Capital One Unveils VulnHunter: An Agentic AI Tool for Proactive Code Security

VulnHunter: Capital One's agentic AI code security tool

Capital One Unveils VulnHunter: An Agentic AI Tool for Proactive Code Security

We are releasing VulnHunter, an open-source, agentic AI security tool designed to shift from passive scanning to proactive, attacker-perspective analysis. By simulating real attack paths and rigorously falsifying its own findings, VulnHunter minimizes false positives and provides developers with evidence-backed code remediations. This developer-first approach aims to secure software supply chains before advanced AI threats can exploit vulnerabilities.

The world faces an increasingly short window of time before highly sophisticated, next-generation AI attack capabilities become affordable and accessible to virtually every adversary.
  1. _pdp_

    IMHO these type of projects are not tools per-se but methodologies. I think this is a better framing since that's exactly what they are - a bunch of markdown files that describe in general terms how to perform an assessment aligned to some principles.

    Btw, these type of methodologies are used all the time. Practically every security consultancy has them so adding them to an LLM makes a lot of sense.

  2. mkagenius

    If there is a pentester here who uses mitmproxy, the security skills below (distilled from 4000 h1 disclosures) might help -https://github.com/instavm/security-skills

    this is just a side project though for me

  3. ph3t

    All these security/vulnerability scanning harnesses look more or less the same. Not sure what’s the point of bragging or publishing about them anymore, there’s no moat

  4. lfx

    There are few more:

    https://github.com/visa/visa-vulnerability-agentic-harness

    https://github.com/cloudflare/security-audit-skill

    I'm on the fence here, for one as from recent Linux mailing discussions those tools can really find good bugs (51% of them?), but on other side - I'm afraid of false sense of security.

  5. _joel

    Why does this feel like an exec trying to justify token spend?

More from this day

2026-07-17