Live data from Hacker News

VulnHunter: Capital One's agentic AI code security tool

capitalone.com

11–20 of 45 posts

Re: VulnHunter: Capital One's agentic AI code security tool

#11
post #8

> If you intend to use VulnHunter on Anthropic's first-party platforms (Claude API / Claude Code), we strongly recommend enrolling first via the verification portal. Has anyone actually had success with this? I applied for my company several weeks ago, and never heard back.

Seems to be very random. I've heard stories like yours, as well as companies who applied and are approved same day.

Re: VulnHunter: Capital One's agentic AI code security tool

#15
post #4

All these security/vulnerability scanning harnesses look more or less the same. Not sure what’s the point of bragging or publishing about them anymore, there’s no moat

They're desperate for the hype.

Eh, Capital One has long been surprisingly progressive on open source and whatnot. They were one of the first to properly adopt OAuth to connect accounts, too, back when Plaid/Mint/etc. were mostly proxying logins.

https://www.capitalone.com/tech/open-source/

https://developer.capitalone.com/documentation/o-auth

Re: VulnHunter: Capital One's agentic AI code security tool

#16
IMHO these type of projects are not tools per-se but methodologies. I think this is a better framing since that's exactly what they are - a bunch of markdown files that describe in general terms how to perform an assessment aligned to some principles.

Btw, these type of methodologies are used all the time. Practically every security consultancy has them so adding them to an LLM makes a lot of sense.

Re: VulnHunter: Capital One's agentic AI code security tool

#17
post #6

Why does this feel like an exec trying to justify token spend?

They dont need to justify it.

Sorry to say, tokens aren’t going anywhere, people aren’t going to suddenly stop using AI, and this whole paradigm shift of how people are changing how they work - is a full blown reality.

There is no reversal, no “eh we don’t think the tokens/AI are worth it”. Accept the new reality.

Re: VulnHunter: Capital One's agentic AI code security tool

#18
post #13
post #4

All these security/vulnerability scanning harnesses look more or less the same. Not sure what’s the point of bragging or publishing about them anymore, there’s no moat

An end product to justify the Billions spent on AI

Also so that the engineers have something for the resume that looks and sounds impressive.

They don't know that Dario told me Fable is going to hack the planet.

Post reply on HN