Agents that build, then shrink, unfamiliar codebases
Debloating only works on code that builds, and every cut risks breaking it. These agents pull source from git, work out the build requirements, containerize the project in Docker, and drive the build loop themselves. Once it builds, they call debloating tools with increasing aggressiveness, roll back to the last working configuration the moment something breaks, and write up what was removed and why.
Related: An Execution Soundness and Security Benchmark for Java Debloating Tools, accepted poster at ACSAC 2026.
- 01Clone the repo
- 02Infer the build
- 03Containerize
- 04Build, fix, repeat
- 05Debloat harder
- 06Roll back on break
- 07Report