Skip to main content

AI coding agentsMCP server · skill · write-time guard

Your agent finds, proves and fixes vulnerabilities. Without reading the codebase.

Vulkro hands your AI coding agent the finding, the attack path behind it and, where a known fix applies, a patch checked by a second scan. 98% fewer tokens than an agent reading the codebase itself to find the same issues. Offline, with no AI in detection.

  • Claude Code
  • Cursor
  • Codex
  • GitHub Copilot
  • Windsurf
  • Any MCP client
AI coding agent · billing-apiMCP: vulkro
  1. YouAdd an endpoint that returns an invoice by id.
  2. AgentAdded GET /api/invoices/:id. Asking Vulkro before I go on.
  3. Tool callscan_file src/routes/invoices.ts
  4. Vulkrojs-taint-sql-001 · Critical · proven
    The id from the URL reaches a SQL query built by string concatenation.
  5. Tool callprove js-taint-sql-001:7f3a…
  6. Vulkro
    1. source req.params.id routes/invoices.ts:12
    2. hop getInvoice(id) services/billing.ts:40
    3. sink db.query("… WHERE id = " + id) services/billing.ts:44
  7. Tool callsuggest_fixes scan_id
  8. VulkroRemedy: the driver's bound-parameter form. Patch applied to a copy and scanned again: fixed.
  9. AgentApplied the patch. Checking my own diff before I commit.
  10. Tool callverify_fix diff
  11. Vulkrofixed · the finding is gone and nothing new at Medium or above appeared in the changed lines.
Tool
verify_fix
Plan
Free
Model tokens Vulkro spent
0

01The problem

AI coding agents ship code before anyone checks it

An agent that hunts for vulnerabilities reads your code into its context and guesses. An agent that writes code can ship it before anyone reviews it. Point at a problem to see it in the log.

AI coding agent · session logno security check
  1. Readsrc/app.ts
  2. Readsrc/routes/index.ts
  3. Readsrc/routes/orders.ts
  4. Readsrc/services/billing.ts
  5. Readsrc/db/client.ts
  6. Runnpx some-mcp-serverunpinned
  7. Readsrc/middleware/auth.ts
  8. Readsrc/models/invoice.ts
  9. Read… and the rest of the tree
  10. Wrotesrc/routes/invoices.tsnot checked
12router.get('/api/invoices/:id', async (req, res) => {
13  const rows = await db.query("SELECT * FROM invoices WHERE id = " + req.params.id);
14  res.json(rows[0]);
15});
  • 01Reading the whole codebase costs tokensAn agent looking for bugs reads the codebase into its context, and reads it again on the next run.
  • 02New code ships before anyone reviews itAgents write more code than anyone can read. An injection in a new route looks like any other line.
  • 03Agent tools can be attacked tooIts MCP servers, its command-line flags and the packages it installs all run with your access.

02Why now

Recent attacks on AI coding agents and the code they write

Invented package names, generated apps with open databases, poisoned MCP servers and agent CLIs run with their permission prompts switched off. Pick an event to see the root cause and what Vulkro flags.

Every attack, with sources

What happened

Researchers disclosed SalesBleed: hidden instructions submitted through a public Web-to-Lead form could make an Agentforce agent query account data and send it out through a DNS technique that bypassed the Trusted URLs redaction. Salesforce deployed a fix for the redaction bypass on 18 August 2026, before public disclosure on 24 September.

Root cause An agent that reads free text anyone can submit, with read access to more records than the task needs and an output path that can carry data out in a URL.

What Vulkro flags

Vulkro for Salesforce flags prompt templates that bind a publicly writable field such as a Web-to-Lead description, prompt templates that emit untrusted URLs, and the complete chain when an exit channel exists.

  • sf-forcedleak-writable-field-in-prompt
  • sf-forcedleak-untrusted-url-in-prompt
  • sf-forcedleak-exfil-chain

03The solution

How Vulkro works inside your AI coding agent

Your agent gets the same deterministic answer every run, with the evidence behind it and, where a known fix applies, a patch that has already been scanned again. Step through each part.

Your agent gets findings without reading every file.

Your agent calls Vulkro over MCP and gets the findings, each with its path, instead of reading every file to look for bugs. The budget goes to the feature.

  • 16 tools for code, 10 of them Free, and 27 for Salesforce and Vulkro Cloud.
  • A whole project, one file, or only the lines the agent changed.
  • GitHub Copilot Chat calls it through the VS Code extension.
Free · change-scoped checks are ProRead the reference

scan_project({ path })

Finding
js-taint-sql-001
Severity
Critical · proven
Where
src/services/billing.ts:44
Path
3 hops from GET /api/invoices/:id

Returned instead of the files. The model reads none of them.

04Proof

98% fewer tokens to find the same issues.

Measured against an agent reading the codebase itself. The tokens saved on searching can go to building the feature.

How the saving works
Agent reads the codebase120 files into context

File after file goes into the model, and the next run reads them again.

Model tokensBaseline
Agent asks Vulkro1 call · 3 findings back

Vulkro reads the files without a model. The agent gets the findings, each with its path.

Model tokens98% fewer

Reading costs more as the codebase grows. Asking Vulkro is one call.

fewer tokens than an agent reading the codebase itself to find the same issues.Internal measurement, agentic development and security review, vulkro 0.28.0, 2026-09-19. Detection itself calls no model.

What your agent gets back

How we measure
  1. fewer tokensthan an agent reading the codebase itself to find the same issues (vulkro 0.28.0)
  2. planted vulnerabilities foundin 9 blind test apps, 48 missed (vulkro 0.30.0)
  3. model tokensto detect, to prove, or to write and verify a deterministic fix
  4. of what grep-and-read loadsin development: the code graph answers the same question about a symbol (Pro, vulkro 0.27.0)

05How it fits

Works with your AI coding agent and the local console

Register the MCP server, add the skill, turn on the guard. Scan the same project in the local console and you see the same findings, with their proof and fixes, in your browser and on this machine.

The MCP servers for code and Salesforce, the skill that teaches Claude when to ask, and the guard on every write.

terminal
# MCP servers
claude mcp add vulkro -- vulkro mcp serve
claude mcp add vulkro-sf -- vulkro-sf mcp serve
# the skill
curl -fsSL https://dist.vulkro.com/skill-install.sh | bash -s -- --agent claude-code
# the guard, on every file the agent writes
vulkro guard install --agent claude-code
Setup guide

Every tool your agent can call

16 tools for code and 27 for Salesforce and Vulkro Cloud. A Pro tool called on Free returns a clear error, and the server keeps running.

MCP reference

vulkro mcp serve10 Free · 6 Pro

scan_project({path, format?})

Scans a project and returns every finding, with a scan_id the other tools reuse without scanning again.

Plan
Free
Where it runs
On this machine. Reads your code, never writes to it.
Model calls
None. Deterministic: the same input gives the same answer.

Free, with no account. Reference

Connect your AI coding agent to Vulkro.