</>MCP Agents Market
Agent

visa-vulnerability-agentic-harness

by visa2.7kPythonUpdated 2026-09-05

Visa Vulnerability Agentic Harness

Visa Vulnerability Agentic Harness (VVAH) is an open-source autonomous AI agent pipeline that discovers, remediates, and validates security vulnerabilities in code using large language models. Built on learnings from Anthropic's Project Glasswing, it runs an eleven-stage workflow from attack surface mapping and threat modeling through adversarial verification and automated fix generation. The agent supports multi-model configurations across Anthropic Claude, OpenAI-compatible endpoints, and open-weight models, with each pipeline stage configurable to use different providers and models. VVAH outputs structured findings in Markdown and SARIF 2.1.0 format and can automatically apply validated fixes to source code repositories.

Key Features

Eleven-stage autonomous pipeline (S1–S11) covering discovery, threat modeling, multi-lens analysis, adversarial verification, reporting, remediation, and fix validation
Multi-model architecture supporting Anthropic Claude, OpenAI-compatible endpoints, and open-weight models with per-role model assignment
Threat-aware analysis combining attack surface mapping, AST/call-graph seeding, and interprocedural taint analysis
Eleven specialist security lenses for deep-dive vulnerability research with multi-agent deterministic voting to reduce false positives
Structured output in Markdown and SARIF 2.1.0 with CVSS scores, CWE mappings, and per-run diagnostics
Automated remediation pipeline that generates, applies, and adversarially validates candidate fixes before adoption
Portfolio-scale scanning with resumable state, CSV-defined repository lists, and SQLite-based checkpoint management
Optional catch-all review for unrecognized file types to prevent silent exclusion from analysis

Use Cases

  • 01Autonomous security audits of application codebases to discover injection flaws, authentication bypasses, and data-flow vulnerabilities
  • 02Continuous vulnerability scanning across portfolio repositories with resumable state for enterprise-scale operations
  • 03AI-assisted triage pipelines that compress time from vulnerability discovery to validated production fix (MTTA optimization)
  • 04Threat-modeled code review focused on reachable attack surfaces rather than whole-repository scanning
  • 05Automated generation and validation of security patches with adversarial testing before human review
  • 06Integration with CI/CD workflows using SARIF output for GitHub Advanced Security and other SAST platforms

Related Agents

View more

visa-vulnerability-agentic-harness — FAQ

What is Visa Vulnerability Agentic Harness?+

VVAH is an open-source autonomous AI agent that uses large language models to discover, remediate, and validate security vulnerabilities in code through an eleven-stage pipeline. It combines threat modeling, multi-lens analysis, and adversarial verification to produce actionable findings and validated fixes.

How do I install and configure VVAH?+

Clone the repository, create a Python 3.11+ virtual environment, install with pip, and configure an Anthropic API key in a .env file. Run vvaharness setup to verify the installation and vvaharness doctor to check backend connectivity before scanning.

Which AI models and providers does VVAH support?+

VVAH supports Anthropic Claude (native), OpenAI and OpenAI-compatible endpoints, and open-weight models served via Chat Completions-compatible APIs. Each of the eleven pipeline stages can be configured to use different models and providers independently.

Do I need API keys to use VVAH?+

Yes, the default profile requires at least one Anthropic credential (ANTHROPIC_API_KEY, ANTHROPIC_AUTH_TOKEN, or ANTHROPIC_SDK_API_KEY). You can configure alternative providers for any pipeline stage using the model configuration system documented in docs/models.md.

Is VVAH free and open source?+

Yes, VVAH is licensed under Apache License 2.0 and free to use. However, running scans incurs costs from your configured model providers (Anthropic, OpenAI, etc.), and there is no global spend cap built in.

Does VVAH modify my code automatically?+

The default profile runs remediation (S10) and validation (S11) stages that apply fixes to source files. Use --stop-after s9 to run detection-only scans without code modification, or use the taint.yaml profile for analysis without remediation.

How do I install visa-vulnerability-agentic-harness?+

Open the source repository on GitHub and follow its README. visa-vulnerability-agentic-harness is a agent — MCP Agents Market links you directly to the official repo.

Is visa-vulnerability-agentic-harness free?+

visa-vulnerability-agentic-harness is an open-source project hosted on GitHub. Check the repository for its license and any usage requirements.

Related searches