Token efficiency
Security analysis without wasting tokens.
An AI agent that reads your codebase to find vulnerabilities spends its context on files that are not the answer. Vulkro does the analysis without a model and hands the agent the finding, the path and the lines.
MCP server · skill · guard · VS Code extension
Typical AI workflow
- Huge codebaseevery file is a candidate
- Massive contextfiles pulled in to be read
- Massive token usagereasoning over all of it
- Expensive analysisand a different answer next run
Vulkro
- Codeand the org metadata
- Targeted analysisdeterministic, no model
- Relevant contextthe path, the rule, the lines
- Actionable findingwhat to fix, and where
98% fewer tokens in agentic development and security review, measured against an AI agent reading the codebase itself to find the same issues (internal measurement, vulkro 0.28.0, September 2026). Detection itself uses no model at all.
01The problem
Reading the whole codebase costs tokens
A security review is the worst case for an agent: it cannot know in advance which file matters, so it reads them all.
01
A model must read code to search it
A model can only look for a vulnerability by reading. To rule out a missing check anywhere, it has to read everywhere: routes, middleware, queries, helpers.
02
Models miss details in long context
The more a model holds, the less reliably it uses any one part of it. A vulnerability is a detail in the middle of a lot of ordinary code.
03
Each review reads the same files again
Nothing a model read last week is kept. The next review reads the same files, and may reach a different answer.
Context as a finite resource whose recall falls as it fills: Anthropic, September 2025. Weaker use of information in the middle of long inputs: Liu et al., TACL 2023. Non-deterministic answers from models asked to find vulnerabilities: Ullah et al., IEEE S&P 2024.
02How Vulkro answers
Vulkro runs the analysis and the agent reads the result
A deterministic engine does the search. The model does what it is good at: changing a few lines correctly.
Detect
The analysis runs first, with no model
The engine maps every entry point, follows the data and records the checks on the way, on your machine. Detection uses zero model tokens.
Hand over
The agent receives only the finding
The agent receives the rule, the file, the lines and the path that proves it. It reads four lines instead of forty files.
Narrow
Only findings on changed lines
scan_diff analyses the whole project, then returns only the findings on the lines a change added or modified.
Repeat
Repeat runs give the same answer
Same code, same findings, with stable identifiers. Ask again and you get the same result, not a new bill and a new list.
03Measured, with its baseline
98% fewer tokens. Zero for detection.
Here is the figure in full, with the baseline it was measured against.
- Agentic review
- 98% fewer tokens in agentic development and security review.
- Measured against
- An AI agent reading the codebase itself to find the same issues.
- In development
- The code graph replaces grep-and-read: one answer about a symbol is 1.3 to 1.6% of the source a grep-and-read pass must load to answer the same question about a symbol (vulkro 0.27.0, Pro).
- Provenance
- Internal measurement, vulkro 0.28.0, September 2026.
- Detection
- Zero model tokens. The scan engine calls no model; it costs CPU time on your machine.
- Repeat runs
- The same code gives the same findings, so asking again costs nothing new.
What the figure is not: a claim about every task an agent performs, or an independent benchmark. It compares two ways of reaching the same security findings during agentic work. Our detection accuracy, including the misses, is published separately on the proof page.
04How agents call it
The MCP server, the skill and the guard
Register the MCP server so the agent can ask, install the skill so it asks well, and install the guard so every file it writes is checked whether it asks or not.
Securing AI coding agentsscan_project- Scan the project and return the findings with a scan id. format: summary returns the counts alone.
get_findings- Re-filter a scan by severity without scanning again.
prove- The hop-by-hop path behind one finding. An empty chain means no proven flow, never "safe".
explain- What a rule means and how to fix it.
verify_fix- Apply a proposed fix to a temporary copy, scan again: fixed, not-fixed or regressed.
scan_diff- Only the findings on the lines a change touched. Part of Vulkro Pro.
code_graph- A ranked map of the most important symbols and what depends on them. Part of Vulkro Pro.
# give Claude Code the scanner over MCP $ claude mcp add vulkro -- vulkro mcp serve # install the skill for Claude Code, Cursor and Codex $ curl -fsSL https://dist.vulkro.com/skill-install.sh | bash # scan every file the agent writes (no token cost) $ vulkro guard install --agent claude-code --scope project
The server is read-only and talks over stdio by default. Tool reference: vulkro mcp serve, the skill, vulkro guard.
05Where it works
Available in every Vulkro product
The same engine answers the agent in the terminal, in the editor and in the hosted workspace.
Application code
vulkro mcp serve, the skill and the guard, for JavaScript, TypeScript, Python, Go, Java, PHP, C and C++.
Salesforce
vulkro-sf mcp serve gives agents the Salesforce scanner: Apex, LWC, Aura, Visualforce, Flows and metadata.
Editor
Language-model tools that GitHub Copilot Chat agent mode can call, and the MCP server registered for you, launched with network access off.
Hosted
The sf_cloud tools let an assistant list what to fix, plan a fix and verify it. Its verdicts are marked as AI and wait for a person. Available by invitation.
Questions
What teams ask first.
- Does Vulkro use a model to find vulnerabilities?
- No. The scan engine calls no model, so detection uses zero model tokens. Optional AI features exist for explaining and drafting fixes; they are opt-in, advisory, and never change a finding, its severity, a report or an exit code.
- What is the 98% measured against?
- 98% fewer tokens in agentic development and security review, measured against an AI agent reading the codebase itself to find the same issues (internal measurement, vulkro 0.28.0, September 2026). It covers the agentic loop, not every task an agent does.
- Does my code go to a model?
- The scan runs on your machine and only its JSON result reaches the agent. What the agent then sends to its own model is up to the agent you run. Set VULKRO_OFFLINE=1 and the scans make no network call.
- Can the agent change my code through Vulkro?
- No. The MCP server is read-only: no tool writes to your repository. verify_fix checks a proposed diff on a temporary copy and leaves your working tree alone.
- Which agents does it work with?
- Any MCP client, including Claude Code, Claude Desktop, Cursor, Windsurf, Continue and the VS Code MCP client. The skill installs for Claude Code, Cursor and Codex CLI. The guard hooks into Claude Code and Cursor, with Windsurf on a best-effort basis.
- What is free?
- Scanning, findings with their proof, explain, verify_fix and the guard. Diff-scoped review (scan_diff) and the code graph (code_graph) are part of Vulkro Pro. See pricing.