</>MCP Agents Market
Skill

VulnHunter

by capitalone985PythonUpdated 2026-08-15

Agentic AI security tool that applies proactive, attacker-first analysis directly to source code.

Claude Code

VulnHunter is an agentic AI security tool delivered as a suite of Claude Code skills that performs attacker-first vulnerability analysis on source code. Unlike traditional pattern-matching SAST scanners, it simulates adversary reasoning to identify exploitable defects, maps attack paths, and proposes evidence-backed fixes. The three composable skills—/vulnhunt for scanning, /vulnhunter-fix for remediation, and /vulnhunt-fix-verify for validation—form a complete hunt-fix-verify loop. Developed by Capital One and optimized for Claude Opus, VulnHunter applies a falsification engine to eliminate false positives before surfacing high-priority, actionable findings.

Key Features

Attacker-first forward analysis starting from entry points (APIs, uploads, network messages) rather than backward sink-first pattern matching
Multi-stage falsification pipeline that actively disproves its own findings to eliminate false positives before reporting
Three composable Claude Code skills forming a complete remediation loop: /vulnhunt scanner, /vulnhunter-fix test-driven fixer, and /vulnhunt-fix-verify independent validator
Evidence-backed remediation that maps exact exploit paths, explains structural flaws, and generates targeted code changes
Headless runtime agent wrapper for CI/CD pipelines with GitHub issue automation and API-direct execution
Batch scanning harness for processing multiple repositories with progress tracking and centralized collection
Benchmarking mode with LLM-judge evaluation against known-vulnerable corpora to measure detection accuracy
Read-only verification skill with restricted tool envelope (no bash execution or network access) for secure validation

Use Cases

  • 01Proactively scanning application source code to discover exploitable vulnerabilities before attackers find them
  • 02Automating test-driven security remediation with red-green-refactor workflow for verified fixes
  • 03Running headless security scans in CI/CD pipelines with automated GitHub issue creation for confirmed bugs
  • 04Batch-scanning multiple repositories across an organization to identify supply chain vulnerabilities
  • 05Independently validating security fixes to prove remediation without relying on developer assertions
  • 06Benchmarking vulnerability detection accuracy against known-vulnerable test corpora

Related Skills

View more

VulnHunter — FAQ

What is VulnHunter?+

VulnHunter is an agentic AI security tool distributed as three Claude Code skills that perform attacker-first vulnerability analysis on source code. It uses deep reasoning to identify exploitable defects, filter out false positives through a falsification engine, and propose evidence-backed fixes.

How do I install VulnHunter?+

Clone the VulnHunter repository and run the install.sh script (or install.cmd on Windows) to copy the skills into your ~/.claude/skills/ directory. Then launch Claude Code with the --add-dir flag pointing to the specific skill directories you want to use.

Which AI clients work with VulnHunter?+

VulnHunter is built exclusively for Claude Code and requires Claude Opus. The framework depends on frontier-class reasoning capabilities and is optimized specifically for the Claude Code skill system.

Do I need an API key or special access?+

You must have Claude Code CLI authenticated with access to Claude Opus. If using Anthropic's platforms, enrollment in Anthropic's Cyber Verification Program is strongly recommended to avoid real-time cyber safeguards blocking vulnerability discovery requests.

Is VulnHunter free to use?+

VulnHunter is open-source software released under the Apache License 2.0, but you supply your own Claude Opus model access. Usage costs depend on your Anthropic API billing.

What are the prerequisites for the fixer skill?+

The /vulnhunter-fix skill requires git, GitHub CLI (gh) authenticated to your repositories, Python 3.12+, and installation of its Python helper package. The scanner skill (/vulnhunt) and verifier skill are prompt-only with no additional dependencies beyond Claude Code.

How do I install VulnHunter?+

Open the source repository on GitHub and follow its README. VulnHunter is a skill — MCP Agents Market links you directly to the official repo.

Is VulnHunter free?+

VulnHunter is an open-source project hosted on GitHub. Check the repository for its license and any usage requirements.

Related searches