Use case · Teams building with AI coding agents
Security scanning for AI coding agents, through an MCP server, a skill and a guard hook.
An agent asked to check its own code for vulnerabilities reads file after file and guesses. With Vulkro it asks a deterministic engine and gets back the finding, the path that proves it and the fix.
Vulkro Core · Vulkro for Salesforce · VS Code extension
Typical AI workflow
- Huge codebaseevery file is a candidate
- Massive contextfiles pulled in to be read
- Massive token usagereasoning over all of it
- Expensive analysisand a different answer next run
Vulkro
- Codeand the org metadata
- Targeted analysisdeterministic, no model
- Relevant contextthe path, the rule, the lines
- Actionable findingwhat to fix, and where
98% fewer tokens in agentic development and security review, measured against an AI agent reading the codebase itself to find the same issues (internal measurement, vulkro 0.28.0, September 2026). Detection itself uses no model at all.
01The problem
AI coding agents review code by reading all of it
Security review by an agent is usually the agent reading the repository into its context and reasoning about what it sees.
Expensive
Every review pays for the codebase in tokens again, and a larger repository costs more each time.
Not repeatable
Ask twice and you can get two different answers. A security check needs the same answer every time.
The agent checks its own work
An agent that wrote the vulnerable line is often the one deciding whether it is safe.
02How Vulkro handles it
What each part of Vulkro does
- An MCP server: scan a project or a file, explain a rule, fetch the proof for one finding, and suggest and verify fixes
- A guard hook for Claude Code, Cursor and Windsurf that scans every file the agent writes and blocks on High and Critical
- A skill that teaches Claude Code, Cursor and Codex how to run the scan and read the result
- Zero model tokens for detection: the scan engine calls no model
- An MCP server for Apex, LWC, Aura, Visualforce, Flows and metadata
- With Vulkro Cloud, tools to list what to fix, triage, fix and verify against your workspace
- Fixes as reviewable patches, Setup links and sf scripts, never deployed
- Scan-file and explain-finding tools the editor’s agent can call, including GitHub Copilot Chat in agent mode
- The engine’s MCP server registered with the editor, launched with network access off
03The workflow
Steps from first scan to fix
- 01Vulkro Core
Connect the agent
Add vulkro mcp serve (or vulkro-sf mcp serve) to your agent, and install the skill.
- 02Vulkro Core
Turn on the guard
Every file the agent writes is scanned in the write loop. A High or Critical finding sends it back to regenerate.
- 03Vulkro Core
Ask the engine for findings
The agent asks for findings and gets each one with its file, line and data-flow proof, not the whole repository.
- 04Vulkro Core
Fix and verify
The agent applies the suggested fix and re-scans to confirm the finding is gone and nothing new appeared.
- 05Vulkro for Salesforce
Do the same for Salesforce
The same loop for Apex and metadata, and for the issue list in your Vulkro Cloud workspace.
04What you get
What you get
- Fewer tokens
- 98% fewer tokens in agentic development and security review, measured against an AI agent reading the codebase itself to find the same issues (internal measurement, vulkro 0.28.0, September 2026).
- Deterministic
- The same code gives the same findings, every run.
- Proof
- Each finding carries its disposition and the data-flow hops behind it.
- Checks every write
- The guard checks every write, with no network call and no model call.
- Local
- Scans run on your machine. Your code is not sent to Vulkro.
Questions
Common questions
- Where does the token figure come from?
- 98% fewer tokens in agentic development and security review, measured against an AI agent reading the codebase itself to find the same issues (internal measurement, vulkro 0.28.0, September 2026). It is about the whole agentic loop. Detection itself spends no model tokens at all.
- Which agents work with it?
- Any MCP client, such as Claude Code, Cursor and Windsurf, and the skill also installs for Codex. The guard hook supports Claude Code, Cursor and Windsurf. In VS Code, the editor’s own agent can call the extension’s tools.
- Is AI deciding what is a vulnerability?
- No. The engine decides, deterministically. AI coding agents call it, and optional AI help elsewhere in Vulkro assists with explanations and fixes but never changes a scan result.