Use case · Application and API teams
Know every endpoint, and which ones an attacker can reach.
Vulkro reads your routes and shows what is open, what needs a login, and where request data ends up. Each finding comes with the path from the route to the risky call.
Vulkro Core · VS Code extension
Anyone can run their own SQL through the order search
- Entry pointsrc/routes/orders.ts:4
router.get('/api/orders', async (req, res) => {Express route · no sign-in needed - Callsrc/routes/orders.ts:5
const rows = await searchOrders(req.query.q)the search term passed straight on - Sinksrc/services/orders.ts:4
pool.query("SELECT * FROM orders WHERE customer_name LIKE '%" + term + "%'")SQL built from the request, no binding
- Who can reach it
- Anyone, no sign-in
- What is at stake
- Every customer's data
- Guards on the path
- None. The value is never bound
- Disposition
- Proven: traced from the request to the query
- Fix
- Bind the value:
pool.query('... LIKE $1', [`%${term}%`])
01The problem
Most APIs have endpoints nobody documented
Most API breaches go through an endpoint the team forgot existed, or one that trusts the caller too much.
Routes nobody listed
Endpoints added in a hurry, debug routes left in, and tools an AI agent can call never make it into the spec.
Login checks with no ownership check
A route that only asks "are you signed in?" hands any user any record whose id they can guess.
Findings without a path
A scanner that flags a query without showing how request data reaches it leaves you to trace it by hand.
02How Vulkro handles it
What each part of Vulkro does
- Every endpoint in the code, with its handler, full path and the guards in front of it, including MCP and agent tools (Free)
- Injection, server-side request forgery and unsafe redirects traced from the route to the call, with each hop (Free)
- Lookups by id with no ownership check flagged for review; they cannot be decided offline, so they are marked not checked and never fail a build (Free)
- Which login level each endpoint requires, an OpenAPI spec inferred from the code, and the endpoints a change added (Pro)
- The finding on the line that causes it, with the path on hover
- The fix on the lightbulb, never applied without you
- The same engine and the same answer as CI
03The workflow
Steps from first scan to fix
- 01Vulkro Core
Map the surface
List every endpoint the code declares, with the guards on each, before any check runs.
- 02Vulkro Core
Scan for what is reachable
Follow request data from each route into queries, commands, files and outbound requests.
- 03Vulkro Core
Read the path
Each finding shows the entry point, every hop and the missing guard, so the fix goes in the right place.
- 04Vulkro Core
Check who can call what
See the login level per endpoint and spot routes that need more than a session.
- 05VS Code extension
Catch it on save
Developers see the same findings in the editor before the pull request.
04What you get
What you get
- Inventory
- Every route the frameworks declare, with its handler and guards, including the ones nobody documented.
- Proof
- Injection reached from a route comes with the trace from request to sink.
- Honest about limits
- Ownership checks Vulkro cannot decide from source are reported as not checked, never as passed.
- Frameworks
- Express, Koa, NestJS, Next.js, FastAPI, Django, Flask, Java web routes, and Go net/http, Gin, Echo and chi.
- Offline
- Your code never leaves the machine. No AI in detection.
Questions
Common questions
- Does it test a running API?
- No. Vulkro reads the source, so it sees routes that are hard to reach from outside, and it never sends traffic to your service.
- Can it prove a broken object-level authorization bug?
- It flags lookups by id with no ownership check, and says plainly that it cannot decide them offline. They are reported for review and never fail a build. Injection and similar flows from a route are proven with a data-flow trace.
- What is free?
- The endpoint inventory, every check and the proof behind each finding are free. The login-level matrix, the inferred OpenAPI spec and the endpoint diff between two versions are Pro.