VulnHunter
Agentic AI security tool that applies proactive, attacker-first analysis directly to source code.
VulnHunter is an agentic AI security tool delivered as a suite of Claude Code skills that performs attacker-first vulnerability analysis on source code. Unlike traditional pattern-matching SAST scanners, it simulates adversary reasoning to identify exploitable defects, maps attack paths, and proposes evidence-backed fixes. The three composable skills—/vulnhunt for scanning, /vulnhunter-fix for remediation, and /vulnhunt-fix-verify for validation—form a complete hunt-fix-verify loop. Developed by Capital One and optimized for Claude Opus, VulnHunter applies a falsification engine to eliminate false positives before surfacing high-priority, actionable findings.
Key Features
Use Cases
- 01Proactively scanning application source code to discover exploitable vulnerabilities before attackers find them
- 02Automating test-driven security remediation with red-green-refactor workflow for verified fixes
- 03Running headless security scans in CI/CD pipelines with automated GitHub issue creation for confirmed bugs
- 04Batch-scanning multiple repositories across an organization to identify supply chain vulnerabilities
- 05Independently validating security fixes to prove remediation without relying on developer assertions
- 06Benchmarking vulnerability detection accuracy against known-vulnerable test corpora
Related Skills
View moresuperpowers
An agentic skills framework & software development methodology that works.
skills
Skills for Real Engineers. Straight from my .agents directory.
skills
Public repository for Agent Skills
ponytail
Makes your AI agent think like the laziest senior dev in the room. The best code is the code you never wrote.
VulnHunter — FAQ
What is VulnHunter?+
VulnHunter is an agentic AI security tool distributed as three Claude Code skills that perform attacker-first vulnerability analysis on source code. It uses deep reasoning to identify exploitable defects, filter out false positives through a falsification engine, and propose evidence-backed fixes.
How do I install VulnHunter?+
Clone the VulnHunter repository and run the install.sh script (or install.cmd on Windows) to copy the skills into your ~/.claude/skills/ directory. Then launch Claude Code with the --add-dir flag pointing to the specific skill directories you want to use.
Which AI clients work with VulnHunter?+
VulnHunter is built exclusively for Claude Code and requires Claude Opus. The framework depends on frontier-class reasoning capabilities and is optimized specifically for the Claude Code skill system.
Do I need an API key or special access?+
You must have Claude Code CLI authenticated with access to Claude Opus. If using Anthropic's platforms, enrollment in Anthropic's Cyber Verification Program is strongly recommended to avoid real-time cyber safeguards blocking vulnerability discovery requests.
Is VulnHunter free to use?+
VulnHunter is open-source software released under the Apache License 2.0, but you supply your own Claude Opus model access. Usage costs depend on your Anthropic API billing.
What are the prerequisites for the fixer skill?+
The /vulnhunter-fix skill requires git, GitHub CLI (gh) authenticated to your repositories, Python 3.12+, and installation of its Python helper package. The scanner skill (/vulnhunt) and verifier skill are prompt-only with no additional dependencies beyond Claude Code.
How do I install VulnHunter?+
Open the source repository on GitHub and follow its README. VulnHunter is a skill — MCP Agents Market links you directly to the official repo.
Is VulnHunter free?+
VulnHunter is an open-source project hosted on GitHub. Check the repository for its license and any usage requirements.