Backlog Hunter
Roster name: hunter.
What it does
It rereads the review conversations on recently closed pull requests and reports the security concerns nobody resolved and the follow-ups nobody picked up.
- Finds vulnerability mentions with no later fix, and promised follow-ups with no issue or pull request that tracks them.
- Flags lingering work: old open issues and pull requests, work carried across several milestones, and stale
review:findings-openlabels. It also flags pull requests merged while findings were still open. - Closes an issue only when it can prove the work is done.
What it reads
- Every comment, review and reviewer finding on the pull requests closed since its last run, in every repository Runink TIDE can reach.
- The open issues and pull requests, and facts from your Git host such as links, dates and merged commits.
What it produces
- One run report per run, shown in the console.
- Once armed, a living “Backlog hunter report” issue with a section per repository. A dry run reports to the console only.
- An evidence comment before any issue it closes.
Human oversight
A person decides what to act on. The hunter stays dry until an administrator arms it. Once armed it closes an issue only when a merged pull request closes it, or when an owner, member or collaborator of the repository marked it a duplicate of an issue closed as completed. It may also remove a stale review:findings-open label once a later clean review supersedes it. Everything it cannot prove is reported as needing a person.
Model
Qwen3.6-35B-A3B, by Qwen, licensed Apache-2.0 (the general tier). Runink domain adaptation for this agent is planned; this release uses the base model.
Where it runs and data handling
On your TIDE deployment’s own inference, on your Server or in your cloud. Review comments go to that model plane and to no third-party AI service.
Guardrails
- The model only sorts comment text into vulnerability mention, follow-up promise or neither. Every other decision is a fact read from the Git host.
- It never closes a security issue without a merged fix.
- It never merges or closes a pull request; on a pull request it only removes a stale
review:findings-openlabel. - A “Duplicate of” note counts only from someone who could close the issue themselves.
- Comments are marked as untrusted data, with chat control sequences neutralised, and screened before the model reads them.
- A small cap on writes per run.
- Comments it could not classify are reported as unclassified, never hidden.
Limitations
- It looks only at pull requests closed since its last run.
- It cannot see conversations held outside the Git host.
- It reports; it does not fix.
Evaluation
No published evaluation scores yet.
Illustrative example
Invented comment. On a closed pull request a reviewer wrote: “this export endpoint skips the permission check for service accounts, we should revisit.” No later merged change touches it. The report lists it as an unresolved vulnerability mention with a link to the comment.