AI coding agentsMCP server · skill · write-time guard
Your agent finds, proves and fixes vulnerabilities. Without reading the codebase.
Vulkro hands your AI coding agent the finding, the attack path behind it and, where a known fix applies, a patch checked by a second scan. 98% fewer tokens than an agent reading the codebase itself to find the same issues. Offline, with no AI in detection.
- Claude Code
- Cursor
- Codex
- GitHub Copilot
- Windsurf
- Any MCP client
- YouAdd an endpoint that returns an invoice by id.
- AgentAdded GET /api/invoices/:id. Asking Vulkro before I go on.
- Tool callscan_file src/routes/invoices.ts
- Vulkrojs-taint-sql-001 · Critical · proven
The id from the URL reaches a SQL query built by string concatenation. - Tool callprove js-taint-sql-001:7f3a…
- Vulkro
- source req.params.id routes/invoices.ts:12
- hop getInvoice(id) services/billing.ts:40
- sink db.query("… WHERE id = " + id) services/billing.ts:44
- Tool callsuggest_fixes scan_id
- VulkroRemedy: the driver's bound-parameter form. Patch applied to a copy and scanned again: fixed.
- AgentApplied the patch. Checking my own diff before I commit.
- Tool callverify_fix diff
- Vulkrofixed · the finding is gone and nothing new at Medium or above appeared in the changed lines.
- Tool
- verify_fix
- Plan
- Free
- Model tokens Vulkro spent
- 0
01The problem
AI coding agents ship code before anyone checks it
An agent that hunts for vulnerabilities reads your code into its context and guesses. An agent that writes code can ship it before anyone reviews it. Point at a problem to see it in the log.
- Readsrc/app.ts
- Readsrc/routes/index.ts
- Readsrc/routes/orders.ts
- Readsrc/services/billing.ts
- Readsrc/db/client.ts
- Runnpx some-mcp-serverunpinned
- Readsrc/middleware/auth.ts
- Readsrc/models/invoice.ts
- Read… and the rest of the tree
- Wrotesrc/routes/invoices.tsnot checked
12router.get('/api/invoices/:id', async (req, res) => {
13 const rows = await db.query("SELECT * FROM invoices WHERE id = " + req.params.id);
14 res.json(rows[0]);
15});- 01Reading the whole codebase costs tokensAn agent looking for bugs reads the codebase into its context, and reads it again on the next run.
- 02New code ships before anyone reviews itAgents write more code than anyone can read. An injection in a new route looks like any other line.
- 03Agent tools can be attacked tooIts MCP servers, its command-line flags and the packages it installs all run with your access.
02Why now
Recent attacks on AI coding agents and the code they write
Invented package names, generated apps with open databases, poisoned MCP servers and agent CLIs run with their permission prompts switched off. Pick an event to see the root cause and what Vulkro flags.
Every attack, with sourcesWhat happened
Researchers disclosed SalesBleed: hidden instructions submitted through a public Web-to-Lead form could make an Agentforce agent query account data and send it out through a DNS technique that bypassed the Trusted URLs redaction. Salesforce deployed a fix for the redaction bypass on 18 August 2026, before public disclosure on 24 September.
Root cause An agent that reads free text anyone can submit, with read access to more records than the task needs and an output path that can carry data out in a URL.
What Vulkro flags
Vulkro for Salesforce flags prompt templates that bind a publicly writable field such as a Web-to-Lead description, prompt templates that emit untrusted URLs, and the complete chain when an exit channel exists.
- sf-forcedleak-writable-field-in-prompt
- sf-forcedleak-untrusted-url-in-prompt
- sf-forcedleak-exfil-chain
Source: Infosecurity Magazine: vulnerabilities in Salesforce Agentforce expose wider AI agent risk
03The solution
How Vulkro works inside your AI coding agent
Your agent gets the same deterministic answer every run, with the evidence behind it and, where a known fix applies, a patch that has already been scanned again. Step through each part.
Your agent gets findings without reading every file.
Your agent calls Vulkro over MCP and gets the findings, each with its path, instead of reading every file to look for bugs. The budget goes to the feature.
- 16 tools for code, 10 of them Free, and 27 for Salesforce and Vulkro Cloud.
- A whole project, one file, or only the lines the agent changed.
- GitHub Copilot Chat calls it through the VS Code extension.
scan_project({ path })
- Finding
- js-taint-sql-001
- Severity
- Critical · proven
- Where
- src/services/billing.ts:44
- Path
- 3 hops from GET /api/invoices/:id
Returned instead of the files. The model reads none of them.
04Proof
98% fewer tokens to find the same issues.
Measured against an agent reading the codebase itself. The tokens saved on searching can go to building the feature.
How the saving worksFile after file goes into the model, and the next run reads them again.
Vulkro reads the files without a model. The agent gets the findings, each with its path.
Reading costs more as the codebase grows. Asking Vulkro is one call.
fewer tokens than an agent reading the codebase itself to find the same issues.Internal measurement, agentic development and security review, vulkro 0.28.0, 2026-09-19. Detection itself calls no model.
What your agent gets back
How we measure- fewer tokensthan an agent reading the codebase itself to find the same issues (vulkro 0.28.0)
- planted vulnerabilities foundin 9 blind test apps, 48 missed (vulkro 0.30.0)
- model tokensto detect, to prove, or to write and verify a deterministic fix
- of what grep-and-read loadsin development: the code graph answers the same question about a symbol (Pro, vulkro 0.27.0)
05How it fits
Works with your AI coding agent and the local console
Register the MCP server, add the skill, turn on the guard. Scan the same project in the local console and you see the same findings, with their proof and fixes, in your browser and on this machine.
The MCP servers for code and Salesforce, the skill that teaches Claude when to ask, and the guard on every write.
# MCP servers claude mcp add vulkro -- vulkro mcp serve claude mcp add vulkro-sf -- vulkro-sf mcp serve # the skill curl -fsSL https://dist.vulkro.com/skill-install.sh | bash -s -- --agent claude-code # the guard, on every file the agent writes vulkro guard install --agent claude-code
Every tool your agent can call
16 tools for code and 27 for Salesforce and Vulkro Cloud. A Pro tool called on Free returns a clear error, and the server keeps running.
vulkro mcp serve10 Free · 6 Pro
scan_project({path, format?})
Scans a project and returns every finding, with a scan_id the other tools reuse without scanning again.
- Plan
- Free
- Where it runs
- On this machine. Reads your code, never writes to it.
- Model calls
- None. Deterministic: the same input gives the same answer.
Free, with no account. Reference