claude-bug-bounty vs pentagi
Autonomous bug-bounty agent for the terminal — recon, 20 vuln classes, a validation gate and submission-ready HackerOne/Bugcrowd reports. Runs as a Claude Code plugin or standalone on free providers. — versus — Self-hosted autonomous pentesting: multi-agent system in sandboxed Docker with 20+ tools, supervised agent hierarchies, Langfuse observability and a Graphiti knowledge graph. 10+ LLM providers.
Autonomous offensive security at two weights: claude-bug-bounty is a terminal agent producing bounty reports; PentAGI is a full self-hosted platform with sandboxing, supervision and memory.
| claude-bug-bounty | pentagi | |
|---|---|---|
| Stars | 4.2k | 22k |
| Forks | 745 | 2.9k |
| Language | Python | Go |
| License | MIT | MIT |
| Last activity | 8 days ago | 3 days ago |
| Topics | security | security, agents |
| Curated connections | 5 | 3 |
claude-bug-bounty — the curator's take
For solo bounty hunters who want an agent to run recon→hunt→validate→report end to end: the strict validation gate before a finding becomes a report is the useful part (cuts false-positive noise reviewers hate), and standalone mode on Ollama means no subscription. NOT a replacement for skilled manual testing on serious targets, and point it ONLY at assets you're authorized to test — autonomous scanning of others' systems is illegal. Report quality still needs a human pass before submission.
pentagi — the curator's take
The most complete self-hosted offensive-AI platform in the open: agent supervision, isolated execution, observability and long-term memory are all first-class, not bolted on — this is infrastructure, not a script. When NOT: it's a serious deployment (Docker stack, Postgres, optional Langfuse/Graphiti services) for serious authorized work — a quick web-app scan doesn't need an AGI acronym; and autonomous exploitation tooling makes your legal scope YOUR problem, doubly so.