AI NewsDev toolsAnnouncement

nealbridges releases a maintained fork of Capital One's VulnHunter that runs on any agent harness, and reaches 424 stars in 14 days

nealbridges has released a maintained fork of Capital One's VulnHunter that works with any agent harness, under Apache 2.0, and the repository has gathered 424 stars in the 14 days since it was created on 22 September 2026.

AI News

Editorial3 min read

LinkedInX
GitHub social card for nealbridges/VulnHunter

Image: GitHub

Why it mattersA security scanner that attaches a working exploit to every finding moves the triage step a human had to do by hand into the project's own gate.

A security scanner that tells an agent to find bugs will fill the report with plausible false positives unless something between the agent and the report refuses to log a finding without a running exploit.

The repository nealbridges/VulnHunter, created on 22 September 2026 and now carrying 424 stars with 73 forks after 14 days, is a maintained fork of Capital One's VulnHunter, licensed under Apache 2.0. The author describes the project in its README as a "maintained fork of Capital One's VulnHunter (Apache-2.0)" that is "built to run on any agent harness, not just Claude Code." Capital One's original repository, created on 7 July 2026 and still active, has 1,056 stars under the same licence.

What the fork changes

The author lists four changes against the upstream project. The scanner's skills are configured through environment variables (VULNHUNT_SKILLS_DIR, VULNHUNT_AGENTS_DIR, VULNHUNT_MODEL), so a user can point the same loop at a different coding agent without rewriting it. The installer asks for directory paths instead of guessing at the host's layout. A Docker-first validation step runs each exploit in a sandbox and records measured outcomes such as rows exposed. A command named vulnhunter-run wraps the loop with explicit stop rules so it can run on a schedule without a person watching it.

The three skills, and the gate between them

The agent runs in three phases. A hunt phase (/vulnhunt) maps the entry points of a codebase to the sinks that would be unsafe to reach, works through a stage the project calls adversarial disprove, and emits only findings for which the agent has already written and run an exploit. A fix phase (/vulnhunter-fix) writes a security test alongside the fix. A verify phase (/vulnhunt-fix-verify) rereads the result from scratch, with the writing agent's work hidden from it, and judges whether the fix held.

The project's own benchmark, which the author describes as "six full scans of one real production Go service, same commit, five harness/model stacks, roughly three weeks", reports a 14-fold spread in the number of confirmed findings across those six runs on the same code. On the single scan that produced the fullest result, 42 of 42 confirmed findings carried an executable exploit test that passed, 55 percent of candidate findings had been eliminated or downgraded by the adversarial disprove pass, and 20 of 20 adversarial payloads ran against a live server with their outcomes measured. The author notes that the raw benchmark artifacts are "retained by the maintainer; ask, or re-run it yourself", so these numbers are the project's own measurements of its own loop.

Who it is for

A security team or a solo maintainer who already runs a coding agent on a codebase, and wants that agent to look for bugs on a schedule and only tell them about bugs it can prove. Python 3.12 or newer is needed for the runtime agent and the benchmarking harness. Open-weight models are described as the primary development target, which keeps the cost side of unattended runs predictable.

The 14-fold spread in confirmed findings across identical reruns is the number worth keeping. One scan says the loop works; six scans say the loop is noisy, and that any one scan is only part of the answer. Running the same codebase through the same stack twice is cheap, and the second run is where the first run's false positives tend to show.

Source

SourceGitHub

This item was written by an AI system from the linked source. Reveneau is responsible for what it publishes.

Share
LinkedInX