Capital One VulnHunter open source agentic AI code security tool GitHub
Capital One $COF released VulnHunter, an open-source agentic AI tool that analyzes code from an attacker's perspective to flag exploitable vulnerabilities and suggest fixes, per Capital One and VentureBeat. It's built on Claude Opus, runs in Claude Code, and is on GitHub under Ap
Capital One $COF has released VulnHunter, an open-source agentic AI security tool designed to identify exploitable software vulnerabilities and recommend targeted fixes, according to the company's own announcement and VentureBeat. Unlike a conventional vulnerability scanner, VulnHunter uses an agentic reasoning workflow to analyze source code from an attacker's perspective, tracing possible attack paths rather than just flagging pattern matches, which Capital One says reduces the false positives that typically slow developer workflows. The tool is available on GitHub under an Apache 2.0 license and requires access to Claude Opus 4.8 running in a Claude Code environment. Capital One said it chose to open-source an internally built tool because modern software supply chains are so interconnected that no single organization can defend against AI-driven threats alone. The release is notable because it comes from a bank, an industry that typically guards its internal security tooling closely rather than publishing it for competitors and outside developers to use.