visa-vulnerability-agentic-harness
Visa Vulnerability Agentic Harness
Visa Vulnerability Agentic Harness (VVAH) is an open-source autonomous AI agent pipeline that discovers, remediates, and validates security vulnerabilities in code using large language models. Built on learnings from Anthropic's Project Glasswing, it runs an eleven-stage workflow from attack surface mapping and threat modeling through adversarial verification and automated fix generation. The agent supports multi-model configurations across Anthropic Claude, OpenAI-compatible endpoints, and open-weight models, with each pipeline stage configurable to use different providers and models. VVAH outputs structured findings in Markdown and SARIF 2.1.0 format and can automatically apply validated fixes to source code repositories.
Key Features
Use Cases
- 01Autonomous security audits of application codebases to discover injection flaws, authentication bypasses, and data-flow vulnerabilities
- 02Continuous vulnerability scanning across portfolio repositories with resumable state for enterprise-scale operations
- 03AI-assisted triage pipelines that compress time from vulnerability discovery to validated production fix (MTTA optimization)
- 04Threat-modeled code review focused on reachable attack surfaces rather than whole-repository scanning
- 05Automated generation and validation of security patches with adversarial testing before human review
- 06Integration with CI/CD workflows using SARIF output for GitHub Advanced Security and other SAST platforms
Related Agents
View morehermes-agent
The agent that grows with you
agency-agents
A complete AI agency at your fingertips - From frontend wizards to Reddit community ninjas, from whimsy injectors to reality checkers. Each agent is a specialized expert with personality, processes, and proven deliverables.
openinterpreter
A coding agent for open models like Kimi K3
cline
Autonomous coding agent as an SDK, IDE extension, or CLI assistant.
visa-vulnerability-agentic-harness — FAQ
What is Visa Vulnerability Agentic Harness?+
VVAH is an open-source autonomous AI agent that uses large language models to discover, remediate, and validate security vulnerabilities in code through an eleven-stage pipeline. It combines threat modeling, multi-lens analysis, and adversarial verification to produce actionable findings and validated fixes.
How do I install and configure VVAH?+
Clone the repository, create a Python 3.11+ virtual environment, install with pip, and configure an Anthropic API key in a .env file. Run vvaharness setup to verify the installation and vvaharness doctor to check backend connectivity before scanning.
Which AI models and providers does VVAH support?+
VVAH supports Anthropic Claude (native), OpenAI and OpenAI-compatible endpoints, and open-weight models served via Chat Completions-compatible APIs. Each of the eleven pipeline stages can be configured to use different models and providers independently.
Do I need API keys to use VVAH?+
Yes, the default profile requires at least one Anthropic credential (ANTHROPIC_API_KEY, ANTHROPIC_AUTH_TOKEN, or ANTHROPIC_SDK_API_KEY). You can configure alternative providers for any pipeline stage using the model configuration system documented in docs/models.md.
Is VVAH free and open source?+
Yes, VVAH is licensed under Apache License 2.0 and free to use. However, running scans incurs costs from your configured model providers (Anthropic, OpenAI, etc.), and there is no global spend cap built in.
Does VVAH modify my code automatically?+
The default profile runs remediation (S10) and validation (S11) stages that apply fixes to source files. Use --stop-after s9 to run detection-only scans without code modification, or use the taint.yaml profile for analysis without remediation.
How do I install visa-vulnerability-agentic-harness?+
Open the source repository on GitHub and follow its README. visa-vulnerability-agentic-harness is a agent — MCP Agents Market links you directly to the official repo.
Is visa-vulnerability-agentic-harness free?+
visa-vulnerability-agentic-harness is an open-source project hosted on GitHub. Check the repository for its license and any usage requirements.