Capital One open-sources an AI red teamer that tries to disprove itself
VulnHunter flips SAST on its head: instead of pattern-matching sinks backward, it walks attack paths forward and falsifies its own findings before reporting them.
What it does
VulnHunter is an agentic security scanner built as a set of Claude Code skills. Rather than the usual sink-first static analysis — find dangerous code patterns, then imagine an attacker — it starts at attacker-reachable entry points (APIs, file uploads, network messages) and reasons forward along the attacker’s actual journey. Findings that survive get an exploit path, an explanation of what the attacker gains, and a proposed fix.
The interesting bit
The falsification engine. After hypothesizing a vulnerability, VulnHunter runs a structured workflow designed to disprove its own argument — hunting for flawed assumptions, logic gaps, or controls that would block the attack. Findings resting on unsupported assumptions get discarded before they reach you. It’s the scientific method applied to a bug scanner, and it’s the mechanism behind the low false-positive pitch.
Key highlights
- Three composable skills forming a closed loop:
/vulnhunt(hunt),/vulnhunter-fix(test-driven fix, RED→GREEN, cuts a PR), and/vulnhunt-fix-verify(a separate read-only agent that independently confirms remediation) - The verifier runs with no Bash execution and no network access — fixes are proven, not taken on faith
vulnhunter-agent/wraps the scanner in a headless runtime for CI/CD, including auto-filing GitHub issuesharness/supports batch scanning across many repos plus benchmarking against a known-vulnerable corpus (ships with a synthetic example mapped to NodeGoat, Juice Shop, WebGoat)- Apache 2.0, developed internally at Capital One
Caveats
- Hard dependency on Claude Opus via Claude Code — the reasoning depth is the product, so you supply (and pay for) frontier model access
- Dual-use territory: without enrollment in Anthropic’s Cyber Verification Program, real-time safeguards may block requests and flag your usage
- The core scanner and verifier skills are prompt-only (
SKILL.md+ phases) — the intelligence lives in orchestration, not novel code
Verdict
Worth a look if you already run Claude Code and want fewer false positives from security scanning — the falsification loop is a genuinely interesting pattern. If you’re hoping for a model-agnostic, drop-in SAST replacement, this isn’t it; it’s Opus-shaped glue, and priced accordingly.
Frequently asked
- What is capitalone/VulnHunter?
- VulnHunter flips SAST on its head: instead of pattern-matching sinks backward, it walks attack paths forward and falsifies its own findings before reporting them.
- Is VulnHunter open source?
- Yes — capitalone/VulnHunter is open source, released under the Apache-2.0 license.
- What language is VulnHunter written in?
- capitalone/VulnHunter is primarily written in Python.
- How popular is VulnHunter?
- capitalone/VulnHunter has 1k stars on GitHub.
- Where can I find VulnHunter?
- capitalone/VulnHunter is on GitHub at https://github.com/capitalone/VulnHunter.