agentsastLast reviewed 2026-09-13

Agentic scanning

Direct answerAn LLM that plans, reads files, runs tools and tests, and iterates over a codebase, instead of answering one prompt over pasted code.

In more detail

Every serious tool on this index is agentic. The differences are in the harness: which tools the agent can run, whether a second wave of agents validates candidates, whether execution provides ground truth, and how much domain knowledge is encoded as skills.

Tools that address it

zkao, Claude Security, Codex Security (formerly Aardvark).

False positive rate, Precision vs recall, LLM plus fuzzing, LLM plus symbolic execution or formal verification, Hallucinated vulnerabilities, Triage burden, Benchmark contamination, Human-in-the-loop, AI-assisted audit vs AI audit, Prompt injection in auditing pipelines, Responsible disclosure of AI-found bugs, Continuous scanning and run-count coverage, Proof-of-concept harness, Threat model file, Severity calibration

Getting help

Firms on this index that handle this in practice: zkSecurity, Trail of Bits, Zellic, Nethermind Security.