Kritt-ai/open-kritt
Open-source, self-hosted AI vulnerability research tool that orchestrates agents to find and validate security issues in code. observed · 2026-08-28
Health v2 · maintenance only
79/100
- Activity 99
- Release rhythm 98
- Longevity 3
Flags: young
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.
- gap_med: 6.0
- age_days: 44
- days_rel: 17
- days_push: 9
- n_releases_24m: 5
Adoption not part of the score
2011 stars · 341 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded
open·kritt is an open-source, self-hosted AI vulnerability research platform that decomposes a codebase into focused security tasks, runs AI agents (Codex or Claude Code) in parallel, and combines results into de-duplicated, ranked findings. It includes a workflow builder, per-finding verification post-scripts, PoC generation, and ZIP export of scan results.
Use cases
- find vulnerabilities in a codebase with ai agents
- automate bug bounty research on smart contracts or web apps
- audit my repository for security issues before release
- build reusable security research workflows with llm prompts
- generate proofs of concept for discovered vulnerabilities
- self-host an ai-powered vulnerability scanner
- triage and de-duplicate security findings with custom severity rules
When to choose
- you are a security researcher or bug bounty hunter wanting AI-assisted code review with full control over prompts, models, and data
- you want self-hosted infrastructure so code never leaves your environment
- you need structured, de-duplicated, ranked findings rather than raw LLM output
- you want to validate findings with automated post-scripts and PoC generation
When to avoid
- you need a fully automated, hands-off scanner with zero configuration
- you lack access to paid LLM providers (OpenAI, Anthropic, OpenRouter, xAI) or Codex/Claude Code
- you need a compliance-oriented SAST tool with established CVE databases rather than AI-driven research
- your codebase is very large and you cannot afford extensive LLM token usage
Facets
application · maturity active
security vulnerability-scanning agent-framework llm-inference workflow-automation developer-tools security artificial-intelligence developer-tools penetration-testing self-hosted cli bug-bounty code-security ai-security-research vulnerability-research source-code-analysis security-automation agpl ai-agents web-server nodejs docker
4 sources
- readme: https://github.com/Kritt-ai/open-kritt · fetched 2026-08-28 · 7413ea870abd
- homepage: https://kritt.ai/ · fetched 2026-08-29 · e0be2bc5a26b
- site_page: https://docs.kritt.ai · fetched 2026-08-29 · 53c17dcc8238
- site_page: https://kritt.ai/pricing · fetched 2026-08-29 · ad8493ed31c6
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| Kritt-ai/open-kritt | main | 79 |
For agents
markdown · JSON · MCP: product_card(name="Kritt-ai/open-kritt")
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem