SonarQube Hunter Agent is now GA: Catch broken access control and business logic flaws
TLDR overview
- SonarQube Hunter Agent is now generally available on SonarQube Cloud, closing the logic-flaws blind spot SAST cannot detect.
- As an AI security agent, it reasons through code like a security researcher to find broken access control, business logic, and authentication flaws.
- Every finding is independently validated for exploitability before it surfaces, pushing average precision to 80–90%.
- Findings show up as SonarQube issues in your existing workflow—no new portal, dashboard, or install.
How it works
Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content — general knowledge won't be enough. Score 70+ to count toward your certificate.
Questions are cached — you'll always get the same 5 for this article.