Definition

AppSec workflow where specialized AI agents collaborate to map architecture, build threat models, hunt vulnerabilities, and independently verify findings — approximating a security research team rather than a single-pass linter.

Key Points

  • Complements deterministic sast / dependency scanners; targets logic bugs, auth bypass, injection with deep context
  • claude-security-plugin is a session-local implementation; Capital One vulnhunter and cisco-antares are related AI AppSec threads
  • Human-in-the-loop patching remains the trust boundary for most 2026 products

Sources