跳到正文

Kritt-ai

open-kritt

Orchestrate AI agents to find real vulnerabilities in code.

README 已保存到本站,可直接阅读

Documentation snapshot

README 快照

本页保存的是公开项目资料快照,阅读过程不需要连接 GitHub。

open·kritt

Orchestrate AI agents to find real vulnerabilities in code.

An open-source, self-hosted security research platform that turns focused AI analysis into de-duplicated, ranked findings with configurable validation and enrichment.

图片:License: AGPL-3.0 图片:Release

Website · Documentation · Getting started · Contributing · Research paper · Discord community · Twitter

图片:open·kritt workflow builder

What is open·kritt?

Pointing a model at an entire repository and asking it to find vulnerabilities rarely works well. open·kritt takes a focused approach: break the research into small, well-defined tasks, run them across AI agents in parallel, and combine their output into findings you can validate and prioritize.

It is built for security researchers and security-minded developers who want control over their prompts, workflows, model providers, and infrastructure.

What it does

  • Build workflows — chain focused prompts into reusable security research playbooks.
  • Run scans — analyze remote or local repositories and their dependencies with Codex or Claude Code.
  • Verify findings — use post-scripts to validate issues, build proofs of concept, and produce reports.
  • Prioritize results — apply custom severity rankers, a consistent finding schema, and automatic de-duplication.
  • Bring your own model access — use a Codex login or connect through OpenAI, Anthropic, or OpenRouter.

Built from real security research. The Kritt team has earned over $1,500,000 in bug-bounty payouts under the researcher name Blockian (Immunefi · HackenProof · blockian.xyz · @ControlZ_1337). open·kritt is the open-source distillation of the internal project behind that work.

Getting started

You need Git, Docker with Docker Compose, and Node.js 20 or newer. The repository-local CLI has no install step.

git clone https://github.com/Kritt-ai/open-kritt
cd open-kritt
./kritt setup
./kritt start

Open http://localhost:5173 once the stack is running. You only need one model-access option; ./kritt setup guides you through the available logins and API keys. A GITHUB_TOKEN is optional and only needed for private GitHub repositories.

The default ports bind to 127.0.0.1, and the backend does not include application authentication. Keep the stack private.

Tool-enabled agents run as root inside disposable job containers, with writable repository copies and direct internet access so they can install tools, compile targets, run tests, and build proofs of concept. Run open·kritt on a dedicated Docker host or VM; see the threat model before scanning untrusted code.

For prerequisites, manual Docker setup, and provider-specific instructions, read the installation guide and AI provider setup.

Documentation

Preview the documentation locally with Mint:

npm install -g mint
cd docs-site
npm run dev

Open http://localhost:3001 to view the site.

  • Product overview
  • Run your first scan
  • Workflows and prompt steps
  • Security and threat model

Community and contributing

Questions and ideas belong in GitHub Discussions. Use GitHub Issues for bugs and feature requests.

Contributions are welcome. Read CONTRIBUTING.md for the development setup, test commands, Conventional Commits, and DCO sign-off requirements.

Please report security vulnerabilities privately by following SECURITY.md, not through a public issue.

License

open·kritt is licensed under the GNU Affero General Public License v3.0.

Official distribution

获取与安装

暂未发现可确认的官方软件包地址

当前 README 快照没有出现 npm、PyPI、Crates.io、pub.dev 等官方包页链接。本站不会根据仓库名称猜测下载地址。

本站不托管项目文件;需要安装时,请以项目维护者发布的官方文档为准。

使用前核验

本站保存公开资料用于阅读,不代表安全审计或功能背书。安装前请核对许可证、依赖来源和发布签名,不要直接运行来源不明的二进制文件或高权限脚本。