Skip to main content

AgenticVulHunter

AgenticVulHunter is a four-stage agentic secure code review tool. It reviews the current Git change and returns comments that pass the Stage 4 validation threshold.

Pipeline

Git diff
   ↓
Stage 1: Candidate localisation
   ↓
Stage 2: Context enrichment
   ↓
Stage 3: CWE hypothesis generation
   ↓
Stage 4: Vulnerability validation
   ↓
Review comments above the threshold

The pipeline runs directly on the repository. It does not use annotated SCRBench data at runtime.

Install

From this folder:

pipx install . --force

Check the installed version:

agenticvulhunter --version

LLM setup

Only the endpoint and API key are public setup values. The model and research settings stay inside AgenticVulHunter.

Option 1: avh_setup.toml

Create avh_setup.toml in the repository where the review is run:

[llm]
endpoint = "http://localhost:11434/v1"
api_key = ""

For an API endpoint that requires a key:

[llm]
endpoint = "https://example.com/v1"
api_key = "your-key"

Option 2: exports

export AVH_ENDPOINT="http://localhost:11434/v1"
export AVH_API_KEY="your-key"

Exports take priority over avh_setup.toml when both are present.

Do not commit a real API key to Git.

Run a review

Use the default threshold of 0.6:

agenticvulhunter review

Use another threshold:

agenticvulhunter review 0.7

The terminal shows the AVH banner and the status of all four stages while the review is running.

Threshold

The threshold is applied to the final Stage 4 validation score. It is not a separate pipeline stage.

agenticvulhunter review       -> 0.6
agenticvulhunter review 0.7   -> 0.7
agenticvulhunter review 0.9   -> 0.9

JSON output

agenticvulhunter review --json

Release files for agenticvulhunter 1.0.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for agenticvulhunter 1.0.0
File Size Uploaded
agenticvulhunter-1.0.0.tar.gz 68.5 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for agenticvulhunter 1.0.0
File Interpreter ABI Platform
agenticvulhunter-1.0.0-py3-none-any.whl Python 3 none any Details

Total release size: 153.3 kB

Release files / agenticvulhunter-1.0.0.tar.gz

Download URL agenticvulhunter-1.0.0.tar.gz
Size 68.5 kB
Tags Source
SHA-256 checksum
How to use checksums
4b830f14997c6c0b11553d7120f4a514e99b8cdab452f74243e308df13b56b01
BLAKE2b-256 checksum
How to use checksums
4aa374a6830072abf25cca0ea18eb8e0bfc2fd4cc40d6ecba524c50751a22f29
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.12.7

Release files / agenticvulhunter-1.0.0-py3-none-any.whl

Download URL agenticvulhunter-1.0.0-py3-none-any.whl
Size 84.8 kB
Tags Python 3
SHA-256 checksum
How to use checksums
3969870a6e173a17fbc3b7a012d563d71ab043d4c6c457187ae0623053a8aaa3
BLAKE2b-256 checksum
How to use checksums
cbcfc20997b979449344abb2861ea13b8c87b86661edc5066b1be5bea4d9b322
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.12.7

Release history Release notifications | RSS feed

1.0.4

2 release files

1.0.3

2 release files

1.0.2

2 release files

1.0.1

2 release files

This release

1.0.0 This release

2 release files

0.7.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page