Capital One Unveils VulnHunter: An Agentic AI Tool for Proactive Code Security
VulnHunter: Capital One's agentic AI code security tool

We are releasing VulnHunter, an open-source, agentic AI security tool designed to shift from passive scanning to proactive, attacker-perspective analysis. By simulating real attack paths and rigorously falsifying its own findings, VulnHunter minimizes false positives and provides developers with evidence-backed code remediations. This developer-first approach aims to secure software supply chains before advanced AI threats can exploit vulnerabilities.
The world faces an increasingly short window of time before highly sophisticated, next-generation AI attack capabilities become affordable and accessible to virtually every adversary.
- _pdp_
IMHO these type of projects are not tools per-se but methodologies. I think this is a better framing since that's exactly what they are - a bunch of markdown files that describe in general terms how to perform an assessment aligned to some principles.
Btw, these type of methodologies are used all the time. Practically every security consultancy has them so adding them to an LLM makes a lot of sense.
- mkagenius
If there is a pentester here who uses mitmproxy, the security skills below (distilled from 4000 h1 disclosures) might help -https://github.com/instavm/security-skills
this is just a side project though for me
- ph3t
All these security/vulnerability scanning harnesses look more or less the same. Not sure what’s the point of bragging or publishing about them anymore, there’s no moat
- lfx
There are few more:
https://github.com/visa/visa-vulnerability-agentic-harness
https://github.com/cloudflare/security-audit-skill
I'm on the fence here, for one as from recent Linux mailing discussions those tools can really find good bugs (51% of them?), but on other side - I'm afraid of false sense of security.
- _joel
Why does this feel like an exec trying to justify token spend?