trailofbits/buttercup
Buttercup finds and patches software vulnerabilities observed · 2026-08-28
Health v2 · maintenance only
56/100
- Activity 99
- Release rhythm 10
- Longevity 42
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.
- gap_med: n/a
- age_days: 597
- days_rel: 384
- days_push: 9
- n_releases_24m: 1
Adoption not part of the score
1683 stars · 183 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded
Buttercup is a Cyber Reasoning System (CRS) developed by Trail of Bits for the DARPA AI Cyber Challenge that automatically finds and patches software vulnerabilities in open-source C and Java repositories. It combines AI/ML-assisted fuzzing built on OSS-Fuzz with a multi-agent LLM-driven patcher to discover, analyze, and repair security bugs.
Use cases
- automatically find vulnerabilities in open-source C or Java projects
- generate patches for discovered security bugs using LLM agents
- run AI-assisted fuzzing campaigns on OSS-Fuzz compatible codebases
- participate in or replicate DARPA AI Cyber Challenge style autonomous vulnerability discovery
- audit code repositories for exploitable memory or logic bugs
When to choose
- you need autonomous end-to-end vulnerability discovery and patching for OSS-Fuzz compatible C or Java projects
- you have Linux x86_64 hardware and budget for third-party LLM API costs
- you want to experiment with multi-agent AI-driven security repair pipelines
When to avoid
- you need a lightweight scanner without heavy LLM API costs or Docker infrastructure
- your target project is not OSS-Fuzz compatible or lacks fuzzing harnesses
- you require Windows or full ARM64 support
Facets
application · maturity active
security vulnerability-scanning machine-learning llm-inference agent-framework testing security developer-tools artificial-intelligence python cyber-reasoning-system fuzzing automated-patching vulnerability-discovery aixcc oss-fuzz llm-agents automation linux macos docker
1 source
- readme: https://github.com/trailofbits/buttercup · fetched 2026-08-28 · d36d33a1826e
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| trailofbits/buttercup | main | 56 |
For agents
markdown · JSON · MCP: product_card(name="trailofbits/buttercup")
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem