Supply chain attacks are everywhere with over 20,000 CVEs filed in Q2 2025. We wrote a non-agentic, internal tool which combines deterministic callgraph-based methods with selective LLM reasoning to βvibe codeβ Semgrep rules, colossally decreasing the time security researchers spend processing CVEs.