23 comments

[ 3.7 ms ] story [ 51.5 ms ] thread
VulnHunter: Capital One’s open-source, agentic AI code security tool.
All these security/vulnerability scanning harnesses look more or less the same. Not sure what’s the point of bragging or publishing about them anymore, there’s no moat
Put a wrapper around nessus, stave off a "below strong" rating another six months
Why does this feel like an exec trying to justify token spend?
This is a sad. Makes me want to move my bank accounts.
> If you intend to use VulnHunter on Anthropic's first-party platforms (Claude API / Claude Code), we strongly recommend enrolling first via the verification portal.

Has anyone actually had success with this? I applied for my company several weeks ago, and never heard back.

If there is a pentester here who uses mitmproxy, the security skills below (distilled from 4000 h1 disclosures) might help -https://github.com/instavm/security-skills

this is just a side project though for me

I can't imagine claude being able to use any of these without immediately refusing.
Wasn't Capital One founded on the premise of massive-scale market and product experimentation? Makes sense that they would design tools that match that approach.
IMHO these type of projects are not tools per-se but methodologies. I think this is a better framing since that's exactly what they are - a bunch of markdown files that describe in general terms how to perform an assessment aligned to some principles.

Btw, these type of methodologies are used all the time. Practically every security consultancy has them so adding them to an LLM makes a lot of sense.

(comment deleted)
Curious if the team at CapitalOne can share in more detail how this tool is being used internally, including how it’s helped their security practices and culture. That would help address some of the legitimacy concerns.
I think it's actually interesting how you can use the same model to both find and falsify the findings
Repo will be inactive and obsolete within 12 months.
Open source... Requires Claude Code CLI, authenticated with access to Claude Opus.

So, not Open Source.