[{"data":1,"prerenderedAt":4},["ShallowReactive",2],{"readme:open-kritt":3},"\u003Cdiv align=\"center\">\u003Cpicture>\n  \u003Csource media=\"(prefers-color-scheme: dark)\" srcset=\"docs\u002Fimages\u002Flogo-dark.png\">\u003C\u002Fsource>\n  \u003Cimg alt=\"open·kritt\" src=\"https:\u002F\u002Fraw.githubusercontent.com\u002FKritt-ai\u002Fopen-kritt\u002FHEAD\u002Fdocs\u002Fimages\u002Flogo-light.png\" width=\"96\" height=\"96\" \u002F>\n\u003C\u002Fpicture>\u003Ch1>open·kritt\u003C\u002Fh1>\n\u003Cp>\u003Cstrong>Orchestrate AI agents to find real vulnerabilities in code.\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>An open-source, self-hosted security research platform that turns focused AI analysis\ninto de-duplicated, ranked findings with configurable validation and enrichment.\u003C\u002Fp>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fgithub.com\u002FKritt-ai\u002Fopen-kritt\u002Fblob\u002FHEAD\u002FLICENSE\" rel=\"nofollow ugc noopener\">\u003Cimg src=\"https:\u002F\u002Fimg.shields.io\u002Fbadge\u002Flicense-AGPL--3.0-blue.svg\" alt=\"License: AGPL-3.0\" \u002F>\u003C\u002Fa>\n\u003Ca href=\"https:\u002F\u002Fgithub.com\u002FKritt-ai\u002Fopen-kritt\u002Freleases\" rel=\"nofollow ugc noopener\">\u003Cimg src=\"https:\u002F\u002Fimg.shields.io\u002Fgithub\u002Fv\u002Frelease\u002FKritt-ai\u002Fopen-kritt?sort=semver\" alt=\"Release\" \u002F>\u003C\u002Fa>\u003C\u002Fp>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fkritt.ai\" rel=\"nofollow ugc noopener\">Website\u003C\u002Fa> ·\n\u003Ca href=\"https:\u002F\u002Fdocs.kritt.ai\" rel=\"nofollow ugc noopener\">Documentation\u003C\u002Fa> ·\n\u003Ca href=\"https:\u002F\u002Fdocs.kritt.ai\u002Fgetting-started\u002Finstallation-and-setup\" rel=\"nofollow ugc noopener\">Getting started\u003C\u002Fa> ·\n\u003Ca href=\"https:\u002F\u002Fgithub.com\u002FKritt-ai\u002Fopen-kritt\u002Fblob\u002FHEAD\u002FCONTRIBUTING.md\" rel=\"nofollow ugc noopener\">Contributing\u003C\u002Fa> ·\n\u003Ca href=\"https:\u002F\u002Fgithub.com\u002FKritt-ai\u002Fopen-kritt\u002Fblob\u002FHEAD\u002FOWNERSHIP.md\" rel=\"nofollow ugc noopener\">Owners\u003C\u002Fa> ·\n\u003Ca href=\"https:\u002F\u002Fkritt.ai\u002Fopen-kritt-launch\" rel=\"nofollow ugc noopener\">Research paper\u003C\u002Fa>\u003C\u002Fp>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Ft.co\u002FWzXMUKWxcR\" rel=\"nofollow ugc noopener\">\u003Cimg alt=\"Join the open·kritt Discord community\" src=\"https:\u002F\u002Fimg.shields.io\u002Fbadge\u002FDiscord-5865F2?logo=discord&amp;logoColor=white\" \u002F>\u003C\u002Fa>\n\u003Ca href=\"https:\u002F\u002Fx.com\u002FKritt_AI\" rel=\"nofollow ugc noopener\">\u003Cimg alt=\"Follow Kritt on X\" src=\"https:\u002F\u002Fimg.shields.io\u002Fbadge\u002FX-000000?logo=x&amp;logoColor=white\" \u002F>\u003C\u002Fa>\u003C\u002Fp>\n\u003C\u002Fdiv>\u003Cp>\u003Cimg src=\"https:\u002F\u002Fraw.githubusercontent.com\u002FKritt-ai\u002Fopen-kritt\u002FHEAD\u002Fassets\u002Fworkflow_screen.png\" alt=\"open·kritt workflow builder\" \u002F>\u003C\u002Fp>\n\u003Ch2>What is open·kritt?\u003C\u002Fh2>\n\u003Cp>Pointing a model at an entire repository and asking it to find vulnerabilities rarely\nworks well. open·kritt takes a focused approach: break the research into small,\nwell-defined tasks, run them across AI agents in parallel, and combine their output into\nfindings you can validate and prioritize.\u003C\u002Fp>\n\u003Cp>It is built for security researchers and security-minded developers who want control\nover their prompts, workflows, model providers, and infrastructure.\u003C\u002Fp>\n\u003Ch3>What it does\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>Build workflows\u003C\u002Fstrong> — chain focused prompts into reusable security research playbooks.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Run scans\u003C\u002Fstrong> — analyze remote or local repositories and their dependencies with Codex\nor Claude Code.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Verify findings\u003C\u002Fstrong> — use post-scripts to validate issues, build proofs of concept, and\nproduce reports.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Prioritize results\u003C\u002Fstrong> — apply custom severity rankers, a consistent finding schema,\nand automatic de-duplication.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Bring your own model access\u003C\u002Fstrong> — use a Codex login or connect through OpenAI,\nAnthropic, or OpenRouter.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cblockquote>\n\u003Cp>\u003Cstrong>Built from real security research.\u003C\u002Fstrong> The Kritt team has earned over \u003Cstrong>$1,500,000 in\nbug-bounty payouts\u003C\u002Fstrong> under the researcher name \u003Cstrong>Blockian\u003C\u002Fstrong>\n(\u003Ca href=\"https:\u002F\u002Fimmunefi.com\u002Fprofile\u002FBlockian\u002F\" rel=\"nofollow ugc noopener\">Immunefi\u003C\u002Fa> ·\n\u003Ca href=\"https:\u002F\u002Fhackenproof.com\u002Fhackers\u002FBlockian\" rel=\"nofollow ugc noopener\">HackenProof\u003C\u002Fa> ·\n\u003Ca href=\"https:\u002F\u002Fblockian.xyz\" rel=\"nofollow ugc noopener\">blockian.xyz\u003C\u002Fa> · \u003Ca href=\"https:\u002F\u002Fx.com\u002FKritt_AI\" rel=\"nofollow ugc noopener\">@Kritt_AI\u003C\u002Fa>).\nopen·kritt is the open-source distillation of the internal project behind that work.\u003C\u002Fp>\n\u003C\u002Fblockquote>\n\u003Ch2>Getting started\u003C\u002Fh2>\n\u003Cp>You need Git, Docker with Docker Compose, and Node.js 20 or newer. The repository-local\nCLI has no install step.\u003C\u002Fp>\n\u003Cpre>\u003Ccode class=\"language-bash\">git clone https:\u002F\u002Fgithub.com\u002FKritt-ai\u002Fopen-kritt\ncd open-kritt\n.\u002Fkritt setup\n.\u002Fkritt start\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>Open \u003Ca href=\"http:\u002F\u002Flocalhost:5173\" rel=\"nofollow ugc noopener\">http:\u002F\u002Flocalhost:5173\u003C\u002Fa> once the stack is running. You only\nneed one model-access option; \u003Ccode>.\u002Fkritt setup\u003C\u002Fcode> guides you through the available logins and\nAPI keys. A \u003Ccode>GITHUB_TOKEN\u003C\u002Fcode> is optional and only needed for private GitHub repositories.\u003C\u002Fp>\n\u003Cp>The default ports bind to \u003Ccode>127.0.0.1\u003C\u002Fcode>, and the backend does not include application\nauthentication. Keep the stack private.\u003C\u002Fp>\n\u003Cp>Tool-enabled agents run as root inside disposable job containers, with writable repository\ncopies and direct internet access so they can install tools, compile targets, run tests,\nand build proofs of concept. Run open·kritt on a dedicated Docker host or VM; see the\n\u003Ca href=\"https:\u002F\u002Fgithub.com\u002FKritt-ai\u002Fopen-kritt\u002Fblob\u002FHEAD\u002Fdocs\u002Fthreat-model.md\" rel=\"nofollow ugc noopener\">threat model\u003C\u002Fa> before scanning untrusted code.\u003C\u002Fp>\n\u003Cp>For prerequisites, manual Docker setup, and provider-specific instructions, read the\n\u003Ca href=\"https:\u002F\u002Fgithub.com\u002FKritt-ai\u002Fopen-kritt\u002Fblob\u002FHEAD\u002Fdocs-site\u002Fgetting-started\u002Finstallation-and-setup.mdx\" rel=\"nofollow ugc noopener\">installation guide\u003C\u002Fa> and\n\u003Ca href=\"https:\u002F\u002Fgithub.com\u002FKritt-ai\u002Fopen-kritt\u002Fblob\u002FHEAD\u002Fdocs-site\u002Fai-provider-setup\u002Foverview.mdx\" rel=\"nofollow ugc noopener\">AI provider setup\u003C\u002Fa>.\u003C\u002Fp>\n\u003Ch2>Documentat\u003C\u002Fh2>\n",1786232077389]