VulnHunter: How Capital One Is Using Agentic AI to Hunt Vulnerabilities Before Attackers Do
Case study on Capital One's VulnHunter: autonomous agentic AI scanning codebases and identifying zero-day logic flaws.
What VulnHunter Is
VulnHunter is an open-source, agentic AI security tool built by Capital One and released under the Apache 2.0 license. Rather than scanning source code for known-bad patterns the way a traditional static analysis (SAST) tool does, VulnHunter reasons about a codebase the way an attacker would: it looks for exploitable defects, traces plausible attack paths through the code, and proposes targeted remediations for a developer to review.
How It Works
The initial release is implemented as a Claude Code skill and is optimized specifically for Claude Opus 4.8, which means running it requires access to that model plus a working Claude Code environment. Rather than a single-pass scan, VulnHunter uses an agentic workflow: it can explore a codebase iteratively, reason about how different components interact, and validate whether a candidate finding is actually reachable and exploitable before surfacing it, aiming to cut down on the noisy false positives that make traditional SAST output hard to act on.
Why Capital One Open-Sourced It
Capital One has framed the release as a response to attackers increasingly using advanced AI models offensively to find and exploit vulnerabilities faster and at greater scale than manual code review allows. The reasoning is straightforward: if AI is lowering the cost of finding vulnerabilities for attackers, defenders benefit from equally capable, publicly available tooling rather than leaving offense-defense AI capability asymmetric in the attacker's favor.
Getting Started and Considerations
VulnHunter is available now on GitHub under capitalone/vulnhunter. Because it depends on Claude Opus 4.8 and Claude Code specifically, teams evaluating it should budget for the associated model access rather than expecting a drop-in, model-agnostic scanner. As with any AI-assisted security tool, treat its output as a strong starting point for a human reviewer rather than an authoritative finding, and validate proposed remediations in a non-production environment before merging.
Related
This post is part of this week's Security Roundup: SharePoint's Next Zero-Day, Oracle's Record CPU, and the EY Breach (Week of July 20, 2026), at colibrisec.org/security-roundup-sharepoints-next-zero-day-cpu-and-the-ey-breach-week-of-july-20-2026/.