Skip to main content

Use case · Teams building with AI coding agents

Security scanning for AI coding agents, through an MCP server, a skill and a guard hook.

An agent asked to check its own code for vulnerabilities reads file after file and guesses. With Vulkro it asks a deterministic engine and gets back the finding, the path that proves it and the fix.

Vulkro Core · Vulkro for Salesforce · VS Code extension

Typical AI workflow

  1. Huge codebaseevery file is a candidate
  2. Massive contextfiles pulled in to be read
  3. Massive token usagereasoning over all of it
  4. Expensive analysisand a different answer next run
Model tokensBaseline

Vulkro

  1. Codeand the org metadata
  2. Targeted analysisdeterministic, no model
  3. Relevant contextthe path, the rule, the lines
  4. Actionable findingwhat to fix, and where
Model tokens98% fewer

98% fewer tokens in agentic development and security review, measured against an AI agent reading the codebase itself to find the same issues (internal measurement, vulkro 0.28.0, September 2026). Detection itself uses no model at all.

01The problem

AI coding agents review code by reading all of it

Security review by an agent is usually the agent reading the repository into its context and reasoning about what it sees.

  • Expensive

    Every review pays for the codebase in tokens again, and a larger repository costs more each time.

  • Not repeatable

    Ask twice and you can get two different answers. A security check needs the same answer every time.

  • The agent checks its own work

    An agent that wrote the vulnerable line is often the one deciding whether it is safe.

03The workflow

Steps from first scan to fix

  1. 01

    Connect the agent

    Add vulkro mcp serve (or vulkro-sf mcp serve) to your agent, and install the skill.

    Vulkro Core
  2. 02

    Turn on the guard

    Every file the agent writes is scanned in the write loop. A High or Critical finding sends it back to regenerate.

    Vulkro Core
  3. 03

    Ask the engine for findings

    The agent asks for findings and gets each one with its file, line and data-flow proof, not the whole repository.

    Vulkro Core
  4. 04

    Fix and verify

    The agent applies the suggested fix and re-scans to confirm the finding is gone and nothing new appeared.

    Vulkro Core
  5. 05

    Do the same for Salesforce

    The same loop for Apex and metadata, and for the issue list in your Vulkro Cloud workspace.

    Vulkro for Salesforce

04What you get

What you get

Fewer tokens
98% fewer tokens in agentic development and security review, measured against an AI agent reading the codebase itself to find the same issues (internal measurement, vulkro 0.28.0, September 2026).
Deterministic
The same code gives the same findings, every run.
Proof
Each finding carries its disposition and the data-flow hops behind it.
Checks every write
The guard checks every write, with no network call and no model call.
Local
Scans run on your machine. Your code is not sent to Vulkro.

Questions

Common questions

Where does the token figure come from?
98% fewer tokens in agentic development and security review, measured against an AI agent reading the codebase itself to find the same issues (internal measurement, vulkro 0.28.0, September 2026). It is about the whole agentic loop. Detection itself spends no model tokens at all.
Which agents work with it?
Any MCP client, such as Claude Code, Cursor and Windsurf, and the skill also installs for Codex. The guard hook supports Claude Code, Cursor and Windsurf. In VS Code, the editor’s own agent can call the extension’s tools.
Is AI deciding what is a vulnerability?
No. The engine decides, deterministically. AI coding agents call it, and optional AI help elsewhere in Vulkro assists with explanations and fixes but never changes a scan result.

Connect Vulkro to your AI coding agent.