open-kritt vs pentagi
Self-hosted platform orchestrating AI agents for vulnerability research: chain focused prompts into reusable workflows, run them in parallel over Codex or Claude Code, dedupe and rank findings. — versus — Self-hosted autonomous pentesting: multi-agent system in sandboxed Docker with 20+ tools, supervised agent hierarchies, Langfuse observability and a Graphiti knowledge graph. 10+ LLM providers.
Agent-driven vulnerability discovery, two shapes: open-kritt orchestrates researcher-designed workflows over code; PentAGI ships a fully autonomous sandboxed pentest platform against live targets.
| open-kritt | pentagi | |
|---|---|---|
| Stars | 1.6k | 22k |
| Forks | 284 | 2.9k |
| Language | JavaScript | Go |
| License | AGPL-3.0 | MIT |
| Last activity | yesterday | 3 days ago |
| Topics | security | security, agents |
| Curated connections | 2 | 3 |
open-kritt — the curator's take
The engineering acknowledges the real problem: point-a-model-at-a-repo doesn't find vulns, so it decomposes research into focused parallel tasks and invests in what security teams actually need — dedup, consistent schemas, severity ranking, PoC validation post-scripts. When NOT: AGPL-3.0 matters if you're a vendor embedding it; findings are only as good as your workflow prompts — it's a power tool for researchers, not a push-button scanner.
pentagi — the curator's take
The most complete self-hosted offensive-AI platform in the open: agent supervision, isolated execution, observability and long-term memory are all first-class, not bolted on — this is infrastructure, not a script. When NOT: it's a serious deployment (Docker stack, Postgres, optional Langfuse/Graphiti services) for serious authorized work — a quick web-app scan doesn't need an AGI acronym; and autonomous exploitation tooling makes your legal scope YOUR problem, doubly so.