Ross ROSS = Recommend OSS · open-source software intelligence for agents

Kritt-ai/open-kritt

Open-source, self-hosted AI vulnerability research tool that orchestrates agents to find and validate security issues in code. observed · 2026-08-28

github.com/Kritt-ai/open-kritt · homepage · JavaScript · AGPL-3.0 (copyleft) observed · 2026-08-28

Health v2 · maintenance only

79/100

  • Activity 99
  • Release rhythm 98
  • Longevity 3

Flags: young

How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: 6.0
  • age_days: 44
  • days_rel: 17
  • days_push: 9
  • n_releases_24m: 5

Full methodology

Adoption not part of the score

2011 stars · 341 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

open·kritt is an open-source, self-hosted AI vulnerability research platform that decomposes a codebase into focused security tasks, runs AI agents (Codex or Claude Code) in parallel, and combines results into de-duplicated, ranked findings. It includes a workflow builder, per-finding verification post-scripts, PoC generation, and ZIP export of scan results.

Use cases

  • find vulnerabilities in a codebase with ai agents
  • automate bug bounty research on smart contracts or web apps
  • audit my repository for security issues before release
  • build reusable security research workflows with llm prompts
  • generate proofs of concept for discovered vulnerabilities
  • self-host an ai-powered vulnerability scanner
  • triage and de-duplicate security findings with custom severity rules

When to choose

  • you are a security researcher or bug bounty hunter wanting AI-assisted code review with full control over prompts, models, and data
  • you want self-hosted infrastructure so code never leaves your environment
  • you need structured, de-duplicated, ranked findings rather than raw LLM output
  • you want to validate findings with automated post-scripts and PoC generation

When to avoid

  • you need a fully automated, hands-off scanner with zero configuration
  • you lack access to paid LLM providers (OpenAI, Anthropic, OpenRouter, xAI) or Codex/Claude Code
  • you need a compliance-oriented SAST tool with established CVE databases rather than AI-driven research
  • your codebase is very large and you cannot afford extensive LLM token usage

Facets

application · maturity active

security vulnerability-scanning agent-framework llm-inference workflow-automation developer-tools security artificial-intelligence developer-tools penetration-testing self-hosted cli bug-bounty code-security ai-security-research vulnerability-research source-code-analysis security-automation agpl ai-agents web-server nodejs docker

4 sources

Member repositories

RepositoryRoleHealth v2
Kritt-ai/open-krittmain79

For agents

markdown · JSON · MCP: product_card(name="Kritt-ai/open-kritt")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem