V
What is VulnHunter?
VulnHunter is an open-source, agentic AI security tool built internally at Capital One and released publicly under Apache 2.0. Instead of pattern-matching like a traditional SAST scanner, it reasons like an attacker: it identifies which defects are actually exploitable, maps prospective attack paths, and proposes targeted, evidence-backed fixes.
It runs as a set of skills inside Claude Code and requires access to Claude Opus.
Key features
- Reasons like an attacker instead of pattern-matching like traditional SAST scanners
- Maps prospective attack paths and proposes evidence-backed fixes
- Runs as a Claude Code skill (/vulnhunt) with companion fix and fix-verify skills
- /vulnhunter-fix helps apply proposed remediations
- /vulnhunt-fix-verify checks that a fix actually closes the vulnerability
- Headless vulnhunter-agent wrapper for CI/CD that files GitHub issues automatically
How to get started
- Clone github.com/capitalone/vulnhunter
- Make sure you have Claude Opus access via Claude Code
- Run the /vulnhunt skill against your codebase
- Review the attack paths and proposed fixes it surfaces
- Optionally wire vulnhunter-agent into CI for automatic scans and GitHub issues
VulnHunter pricing
VulnHunter itself is free and open source under Apache 2.0. The real cost is Claude Opus API usage - independent estimates put a full scan of a 50K-line codebase at roughly $200-500 in token costs.
| Plan | Price | Best for |
|---|---|---|
| Open source | Free (Apache 2.0) | Any team willing to run their own Claude Opus usage |
| Claude API usage | ~$200-500 per 50K-line scan | The actual cost driver, paid to Anthropic, not Capital One |
Our take: Genuinely free and open source to run, but it's Opus-only and token-hungry - a real cost barrier for teams without an existing Claude Opus budget, and Capital One notes other models are not yet validated for it.
Prices verified 2026-09. Plans change often — confirm on the official site above before you buy.
Use cases
- Security teams triaging SAST false positives with exploitability proof
- One-off deep security audits of a medium-sized codebase (10K-100K lines)
- CI pipelines that need automatic vulnerability reports filed as GitHub issues
- Teams already paying for Claude Opus and Claude Code access
VulnHunter vs. alternatives
| Tool | How it compares |
|---|---|
| VulnHunter | Capital One's open-source, agentic AI security scanner that proves which code vulnerabilities are actually exploitable. |
| CodeRabbit | CodeRabbit focuses on general code review rather than adversarial security analysis. |
| Claude Code | Claude Code is the harness VulnHunter runs inside of. |
FAQ
Is VulnHunter free to use?
VulnHunter's plans: Free and open source (Apache 2.0); you pay only for the Claude API usage it runs on. Pricing and free-tier limits change over time, so check the official site above for the latest details.
What is VulnHunter used for?
Capital One's open-source, agentic AI security scanner that proves which code vulnerabilities are actually exploitable.
Who is VulnHunter best for?
VulnHunter is a good fit for security teams triaging SAST false positives with exploitability proof, or one-off deep security audits of a medium-sized codebase (10K-100K lines).
What are the alternatives to VulnHunter?
Commonly compared alternatives include CodeRabbit and Claude Code, see the comparison above for how they differ.
How much does VulnHunter cost?
VulnHunter has no license fee - it is free, open source, and Apache 2.0 licensed. All cost comes from Claude Opus API usage through Anthropic, which can run $200-500+ per scan on a mid-sized codebase.
Related tools
Last updated: 2026-09 · Reviewed by AIKetra editors · Domain registered 2007 (19 years old) · How we evaluate tools · Embed a Featured badge