Skip to main content

Token efficiency

Security analysis without wasting tokens.

An AI agent that reads your codebase to find vulnerabilities spends its context on files that are not the answer. Vulkro does the analysis without a model and hands the agent the finding, the path and the lines.

MCP server · skill · guard · VS Code extension

Typical AI workflow

  1. Huge codebaseevery file is a candidate
  2. Massive contextfiles pulled in to be read
  3. Massive token usagereasoning over all of it
  4. Expensive analysisand a different answer next run
Model tokensBaseline

Vulkro

  1. Codeand the org metadata
  2. Targeted analysisdeterministic, no model
  3. Relevant contextthe path, the rule, the lines
  4. Actionable findingwhat to fix, and where
Model tokens98% fewer

98% fewer tokens in agentic development and security review, measured against an AI agent reading the codebase itself to find the same issues (internal measurement, vulkro 0.28.0, September 2026). Detection itself uses no model at all.

01The problem

Reading the whole codebase costs tokens

A security review is the worst case for an agent: it cannot know in advance which file matters, so it reads them all.

  • 01

    A model must read code to search it

    A model can only look for a vulnerability by reading. To rule out a missing check anywhere, it has to read everywhere: routes, middleware, queries, helpers.

  • 02

    Models miss details in long context

    The more a model holds, the less reliably it uses any one part of it. A vulnerability is a detail in the middle of a lot of ordinary code.

  • 03

    Each review reads the same files again

    Nothing a model read last week is kept. The next review reads the same files, and may reach a different answer.

Context as a finite resource whose recall falls as it fills: Anthropic, September 2025. Weaker use of information in the middle of long inputs: Liu et al., TACL 2023. Non-deterministic answers from models asked to find vulnerabilities: Ullah et al., IEEE S&P 2024.

02How Vulkro answers

Vulkro runs the analysis and the agent reads the result

A deterministic engine does the search. The model does what it is good at: changing a few lines correctly.

  • Detect

    The analysis runs first, with no model

    The engine maps every entry point, follows the data and records the checks on the way, on your machine. Detection uses zero model tokens.

  • Hand over

    The agent receives only the finding

    The agent receives the rule, the file, the lines and the path that proves it. It reads four lines instead of forty files.

  • Narrow

    Only findings on changed lines

    scan_diff analyses the whole project, then returns only the findings on the lines a change added or modified.

  • Repeat

    Repeat runs give the same answer

    Same code, same findings, with stable identifiers. Ask again and you get the same result, not a new bill and a new list.

03Measured, with its baseline

98% fewer tokens. Zero for detection.

Here is the figure in full, with the baseline it was measured against.

Agentic review
98% fewer tokens in agentic development and security review.
Measured against
An AI agent reading the codebase itself to find the same issues.
In development
The code graph replaces grep-and-read: one answer about a symbol is 1.3 to 1.6% of the source a grep-and-read pass must load to answer the same question about a symbol (vulkro 0.27.0, Pro).
Provenance
Internal measurement, vulkro 0.28.0, September 2026.
Detection
Zero model tokens. The scan engine calls no model; it costs CPU time on your machine.
Repeat runs
The same code gives the same findings, so asking again costs nothing new.

What the figure is not: a claim about every task an agent performs, or an independent benchmark. It compares two ways of reaching the same security findings during agentic work. Our detection accuracy, including the misses, is published separately on the proof page.

04How agents call it

The MCP server, the skill and the guard

Register the MCP server so the agent can ask, install the skill so it asks well, and install the guard so every file it writes is checked whether it asks or not.

Securing AI coding agents
scan_project
Scan the project and return the findings with a scan id. format: summary returns the counts alone.
get_findings
Re-filter a scan by severity without scanning again.
prove
The hop-by-hop path behind one finding. An empty chain means no proven flow, never "safe".
explain
What a rule means and how to fix it.
verify_fix
Apply a proposed fix to a temporary copy, scan again: fixed, not-fixed or regressed.
scan_diff
Only the findings on the lines a change touched. Part of Vulkro Pro.
code_graph
A ranked map of the most important symbols and what depends on them. Part of Vulkro Pro.
terminal
# give Claude Code the scanner over MCP
$ claude mcp add vulkro -- vulkro mcp serve
# install the skill for Claude Code, Cursor and Codex
$ curl -fsSL https://dist.vulkro.com/skill-install.sh | bash
# scan every file the agent writes (no token cost)
$ vulkro guard install --agent claude-code --scope project

The server is read-only and talks over stdio by default. Tool reference: vulkro mcp serve, the skill, vulkro guard.

05Where it works

Available in every Vulkro product

The same engine answers the agent in the terminal, in the editor and in the hosted workspace.

  • Application code

    Vulkro Core

    vulkro mcp serve, the skill and the guard, for JavaScript, TypeScript, Python, Go, Java, PHP, C and C++.

  • Salesforce

    Vulkro for Salesforce

    vulkro-sf mcp serve gives agents the Salesforce scanner: Apex, LWC, Aura, Visualforce, Flows and metadata.

  • Editor

    VS Code extension

    Language-model tools that GitHub Copilot Chat agent mode can call, and the MCP server registered for you, launched with network access off.

  • Hosted

    Vulkro Cloud for Salesforce

    The sf_cloud tools let an assistant list what to fix, plan a fix and verify it. Its verdicts are marked as AI and wait for a person. Available by invitation.

Questions

What teams ask first.

Does Vulkro use a model to find vulnerabilities?
No. The scan engine calls no model, so detection uses zero model tokens. Optional AI features exist for explaining and drafting fixes; they are opt-in, advisory, and never change a finding, its severity, a report or an exit code.
What is the 98% measured against?
98% fewer tokens in agentic development and security review, measured against an AI agent reading the codebase itself to find the same issues (internal measurement, vulkro 0.28.0, September 2026). It covers the agentic loop, not every task an agent does.
Does my code go to a model?
The scan runs on your machine and only its JSON result reaches the agent. What the agent then sends to its own model is up to the agent you run. Set VULKRO_OFFLINE=1 and the scans make no network call.
Can the agent change my code through Vulkro?
No. The MCP server is read-only: no tool writes to your repository. verify_fix checks a proposed diff on a temporary copy and leaves your working tree alone.
Which agents does it work with?
Any MCP client, including Claude Code, Claude Desktop, Cursor, Windsurf, Continue and the VS Code MCP client. The skill installs for Claude Code, Cursor and Codex CLI. The guard hooks into Claude Code and Cursor, with Windsurf on a best-effort basis.
What is free?
Scanning, findings with their proof, explain, verify_fix and the guard. Diff-scoped review (scan_diff) and the code graph (code_graph) are part of Vulkro Pro. See pricing.

Save tokens on security review with Vulkro.