VulnHunter: Capital One's agentic AI code security tool
31–40 of 45 posts
Re: VulnHunter: Capital One's agentic AI code security tool
#32Earlier quoted context omitted.
They dont need to justify it. Sorry to say, tokens aren’t going anywhere, people aren’t going to suddenly stop using AI, and this whole paradigm shift of how people are changing how they work - is a full blown reality. There is no reversal, no “eh we don’t think the tokens/AI are worth it”. Accept the new reality.
Don’t underestimate how banks operate. Things move very slowly in banking, so they absolutely need to justify it. Many banks still use GPT Mini, and even that requires approval from two levels of management. Even upgrading from Java 8 to Java 17 requires extensive justification. Forget AI—you even have to justify using a MacBook.
Re: VulnHunter: Capital One's agentic AI code security tool
#33I think it's actually interesting how you can use the same model to both find and falsify the findings
Re: VulnHunter: Capital One's agentic AI code security tool
#34Why does this feel like an exec trying to justify token spend?
They dont need to justify it. Sorry to say, tokens aren’t going anywhere, people aren’t going to suddenly stop using AI, and this whole paradigm shift of how people are changing how they work - is a full blown reality. There is no reversal, no “eh we don’t think the tokens/AI are worth it”. Accept the new reality.
Re: VulnHunter: Capital One's agentic AI code security tool
#35There are few more: https://github.com/visa/visa-vulnerability-agentic-harness https://github.com/cloudflare/security-audit-skill I'm on the fence here, for one as from recent Linux mailing discussions those tools can really find good bugs (51% of them?), but on other side - I'm afraid of false sense of security.
Are they glorified markdown skill files, or something more?
Re: VulnHunter: Capital One's agentic AI code security tool
#36If there is a pentester here who uses mitmproxy, the security skills below (distilled from 4000 h1 disclosures) might help - https://github.com/instavm/security-skills this is just a side project though for me
How does your skills comparison to the offering from Capital One, as well,as what Visa published?
Re: VulnHunter: Capital One's agentic AI code security tool
#37If there is a pentester here who uses mitmproxy, the security skills below (distilled from 4000 h1 disclosures) might help - https://github.com/instavm/security-skills this is just a side project though for me
Thanks for sharing. How does your skills comparison to the offering from Capital One, as well,as what Visa published? https://github.com/visa/visa-vulnerability-agentic-harness
More like a red team.
Re: VulnHunter: Capital One's agentic AI code security tool
#38If there is a pentester here who uses mitmproxy, the security skills below (distilled from 4000 h1 disclosures) might help - https://github.com/instavm/security-skills this is just a side project though for me
Re: VulnHunter: Capital One's agentic AI code security tool
#39Re: VulnHunter: Capital One's agentic AI code security tool
#40So, not Open Source.