TLDR overview
- SonarQube Hunter Agent is now generally available on SonarQube Cloud, closing the logic-flaws blind spot SAST cannot detect.
- As an AI security agent, it reasons through code like a security researcher to find broken access control, business logic, and authentication flaws.
- Every finding is independently validated for exploitability before it surfaces, pushing average precision to 80–90%.
- Findings show up as SonarQube issues in your existing workflow—no new portal, dashboard, or install.
