First in China with Same-Session Fixes

AI coding tools have sharply lowered the bar for "getting software to run" without lowering the bar for "getting software to run securely." Per data from the security firm Veracode: over the past two years, models' syntactic correctness climbed from about 50% to over 95%, but the security pass rate has stayed stuck between 45%~55%. A GitLab survey of 3,266 DevSecOps practitioners found 73% had run into code problems from Vibe Coding, and 76% said more compliance issues only surface after deployment. Alibaba's Qoder built Qoder Security against exactly this pain point — making code security native to the coding session, through every step from writing to commit — which makes Qoder China's first Agentic Coding product to deliver "three layers of in-session security protection + same-session remediation."

What It Is: Three Layers of Defense, All Inside the Coding Session

Qoder Security embeds security checks into the same coding session, built around "detect the problem → fix it in the same session → re-verify to close the loop" — no jumping out of the editor, no waiting for CI, no separate ticket. To balance not disturbing developer flow against controlling compute costs, it deploys three layers of defense:

L1 Static Checks: Real-Time Regex Interception

  • Trigger: fires automatically the instant code is generated.
  • How it works: screens for known high-risk patterns.
  • Speed: millisecond-level, zero latency, zero extra compute — developers never feel it.
  • Price: completely free.

L2 Lightweight Scan: Semantic-Level Incremental Review

  • Trigger: a "Scan for code security risks" card pops up during coding; click it for results. You can also trigger it proactively in the session with /security-scan.
  • How it works: focuses on the code increment (Diff) produced by the current task, comparing semantic differences between new and old code to keep new code from breaking existing security boundaries.
  • Coverage: risks that require understanding semantics to spot, such as cross-function data-flow taint, SQL injection, remote command execution, and sensitive-information leakage.

L3 Deep Scan: Cross-File Deep Review

  • Trigger: fires before commit.
  • How it works: builds a global dependency graph and traces complete data flows across files and functions — from taint sources to dangerous sinks — digging out hidden correlated vulnerabilities that a single-file view cannot see.

Enable Qoder Security in Three Steps

Coverage: Qoder Desktop and Qoder CLI on both the International edition and Qoder CN — one toggle in settings, with no additional plugins to install or configure.

Desktop (Qoder Desktop)

  1. Open Qoder, click User Settings in the top-left, and choose Qoder Settings.
  2. Select "Security" from the sidebar.
  3. Under scan levels, confirm that the toggles for Static Checks (L1), Lightweight Scan (L2), and Deep Scan (L3) are all on.

Command Line (Qoder CLI, v1.1.0 and up)

# View and toggle the three defense layers
/security-settings

# Actively trigger a security scan during the session
/security-scan

# Or use natural language
Run a code security scan for me

Both the International edition and the China (CN) edition support this.

💡 Tip: L2's /security-scan is the most commonly used command in daily development. Scan once after finishing each feature module — it beats batching everything into a single L3 scan before commit, and fixes cost less too.

Measured Results and Data

Headline numbers versus traditional security approaches:

  • Vulnerability detection rate up about 60%
  • False-positive rate down about 80%
  • Time from discovery to fix for a single vulnerability compressed to hours (traditional processes run on days or weeks)
  • After Alibaba's internal R&D adopted it, security-related review comments in code review dropped about 35%~45%

Dual-Agent Architecture: No "Grading Your Own Homework Full Marks"

  • Built on a proprietary security LLM that understands code context and taint propagation paths, it self-verifies the reachability of every finding and reports only genuinely reachable risks.
  • The coding agent and the security review agent are independent of each other — avoiding "fix it yourself, then grade yourself full marks."
  • Inside the security review agent, scanning and verification are split between two cooperating agents, improving accuracy.

Verified Against Two Real CVE Scenarios

  • CVE-2022-31115 (insecure deserialization): while adding YAML compatibility to a historical OpenSearch version, the agent reused an existing pattern that called Ruby's extremely dangerous YAML.load. The moment the security scan card was clicked, it raised an alert and fixed it in-session to YAML.safe_load — no context switching at any point.
  • CVE-2026-42550 (SQL identifier injection): while adding a DB wrapper to a historical flightphp/core commit, PDO prepared statements can bind values but not table/column names, and the agent bluntly concatenated the key names. The security scan flagged the dynamic SQL identifier concatenation as high-risk and proposed a fix (strict character whitelist filtering plus backtick escaping for table/column names).

How It Differs from Peer Products

ProductSecurity approach
OpenAI Codex SecurityRepository-level scanning
Anthropic Claude CodeSecurity review integrated into the coding session
Qoder SecuritySecurity protection built inside the agentic coding session + three layers + same-session remediation

The Qoder team is candid: by "first in China" they mean being the first to make the "three-layer in-session protection + same-session remediation" paradigm a usable capability inside a mainstream domestic Agentic Coding product, complementing rather than replacing existing security systems. They also admit security checks cannot be 100% accurate and occasionally produce false positives — the final call always rests with the developer.

Use Cases

  • Everyday Agentic Coding: let AI write code with security automatically backstopping it, no separate SAST tool runs needed.
  • Legacy project rework: when layering new features onto legacy spaghetti code, L3 cross-file scanning finds correlated vulnerabilities a single file cannot reveal.
  • Teams with heavy compliance demands: finance, healthcare, ToB projects — finding problems before deployment versus after deployment differs by an order of magnitude in cost.
  • Lighter code reviews: internal Alibaba measurements show security-related review comments down 35%~45%, letting reviewers focus on business logic.

FAQ

  • Should all three layers be on?: yes, turn them all on. L1 costs nothing and adds no latency, L2 is a quick scan after each module, L3 is the pre-commit backstop.
  • Are there many false positives?: the vendor says the false-positive rate is down about 80% versus traditional approaches, and the security LLM self-verifies the reachability of findings — but occasional false positives remain, and the developer makes the final judgment.
  • Does it slow down coding?: L1 is millisecond-level and imperceptible; L2 scans only the Diff, an incremental review; L3 triggers only before commit and never disturbs the daily coding flow.
  • Are the International and CN editions identical?: yes — both Desktop and the CLI (v1.1.0+) get the full three-layer protection.