Skip to main content

AgenticVulHunter

AgenticVulHunter is a four-stage agentic secure code review tool. It reviews the current Git change and returns comments that pass the Stage 4 validation threshold.

Pipeline

Git diff
   ↓
Stage 1: Candidate localisation
   ↓
Stage 2: Context enrichment
   ↓
Stage 3: CWE hypothesis generation
   ↓
Stage 4: Vulnerability validation
   ↓
Review comments above the threshold

The pipeline runs directly on the repository. It does not use annotated SCRBench data at runtime.

Install

From this folder:

pipx install . --force

Check the installed version:

agenticvulhunter --version

LLM setup

Only the endpoint and API key are public setup values. The model and research settings stay inside AgenticVulHunter.

Option 1: avh_setup.toml

Create avh_setup.toml in the repository where the review is run:

[llm]
endpoint = "http://localhost:11434/v1"
api_key = ""

For an API endpoint that requires a key:

[llm]
endpoint = "https://example.com/v1"
api_key = "your-key"

Option 2: exports

export AVH_ENDPOINT="http://localhost:11434/v1"
export AVH_API_KEY="your-key"

Exports take priority over avh_setup.toml when both are present.

Do not commit a real API key to Git.

Run a review

Use the default threshold of 0.6:

agenticvulhunter review

Use another threshold:

agenticvulhunter review 0.7

The terminal shows the AVH banner and the status of all four stages while the review is running.

Threshold

The threshold is applied to the final Stage 4 validation score. It is not a separate pipeline stage.

agenticvulhunter review       -> 0.6
agenticvulhunter review 0.7   -> 0.7
agenticvulhunter review 0.9   -> 0.9

JSON output

agenticvulhunter review --json

Remove old build

rm -rf dist

Build package

python -m build

Check package

python -m twine check dist/*

Upload to PyPI

python -m twine upload dist/*

Remove old installation

pipx uninstall agenticvulhunter

Clear cache

uv cache clean

Install latest version

pipx install agenticvulhunter

Check version

agenticvulhunter --version

Release files for agenticvulhunter 1.0.2

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for agenticvulhunter 1.0.2
File Size Uploaded
agenticvulhunter-1.0.2.tar.gz 69.0 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for agenticvulhunter 1.0.2
File Interpreter ABI Platform
agenticvulhunter-1.0.2-py3-none-any.whl Python 3 none any Details

Total release size: 154.2 kB

Release files / agenticvulhunter-1.0.2.tar.gz

Download URL agenticvulhunter-1.0.2.tar.gz
Size 69.0 kB
Tags Source
SHA-256 checksum
How to use checksums
307bc6b0fd5a5f99a69d33d9b30ca973c15edd33750a3d9a9c00b28f1cc26f64
BLAKE2b-256 checksum
How to use checksums
8486c2241d5804d59669580992f87dc36e8f59b4019ef9e0d27ae32e6aabd716
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.12.7

Release files / agenticvulhunter-1.0.2-py3-none-any.whl

Download URL agenticvulhunter-1.0.2-py3-none-any.whl
Size 85.3 kB
Tags Python 3
SHA-256 checksum
How to use checksums
541e73fe2689a5ff7a6031eb1aaa82857734840dcc3f8efa06fec4526e1994e6
BLAKE2b-256 checksum
How to use checksums
1d2ebc2a48fd1cdb84532ce51c4d9efae4a075d1ccba041192376763661fd0e3
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.12.7

Release history Release notifications | RSS feed

1.0.4

2 release files

1.0.3

2 release files

This release

1.0.2 This release

2 release files

1.0.1

2 release files

1.0.0

2 release files

0.7.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page