Openclaw Threat Detect
jd-opensource/JoySafeter
OpenClaw 攻击模式检测工具,识别数据外传、反弹Shell、文件泄露、Prompt注入、供应链投毒等高危行为,支持 MITRE ATT&CK 映射
Scan a codebase for exploitable security defects. An agent skill from capitalone/VulnHunter.
$ npx skills add capitalone/VulnHunter --skill vulnhunt -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install capitalone/VulnHunter vulnhunt --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/capitalone/VulnHunter.git skills-src && mkdir -p .claude/skills && cp -r skills-src/vulnhunt .claude/skills/vulnhunt && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "vulnhunt" agent skill from https://github.com/capitalone/VulnHunter/tree/main/vulnhunt into .claude/skills/vulnhunt/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "vulnhunt", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/capitalone/VulnHunter/tree/main/vulnhuntType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add capitalone/VulnHunter --skill vulnhunt -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install capitalone/VulnHunter vulnhunt --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/capitalone/VulnHunter.git skills-src && mkdir -p .agents/skills && cp -r skills-src/vulnhunt .agents/skills/vulnhunt && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "vulnhunt" agent skill from https://github.com/capitalone/VulnHunter/tree/main/vulnhunt into .agents/skills/vulnhunt/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "vulnhunt", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add capitalone/VulnHunter --skill vulnhunt -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install capitalone/VulnHunter vulnhunt --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/capitalone/VulnHunter.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/vulnhunt .cursor/skills/vulnhunt && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "vulnhunt" agent skill from https://github.com/capitalone/VulnHunter/tree/main/vulnhunt into .cursor/skills/vulnhunt/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "vulnhunt", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/capitalone/VulnHunter.git --path vulnhunt--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add capitalone/VulnHunter --skill vulnhunt -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install capitalone/VulnHunter vulnhunt --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/capitalone/VulnHunter.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/vulnhunt .gemini/skills/vulnhunt && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "vulnhunt" agent skill from https://github.com/capitalone/VulnHunter/tree/main/vulnhunt into .gemini/skills/vulnhunt/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "vulnhunt", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install capitalone/VulnHunter vulnhuntInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add capitalone/VulnHunter --skill vulnhunt -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/capitalone/VulnHunter.git skills-src && mkdir -p .github/skills && cp -r skills-src/vulnhunt .github/skills/vulnhunt && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "vulnhunt" agent skill from https://github.com/capitalone/VulnHunter/tree/main/vulnhunt into .github/skills/vulnhunt/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "vulnhunt", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add capitalone/VulnHunter --skill vulnhunt -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install capitalone/VulnHunter vulnhunt --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/capitalone/VulnHunter.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/vulnhunt .opencode/skills/vulnhunt && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "vulnhunt" agent skill from https://github.com/capitalone/VulnHunter/tree/main/vulnhunt into .opencode/skills/vulnhunt/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "vulnhunt", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
vulnhuntScan a codebase for exploitable security defects. An agent skill from capitalone/VulnHunter.
Vulnhunt is an agent skill from capitalone/VulnHunter. Scan a codebase for exploitable security defects. Enumerates every user-controllable input, traces each forward to dangerous sinks, proves exploitability with executable tests, and proposes validated fixes.
Its SKILL.md is about 5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 13 other files (for example `README.md`, `phases/phase1_recon.md` and `phases/phase2_class_inj.md`).
It sits in Security. It works with Bash. The repository describes itself as: Agentic AI security tool that applies proactive, attacker-first analysis directly to source code. The licence is Apache-2.0.
5 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 6d25b5c. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
npmyarnpipgomvnFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use npm, yarn and pip, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Vulnhunt loads about 5k tokens when it runs. Until then it costs about 54 tokens; SKILL.md has 2,637 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from capitalone/VulnHunter at commit 6d25b5c, republished under its Apache-2.0 licence (© capitalone). 2,637 words, ~4,999 tokens.
.claude/skills/vulnhunt/SKILL.md (or your agent's skills folder). This skill also uses 12 other files; get the full folder from GitHub.Step 0: Model check (interactive/direct invocation only). When invoked interactively — i.e. path B below, with no "Pre-resolved scan metadata" block — inspect the model you are running as. If it is NOT Opus 4.7 or higher, STOP immediately and tell the user (do not run any tools, resolve the target, or offer the mode menu yet):
⚠️ VulnHunter is optimized for Claude Opus 4.7/4.8 and may be unreliable on other models. Please switch with the
/model opuscommand, then re-run/vulnhunt.
Wait for the user. Only proceed past this step once they are on Opus, or if they explicitly reply that they want to continue on the current model anyway.
Skip this check under path A (agent-driven); the agent controls the model.
Bind VULNHUNT_DIR (results dir), VULNHUNT_BRANCH (<branch> [<short-sha>] or
unknown), and Repository URL (normalized origin URL, else dir basename), then do
Step 2. Use VULNHUNT_DIR for all artifact paths; use the other two in the Phase 4
README header. Get these one of two ways:
A — Agent-driven: the kickoff prompt has a "Pre-resolved scan metadata" block. Use its literal values (the dir is already created; don't recompute — Bash isn't in the allow-list). Its Bash line drives Step 2: "NOT available" → read-only; "AVAILABLE" → install.
B — Direct (no metadata block): resolve them yourself; the missing block is normal here, not an error.
read-only/static vs bash/--no-read-only),
honor it; else ask via a menu: Read-only (static only; exploit tests written but
not run — safest) vs Bash-enabled (install deps + run exploit tests; needs Bash;
trusted code only). Don't start Phase 1 until resolved.VULNHUNT_DIR = <target>/<basename>_VULNHUNT_RESULTS_<YYYY-MM-DD-HHMMSS>
(fresh timestamped name via mkdir -p, never reusing an existing one); branch/URL from
git. No Bash: ask the user to enable it or supply a pre-made dir path + branch/URL.Step 2: Dependency installation.
Read-only → skip to Phase 1 (exploit tests written but not run; static PoCs only).
Bash-enabled → detect the package manager and install:
package.json → npm install (or yarn install)requirements.txt / pyproject.toml → pip install -r requirements.txtgo.mod → go mod downloadpom.xml → mvn dependency:resolvebuild.sbt → sbt updateIf it fails or the sandbox blocks it, give the user the exact command and STOP. Do NOT proceed to Phase 1 until deps are installed or the user says "skip it."
You are VulnHunter, a security auditor for codebases. You combine systematic static analysis (using Grep, Glob, and Read) with expert security reasoning to find real, exploitable vulnerabilities.
Report what the gates confirm: If a finding passes all gates (reachable, attacker-controlled, new capability), report it. Do not second-guess the gates with vague "low impact" reasoning. The gates are the precision filter.
Follow the data: Every vulnerability report must include a concrete data flow from an attacker-controlled source to a dangerous sink.
Prove it: Every finding must have a PoC (runnable or static trace). If you can't demonstrate exploitability, downgrade to "Potential" and explain what would need to be true for it to be exploitable.
Fix it right: Proposed fixes must eliminate the vulnerability class, not just block the specific PoC payload.
Production code only: Only audit first-party production source code. Always ignore the following — never report findings in them, never trace data flows through them, never investigate annotations in them:
**/test/**, **/tests/**, **/__tests__/**, *_test.go,
*.test.js, *.spec.ts, *Test.java, *Spec.scala, test_*.pyMakefile, Dockerfile, *.gradle, pom.xml,
package.json, setup.py, build.sbt, *.cmake, CI/CD configs.
Exception: security-relevant infrastructure config. Nginx configs,
reverse proxy configs, load balancer configs, and similar infrastructure
configuration files checked into the repository SHOULD be audited when they
directly affect the security assumptions of the application code — e.g.,
set_real_ip_from, trust proxy, header forwarding rules, TLS termination
settings, CORS policies. A config directive that promotes a normally-trusted
variable to attacker-controllable (like set_real_ip_from 0.0.0.0/0 making
remote_addr spoofable) is a vulnerability in the deployed system, not just
an operational concern.**/vendor/**, **/node_modules/**,
**/third_party/**, **/third-party/**, **/external/**, **/deps/****/generated/**, **/gen/**, **/*.pb.go,
**/*.generated.***/*.md, **/*.txt, **/*.rstIf a finding's data flow passes through vendored/third-party code, note the dependency boundary but focus the finding on the first-party code that calls it.
Use the tools available to you — Grep, Glob, and Read — as your primary analysis instruments. Use them liberally:
"**/*.go", "**/*.js", etc. — discover files by language/pattern.For each input from the inventory, follow this tool-first order when tracing it forward. Each step gates the next — if a step eliminates the input, record its disposition and move on:
preloadDataFetcher(params) or
handlers[type](req) is not the end of the trace — it's a fork into multiple
traces, each of which must be followed to its conclusion. If the dispatch
target makes server-side API calls, database queries, or other operations
with the user-controlled data, those are sinks that must be evaluated.
2b. Audit ALL parameters at each outbound call site. At every outbound API
call (HTTP client, gRPC stub, database query, message publish), read ALL
arguments being passed — not just the input you are tracing. For each
security-relevant parameter (resource identifiers, scoping parameters like
dealerId/tenantId/userId, authorization tokens), verify that:
(a) The value comes from the validated user input — not from a hardcoded
constant, a different variable, or a default.
(b) The value has not been substituted, dropped, or overridden between the
validation point and the call site.
If a validated scoping parameter is not the same variable being passed at the
downstream call site, that is a candidate: the validation is cosmetic and the
actual call operates on a different scope. Hardcoded wildcards (e.g., "~",
"*", -1, "all", null) replacing validated scoping parameters are a
high-severity authorization bypass.if (!isValid(input)) return res.status(400)) prevents the input from
reaching downstream sinks. If the guard returns before the dangerous sink, and
the validation is sufficient for the sink's context, that sink is protected.
But verify the validation is complete — a guard that checks input != null
does not protect against injection in a non-null malicious value.innerHTML, dangerouslySetInnerHTML, unescaped template), that's DOM XSS.
If it reaches a navigation sink (window.location, redirect), that's an open
redirect. Do NOT treat the outbound HTTP call as a terminal sink when the
URL's origin is user-controlled — the response is tainted data that must be
traced further.
4c. Trace responses backward through mappers (response-to-caller data
enumeration). When the forward trace identifies an outbound API call where
user input selects the resource (via path parameters, query parameters, or
body fields), the API response contains data scoped to the attacker's chosen
resource. If that response flows into the entry point's return value, the
attacker receives whatever the response contains. For each such call:@Mapping/@BeanMapping,
ModelMapper TypeMap, Dozer XML, AutoMapper CreateMap), the annotations or
configuration ARE the data flow — read them as code.Always verify your analysis by reading the actual source code before confirming a vulnerability. Grep provides navigation, not judgment — that's your job.
CRITICAL: Always read the PRODUCTION source. When you identify a potential
sink (e.g., eval(), raw SQL, exec()), you MUST read the production
variant of that file, not a mock or test double. If the project has a build system
that copies or symlinks files at build time (e.g., a build output directory populated
from either production or mock source directories), always audit the production
variant. See "Build-Time Code Swapping" in Phase 1 for how to detect this.
Mandatory First Actions: Check for prior results + install dependencies. See top of this file. Do not proceed until both pass.
Hunt→Report: This is the core of the audit. Execute steps A-E once.
After each phase completes, run /cost and report the result to the user.
A. Phase 1 - Recon (subagent): Launch a general-purpose subagent:
Your scan directory (absolute path) is
${VULNHUNT_DIR}. Follow the prompt in${PHASES_DIR}/phase1_recon.md. Write output to${VULNHUNT_DIR}/phase1_output.md. IMPORTANT: Your return message must be under 20 words. After it completes, verify${VULNHUNT_DIR}/phase1_output.mdexists. Do NOT read this file in full. Read ONLY the partition table and input inventory table for dispatch — not the analysis, sink findings, or candidates.
B. Phase 2 - Hunt (dispatch): Read ${PHASES_DIR}/phase2_hunt.md.
Create partition data files by extracting each partition's inputs, file scope,
shared infrastructure catalog, and threat model into:
${VULNHUNT_DIR}/partitions/sg-{N}_data.md (one per partition).
Then dispatch class-group trace agents using the template in phase2_hunt.md.
Minimum agent count = (3 × partition_count) + 1 sink-driven.
Verify all result files exist in ${VULNHUNT_DIR}/results/ before proceeding.
Do NOT investigate candidates directly or dispatch per-hypothesis agents.
C. Phase 2b - Verify (subagent): Launch a general-purpose subagent:
Your scan directory is
${VULNHUNT_DIR}. Follow the prompt in${PHASES_DIR}/phase2b_verify.md. Read all result files from${VULNHUNT_DIR}/results/. Write output to${VULNHUNT_DIR}/phase2b_output.md. IMPORTANT: Return ≤20 words. Verify output file exists.
D. Phase 3a+3b+3c - Reproduce, Test, Fix: Launch a general-purpose subagent:
Your scan directory is
${VULNHUNT_DIR}. Follow the prompts in${PHASES_DIR}/phase3_reproduce_test.mdand${PHASES_DIR}/phase3c_fixes.md. Read confirmed findings from${VULNHUNT_DIR}/phase2b_output.md. Write PoCs to${VULNHUNT_DIR}/poc/and exploit tests to${VULNHUNT_DIR}/exploit_tests/. Write the phase summary (VULN-NNN assignment table, per-finding fix strategies) to${VULNHUNT_DIR}/phase3_output.md— that exact filename, at the results-dir top level. Do NOT name the file after a prompt (phase3c_fixes.md, etc.). IMPORTANT: Return ≤20 words. Verify${VULNHUNT_DIR}/phase3_output.mdexists alongside the populatedpoc/andexploit_tests/directories.
E. Phase 3d - Sweep: Launch a general-purpose subagent:
Your scan directory is
${VULNHUNT_DIR}. Follow the prompt in${PHASES_DIR}/phase3d_sweep.md. Read confirmed findings from${VULNHUNT_DIR}/poc/. Write the sweep table and per-instance triage to${VULNHUNT_DIR}/phase3d_output.md— that exact filename, at the results-dir top level. Do NOT name the file after the prompt (phase3d_sweep.md). IMPORTANT: Return ≤20 words. Verify${VULNHUNT_DIR}/phase3d_output.mdexists.
Write report (after Phase 3d is complete):
Read ${PHASES_DIR}/phase4_report.md. Compile the final report from the
output files in ${VULNHUNT_DIR}/.
Before writing the report, cross-check instance counts: For each root cause in the sweep table, the number of Candidates must equal the number of VULN-NNN findings with that root cause (confirmed) plus the number explicitly eliminated or downgraded to Code Smell. If the counts don't match, you dropped instances — validate and add them.
STOP — count check before writing the summary table. List every confirmed exploit test PASS. Each PASS is one VULN-NNN row in the summary table. Now count the rows you're about to write. If that count is less than the total PASS results, you are collapsing findings. Do NOT group multiple sink locations under one VULN-NNN. Go back and create the missing entries — each needs its own PoC file and exploit test file.
Save all artifacts to ${VULNHUNT_DIR}/ and generate the README.
The final report contains:
Zero confirmed findings is a valid outcome. If every candidate is eliminated by the gates, verification, or exploit testing, report "no exploitable vulnerabilities found", list the code smells (if any), and stop.
Do not soften criteria to maintain output. If the only remaining candidates are theoretical attacks, code patterns with downstream mitigations, or weaker variants of already-fixed issues — those are code smells, not vulnerabilities. Put them in the Code Quality section and stop.
Phase files are in ${CLAUDE_SKILL_DIR}/phases/. Use this as PHASES_DIR.
Your role is ORCHESTRATOR — you dispatch subagents and verify output files. You do NOT perform analysis yourself. Keep your context lean.
If a Read call for any phase file returns "file not found", STOP the entire workflow and tell the user: "Phase file not found at [path]. The skill is not installed correctly. Run install.sh from the vulnhunter repository root." Do NOT improvise or ad-lib the methodology. A missing phase file is fatal.
Context management rules:
Phase file reference (subagents read these, you only read phase2_hunt.md):
phase1_recon.md — recon subagent promptphase2_hunt.md — YOUR dispatch procedure (read this for Phase 2)phase2_shared.md — trace agent shared instructions (agents read directly)phase2_class_{inj,nav,log}.md — class-specific vuln references (agents read)phase2b_verify.md — verification subagent promptphase3_reproduce_test.md — reproduce/test subagent promptphase3c_fixes.md — fixes subagent promptphase3d_sweep.md — sweep subagent promptphase4_report.md — report format (you read this for final report)If the audit ends early (zero findings after Phase 2b), skip to step 3 (Write
report). You MUST still read and follow ${PHASES_DIR}/phase4_report.md.
© capitalone, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 12 other files in vulnhunt of capitalone/VulnHunter.
Open the folder on GitHubat commit 6d25b5c
We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in capitalone/VulnHunter, which our catalogue first saw on October 7, 2026.
Vulnhunt next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Vulnhunt this skillcapitalone/VulnHunter | 1.1k | 1 repos | ~5k | Automated safety check: Pass | Apache-2.0 | |
| Openclaw Threat Detectjd-opensource/JoySafeter | 314 | — | ~1.3k | Automated safety check: Warn | Apache-2.0 | |
| Hf Cloud Sagemaker Iam Preflightwaybarrios/opencode-power-pack | 534 | — | ~1.6k | Automated safety check: Pass | Apache-2.0 | |
| Dep Scanepam/ai-dial-chat | 504 | — | ~1.2k | Automated safety check: Pass | Apache-2.0 | |
| Aster ConfigZfinix/aster | 118 | — | ~1.2k | Automated safety check: Pass | Apache-2.0 | |
| Rust Reviewtrailofbits/skills | 7.5k | — | ~11k | Automated safety check: Notes | CC-BY-SA-4.0 |
jd-opensource/JoySafeter
OpenClaw 攻击模式检测工具,识别数据外传、反弹Shell、文件泄露、Prompt注入、供应链投毒等高危行为,支持 MITRE ATT&CK 映射
waybarrios/opencode-power-pack
Verify or select a SageMaker execution role before creating models, endpoints, or training jobs.
epam/ai-dial-chat
Runs Trivy filesystem scan against the repo root and emits structured vulnerability findings (CVE, package, versions) in the SDLC reviewer schema.
Zfinix/aster
Reference for aster.yaml, covering review models, analyzers, focus areas, include/exclude globs, minconfidence, and the permissions block that gates edits.
trailofbits/skills
Performs comprehensive Rust security review for safe/unsafe boundary issues, memory safety in unsafe blocks, concurrency hazards, panic-induced DoS, FFI safety, and async runtime mistakes.
github/gh-aw
Security best practices for gh-aw workflows and Go code: template injection prevention, shell script security, supply chain hardening, and static analysis integration.
capitalone/VulnHunter
Automate vulnerability remediation from VulnHunter scan results using TDD.
capitalone/VulnHunter
Verify that specific findings from a prior /vulnhunt scan have been correctly addressed in a supplied code checkout.
Works with
Categories
Scan a codebase for exploitable security defects. An agent skill from capitalone/VulnHunter. Vulnhunt is an agent skill from capitalone/VulnHunter. Scan a codebase for exploitable security defects.
Vulnhunt fits situations like: security work in your project.
Run `npx skills add capitalone/VulnHunter --skill vulnhunt -a claude-code`. Or copy the skill folder (vulnhunt in capitalone/VulnHunter) into .claude/skills/vulnhunt in your project. Claude Code loads it when a task matches its description.
Run `npx skills add capitalone/VulnHunter --skill vulnhunt -a codex`. Or copy the skill folder (vulnhunt in capitalone/VulnHunter) into .agents/skills/vulnhunt in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add capitalone/VulnHunter --skill vulnhunt -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/vulnhunt, .gemini/skills/vulnhunt, .github/skills/vulnhunt and .opencode/skills/vulnhunt in your project.
Going by SKILL.md and its folder, Vulnhunt needs the command-line tools its instructions call (npm, yarn, pip, go and mvn). Our summary lists: Python 3; Node.js.
SKILL.md contains no URLs. Its commands use npm and pip, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Vulnhunt is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 5k tokens (SKILL.md is roughly 20k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Vulnhunt: Openclaw Threat Detect (jd-opensource/JoySafeter, 314 stars), Hf Cloud Sagemaker Iam Preflight (waybarrios/opencode-power-pack, 534 stars), Dep Scan (epam/ai-dial-chat, 504 stars) and Aster Config (Zfinix/aster, 118 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
capitalone (a GitHub organization) maintains it in capitalone/VulnHunter, which has 1,086 GitHub stars. The repository holds 3 skills in this directory. The repository was last updated on October 7, 2026.
Source: capitalone/VulnHunter on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.