Attacker-first agents turn vuln triage into repair candidates

A security agent can start from attacker-first exploit-path search and prepare a production-code fix instead of following an abstract checklist.

Capability delta

Before: Security review identifies a vulnerability and hands remediation back to humans. Enabling change: VulnHunter-style agent reasons from attacker behavior to vulnerable code and repair candidates. After: The workflow can move from exploit-oriented analysis to proposed code change faster. Human consequence: Security teams get a more actionable review artifact, but still need human approval before code changes.

Source ledger

Publishable sources attached to this record.

1 public source
#SourceRolePublic status
1medium.comsourceprimary receiptsource_urls

This delta is useful as a project seed: do not publish an autonomous fix, but build a read-only or approval-gated workflow that shows the exploit path, affected code, proposed patch, and evidence.

Discovery graph / next reads

Continue through New Runtime

Open the graph
  1. 01related materialManual continue prompting -> goal-scoped agent loopsShift connected to this capability delta.
  2. 02related materialCapital One's VulnHunter Points AI at Real Attack PathsField Note connected to this capability delta.
  3. 03topicAgents - New RuntimeExplore the agents topic hub.
  4. 04topicCode Review - New RuntimeExplore the code review topic hub.
  5. 05related materialAgent-first API makes retries deterministicShares agents.

These links are also published in this page’s JSON twin and as typed edges in DiscoveryGraph v1.

Who read this page?Machine requests, hidden until opened

Loading the privacy-safe route aggregate…

Open the JSON contract