open-kritt is a free, open source ai security & privacy project written in JavaScript and released under AGPL-3.0. It has 2,146 GitHub stars, 367 forks and 7 open issues, and was last pushed 2 days ago. On this registry it ranks #16 of 34 tracked projects in AI Security & Privacy, with 5 head-to-head comparisons available. It gained 12 stars over the last 3 tracked days.

What is open-kritt?

What it is

open-kritt is an open-source, self-hosted AI vulnerability research tool written in JavaScript and licensed under AGPL-3.0. It lives in the AI security and vulnerability research ecosystem, using language models to inspect code for security issues. The project orchestrates AI agents instead of asking one model to review an entire repository in a single pass.

The concrete problem is that broad AI repository review often produces weak or noisy findings. open-kritt breaks research into smaller, well-defined tasks, runs them across agents in parallel, and combines output into findings that can be validated, enriched, de-duplicated, and prioritized. It gives researchers control over prompts, workflows, model providers, and infrastructure.

Key capabilities

  • It lets users build reusable security research playbooks by chaining focused prompts into workflows.
  • It scans remote or local repositories and their dependencies using Codex or Claude Code as the analysis agent.
  • It provides post-scripts that validate findings, build proofs of concept, and produce reports.
  • It exports completed scans as ZIP archives with canonical findings, structured data, post-processing output, reports, and proofs of concept, while stopped or failed scans with findings produce clearly marked partial exports.
  • It prioritizes results through a consistent finding schema, automatic de-duplication, and custom severity rankers.
  • It supports model access through a Codex login or connections to OpenAI, Anthropic, OpenRouter, or xAI.

Who uses it and how

  • Security researchers and developers use it to run focused code-security scans on remote or local repositories and their dependencies instead of sending an entire repository to one model prompt.
  • Teams on servers without a browser can run the stack and use the headless CLI to import portable workflow, post-script, skill, and ranker JSON, create scans, inspect status, edit non-secret settings, and export finding bundles.
  • Researchers needing isolated execution can run tool-enabled agents in disposable Docker job containers, where agents install tools, compile targets, run tests, and build proofs of concept.

Getting started

Install requires Git, Docker with Docker Compose, and Node.js 20 or newer. Clone the repository, run ./kritt setup and ./kritt start, then open http://localhost:5173; on a headless server, use ./kritt-headless while the stack remains running.

When to use it — and when not to

Use open-kritt when researchers need a self-hosted platform for structured AI-assisted vulnerability research with control over prompts, workflows, model providers, and scan infrastructure. Do not expose it as a shared public service without adding protection, because the backend lacks application authentication and default ports bind only to 127.0.0.1. Do not scan untrusted code outside a dedicated Docker host or VM, because tool-enabled agents run as root inside disposable job containers with writable repository copies and direct internet access.

project readme (upstream, from github) — read inline

open·kritt

Orchestrate AI agents to find real vulnerabilities in code.

An open-source, self-hosted security and vulnerability research platform that turns focused AI analysis into de-duplicated, ranked findings with configurable validation and enrichment.

License: AGPL-3.0 Release

Website · Documentation · Getting started · Contributing · Owners · Research paper

Join the open·kritt Discord community Follow Kritt on X

open·kritt workflow builder

What is open·kritt?

Pointing a model at an entire repository and asking it to find vulnerabilities rarely works well. open·kritt takes a focused approach: break the research into small, well-defined tasks, run them across AI agents in parallel, and combine their output into findings you can validate and prioritize.

It is built for security researchers and security-minded developers who want control over their prompts, workflows, model providers, and infrastructure.

What it does

  • Build workflows — chain focused prompts into reusable security research playbooks.
  • Run scans — analyze remote or local repositories and their dependencies with Codex or Claude Code.
  • Verify findings — use post-scripts to validate issues, build proofs of concept, and produce reports.
  • Export scan results — package canonical findings, structured data, post-processing output, reports, and proofs of concept in one ZIP archive with a share-safe manifest; completed scans produce complete exports, while stopped or failed scans with findings produce clearly marked partial exports. Attacker-influenced report and PoC source is kept as plain text.
  • Prioritize results — apply custom severity rankers, a consistent finding schema, and automatic de-duplication.
  • Bring your own model access — use a Codex login or connect through OpenAI, Anthropic, OpenRouter, or xAI.

Built from real security research. The Kritt team has earned over $1,500,000 in bug-bounty payouts under the researcher name Blockian (Immunefi · HackenProof · blockian.xyz · @Kritt_AI). open·kritt is the open-source distillation of the internal project behind that work.

Getting started

You need Git, Docker with Docker Compose, and Node.js 20 or newer. The repository-local CLI has no install step.

git clone https://github.com/Kritt-ai/open-kritt
cd open-kritt
./kritt setup
./kritt start

Open http://localhost:5173 once the stack is running. You only need one model-access option; ./kritt setup guides you through the available logins and API keys. A GITHUB_TOKEN is optional and only needed for private GitHub repositories.

On a server without a browser or desktop, leave the stack running and open another shell:

./kritt-headless

The headless CLI imports portable workflow, post-script, skill, and ranker JSON; creates scans with the same backend validation as the web form; displays scan status, stages, and failure reasons; edits non-secret runtime settings; and exports finding bundles. It does not display finding contents in the terminal. See the headless CLI guide.

The default ports bind to 127.0.0.1, and the backend does not include application authentication. Keep the stack private.

Tool-enabled agents run as root inside disposable job containers, with writable repository copies and direct internet access so they can install tools, compile targets, run tests, and build proofs of concept. Run open·kritt on a dedicated Docker host or VM; see the threat model before scanning untrusted code.

For prerequisites, manual Docker setup, and provider-specific instructions, read the installation guide and AI provider setup.

In Accounts, use the persisted Active switch to choose which accounts may receive new assignments while keeping other credentials saved. See active provider accounts.

Documentation

Preview the documentation locally with Mint:

npm install -g mint
cd docs-site
npm run dev

Open http://localhost:3001 to view the site.

Community and contributing

open·kritt is jointly owned and maintained by Harel Rom (@harel-coffee) and Gabriel Balko (@GabiCtrlZ). See project ownership and copyright for details.

Questions and ideas belong in GitHub Discussions. Use GitHub Issues for bugs and feature requests.

Contributions are welcome. Read CONTRIBUTING.md for the development setup, test commands, and Conventional Commit requirements.

Please report security vulnerabilities privately by following SECURITY.md, not through a public issue.

License

open·kritt is licensed under the GNU Affero General Public License v3.0.

Frequently asked questions

Is open-kritt free to use?

open-kritt is open source under the AGPL-3.0 licence. There is no licence fee and no seat count — you can self-host it or, where the project offers one, pay a vendor for a managed version instead.

What does open-kritt do?

Open-source, self-hosted AI vulnerability research tool that orchestrates agents to find and validate security issues in code.

What is open-kritt written in?

open-kritt is primarily written in JavaScript. Its source is publicly available at https://github.com/Kritt-ai/open-kritt, and it has 2,146 GitHub stars.