Work / Case studyWinner · Microsoft prize · ShellHacks 2026

Repro

Proof, not promises.

Repro reproduces every scanner warning in a sandbox and fixes only what it proves; a person merges.

Event
ShellHacks 2026
Result
Winner · Microsoft prize
Built in
36 hours
Team
Alexander Gese, Adrian Morton, Brandon Delgado
(01) The problem

A warning is a claim.

Scanners report warnings. Repro treats each one as unproven until it can be reproduced, and it only fixes what it has proven.

No model decides what counts as a finding, nothing is repaired without a reproduction, and no fix is merged by Repro itself. A person decides whether to merge.

(02) How it worksSix stages

Reproduce first. Verify after.

  1. Prove the problem

    Ingest

    Pinned commit

    Clones the target into a fresh workspace, pinned to one commit.

  2. Prove the problem

    Detect

    Deterministic

    Deterministic scanners; no model decides what counts as a finding.

  3. Prove the problem

    Reproduce

    Proof gate

    Re-runs each finding's reproduction command in a sandbox, keeps only what shows the problem.

  4. Prove the fix

    Diagnose

    By root cause

    Groups findings by root cause, proposes a fix per group.

  5. Prove the fix

    Repair

    Diff from git

    Edits files through sandboxed tools; the diff comes from git.

  6. Prove the fix

    Verify

    A person merges

    Tests + reproduction re-run, an adversarial check tries to break the fix; a person decides whether to merge.

(03) Results

Results

Finding bugs
0%of model tokens spent finding bugs. Scanners find; no model decides what counts as a finding.
Fixing them
~68%fewer tokens to fix them than repairing every finding separately, by fixing one root cause per group.
Build time
36hBuilt in 36 hours at ShellHacks 2026.

*The ~68% figure is an estimate: it compares grouping findings by root cause with repairing every finding separately. It is not a measured benchmark.

(04) The win

Microsoft prize.

Repro won the Microsoft prize at ShellHacks 2026. The project page is on Devpost.