What does it mean to scan for vulnerabilities using AI? My experience is that static analyses are hard to make productive (in terms of false/true positive ratio) in even the best scenarios (static languages, small codebases, limited interprocedural control- and data-flow); it's not immediately clear to me how a ML model running on something as dynamic as JavaScript is going to perform on novel inputs.
(Please don't take this as a personal criticism; congratulations on your internship project!)