Vulnerability intelligence for AI coding agents
Automated dependency scanning, exploit analysis and fix intelligence — built into your development workflow. Not another scanner. Not another point solution. Vulnerability operations where your code is written.
Make AppSec work where your code is written
Three guardrails watch the moments that matter, and stay silent when your policy is already satisfied. Eighteen skills cover the work that needs your working tree — choosing a dependency, tracing a CVE into this codebase, applying and verifying a fix. Decisions persist as auditable VEX attestations.
Live data from 160 upstream sources
CVE, GHSA, OSV, vendor advisories and many more — aggregated, normalised and enriched with exploit intelligence, malware associations and safe upgrade paths.
- 160 re-served vulnerability sources
- 60+ identifier scheme lookups
- Fix advisories and patch links
- 50 queries / day
- Everything in Community
- Exploit maturity & sightings
- Malware campaigns & indicators
- Safe harbour versioning
- 2,000 queries / day
- Everything in Pro
- 10 API keys included
- 100,000 queries / day / key
- Dedicated support channel
Automatic security scanning, no extra step
Three hooks, one command. The dependency guard checks what an install is about to add and prints nothing when it already meets your policy — measured, none of 33 everyday commands produce output. The change guard catches a credential before it is committed. Session context opens with what the last scan found, and resolves any CVE you name against this repository.
Vulnerability intelligence on demand
Eighteen skills, each one local work. Weigh which package to add before adding it, answer whether a CVE reaches anything here, apply a fix with a rollback path and verify it landed, and produce the SBOM and VEX an auditor asked for.
Lookups over MCP, and five subagents for the long jobs
Lookups are not skills here. The Vulnetix MCP server answers those with 31 tools over live data — one URL, one header, nothing to install — so a question has one answer instead of three. Five subagents handle the multi-step work: bulk triage, upgrade orchestration, PR review, compliance bundling and incident response.
Every decision recorded as auditable evidence
Findings, decisions and scan history persist in the .vulnetix/ directory. A structured YAML memory tracks every vulnerability from discovery to resolution. Package search results, CycloneDX SBOMs and cached PoC source code provide audit-ready artefacts.
Built for the whole stack
150+ ecosystems across 50+ languages, 20+ operating systems and 100+ million packages — one live source of truth.
Questions before you install
How does this differ from running a scanner locally?
Do I need a Vulnetix account?
Which languages and ecosystems are supported?
How does it handle false positives?
Is my source code sent to Vulnetix?
.vulnetix/.Which AI coding agents are supported?
Ready to make AppSec work where your code is written?
Install the plugin, point it at a free Community API key, and your next commit will be scanned with the same vulnerability data the enterprise platform uses.