CEO & Co-Founder at DryRun Security, Instructor at LinkedIn Learning, and Univ. of Oklahoma Alum. For speaking requests: wickett.me

Austin, TX
James Wickett retweeted
Trying to clarify different AI software factory loops: (blogpost pending) - production loops: these act on the code - maintenance loops: keeps the line running within the factory rules - feedback loops: changes the rules what the factory decides Thoughts are welcome!
3
1
17
1,340
Just the mention of winamp brought lots of feelse were talking about a WinAMP feature... Just the mention of winamp brought lots of feels all around.
1
1
292
Love this! We should collab to get @dryrunsec involved.
We ran Kimi K3 on a private cybersecurity benchmark. TL;DR: Kimi K3 is the workhorse for cyber security tasks at great recall/precision/price. GPT 5.6 is best recall/precision but at 7x higher cost per run. For context, Deepsec.sh is an open-source cyber harness designed for finding vulnerabilities in large codebases. The eval runs deepsec on an undisclosed open-core application at a git sha before a large number of security issues were fixed. This is a secret eval that cannot be directly benchmark-maxxed. S-Tier: GPT 5.6 Sol: By far the most thorough analysis, but coming in at over 7x the price of the runner up. Best price/recall: Kimi K3. Next tier of recall at a good price Best price at good recall: GLM 5.2 (40% lower price than Kimi K3) GPT 5.5: Only recommended with subscription or high-discount API price. Similar recall to Kimi at much higher list price. Opus 4.8: Only recommended with subscription or high-discount API price. Similar recall to GLM 5.2 at much higher list price. Fable 5: 100% refusal rate. Cannot be used for security analysis. Sol on a large code base will quickly get into 6-figure pricing. This is still affordable relative to the risk of letting security issues unfixed or paying bug bounties. I'd recommend using Sol for a one-time baseline and then using Kimi K3 for continuous analysis. When using open-weight models, make sure to use an inference vendor that supports zero data retention.
717
I’m at #unprompted con and if there was a drinking game for this event, I’d suggest: “context”, “reasoning”, “skills” as bingo squares
1
214
James Wickett retweeted
PR FEEDBACK IS LIVE IN DRYRUN SECURITY 🔥🔥🔥 When a security finding shows up in a pull request, it shouldn’t turn into a side quest. PR Feedback closes that loop. Now when DryRun Security flags something, developers can reply directly in the thread to mark a false positive or nitpick. DryRun updates the findings instantly, regenerates the PR summary, and logs the action for a clean audit trail. No tickets to file. No separate workflow to manage. No chasing someone down to clear it. Read how it works → dryrun.security/blog/securit…
2
3
410
Opener of #unpromptedcon happening now. Hanging with @LiorKolnik and @abraham_jabez Who else is around? I’ve seen @treyford and @rmogull #unprompted
1
3
255
James Wickett retweeted
AppSec leaders: quick gut check. Can you answer these questions about your program with confidence? In this short video, @cktricky, DryRun Security CTO & Co-founder, shares the pointed questions he keeps hearing teams struggle with as development and risk accelerates: ❓Can you train developers based on the actual risks they introduce instead of one-size-fits-all training? ❓Do you know what’s being shipped without being told beyond the release/review process? ❓Are your developers ready to build secure AI applications? ❓Do you know which teams are using AI coding assistants, and do you have the right guardrails? ❓Can you respond to zero-days in minutes, with clear visibility into exposure and next steps? If any of these made you pause, you’re not alone. A lot of teams are still forced into the “old way” of doing AppSec while engineering velocity keeps climbing. We built DryRun Security to help practitioners close these gaps with a modern approach to code risk and visibility. If you want confidence in answering these questions, schedule a demo with us at dryrun.security/get-a-demo
1
2
124
James Wickett retweeted
📢 We’re thrilled to welcome Andrew Peterson to our Board of Directors, effective immediately! Andrew is a rare blend of security builder, technologist, and investor with a track record of helping create category-defining companies. He: ➡️ Co-founded Signal Sciences, helping pioneer modern web app & API security (acquired by Fastly in 2020) ➡️ Founded Aviso Ventures, an early-stage fund focused on enterprise & infrastructure software ➡️ Has backed standout AI security teams including Protect AI (acquired by Palo Alto Networks in 2024) and SGNL.ai (acquired by CrowdStrike earlier this year) As Andrew put it: “As AI agents take on more responsibility in writing and reviewing code, security must evolve into something more intelligent, contextual, and adaptive.” That’s exactly the mission at DryRun Security: AI-native code security intelligence built for the agentic era—reducing noise, surfacing real risk, and bringing policy-driven visibility to agentic code changes. Since emerging from stealth, DryRun Security customers are now running 250,000+ code reviews per month through DryRun Security, proof that the way software is built is changing fast, and security has to keep up. Welcome, Andrew! We’re excited to build what’s next! 💥 🔗 Read more at globenewswire.com/news-relea…
2
3
378
James Wickett retweeted
AI did not create entirely new AppSec problems. It changed where they show up. Prompts. Generated code. Tool calls. Model integrations. The risks are familiar. The workflows are not. Join our live fireside chat, Code Velocity in an AI-era: How AppSec Teams Can Stay Ahead, with Adam Dyche with @poweredbyCMRC, @wickett , @cktricky, and Zac Fowler with DryRun Security. They'll unpack how real teams are securing LLM-powered applications without rebuilding their entire AppSec stack. 🗓️ Feb 4 | 1PM ET Register 👉 na2.hubs.ly/H037Qhw0
2
3
237
James Wickett retweeted
LLM apps are moving fast, and the risks are moving faster. That’s why we’ve developed a guide for securing AI Applications. In “Building Secure AI Applications,” we break down how the OWASP LLM Top 10 shows up in real systems and map each risk to controls teams can actually implement today. If you’re building or securing LLM features, we include a full vendor-neutral reference architecture. Download the Guide → dryrun.security/resources/ow…
4
6
396
James Wickett retweeted
Mark Burgess once pointed out that determinism in large systems is mostly an illusion. He was right. We pretend our tools can capture risk with fixed rules, but modern software isn’t static enough for that. In our most recent post, @wickett discusses how AI is pushing us into an era where code evolves faster than rule sets ever could. Probabilistic security isn’t a trend; it’s becoming the only model that fits reality. Read the whole post at dryrun-staging.webflow.io/bl…
1
2
80
I’m turning around if I’d booked a meeting there
The meeting room setup at Reinvent is so dystopian. Feels like I’m in the B2B SaaS version of Severance.
1
125
Post Halloween vibes
126
James Wickett retweeted
Huge thanks to the @LASCONATX volunteer team (incredible hosts) and to everyone who stopped by our booth for great #appsecurity conversations. If you missed it live, catch @wickett's talk "Out of Control: Promise Theory and the Future of Code Security Agents" slides here: promise-theory-34zpp7h.gamma…
1
3
126
You have my support!
The @owasp Board of Directors election starts tomorrow! Many people do not know me by name, but they know my work on DependencyCheck. I've been volunteering with OWASP for over a decade. If you are an OWASP member, I would be honored to have your vote.
1
211
James Wickett retweeted
Thrilled to team up with @secdim to connect DryRun Security contextual risk insights with hands-on secure coding labs. This helps engineering teams turn findings into learning and fixes faster. Thanks, Pedram, for this innovative use case for the DryRun MCP!
This is how you use SAST findings to upskill developers in security, right in your Claude IDE. Brought to you by @dryrunsec + @secdim #sast #training #securecoding
1
3
207
I’m ready for copilot for MS-Paint
When did notepad become copilot enabled ='(
1
1
318