Autonomous, self-hosted security testing for authorized bug bounty and pentesting
- Proven in the Security Community
- What is BugTraceAI?
- The Ecosystem
- Architecture
- Scanning Pipeline
- What's New
- Demo Report
- CI/CD Integration Proposal
- Quick Start
- Documentation
- Community & Support
| Product | CVE | CVSS |
|---|---|---|
| Wallos | CVE-2026-27479 | 7.7 High |
| ZoneMinder | CVE-2026-27470 | 8.8 High |
| Piwigo | CVE-2026-27834 | 7.2 High |
- RootedCON 2026, Madrid, Spain
- HKOSCon 2026, Hong Kong
- DEF CON 34, Las Vegas, USA
BugTraceAI combines AI-guided investigation with deterministic security tools. The AI prioritizes and reasons about hypotheses; tools and evidence validate what is real.
This platform is provided for educational and authorized security testing purposes only.
- Only test applications for which you have explicit, written authorization
- AI output may contain inaccuracies, false positives, or false negatives
- It is not a substitute for professional security auditing
- The creators assume no liability for misuse or damage
Always verify findings manually.
BugTraceAI is an opensource, self-hosted framework for bug bounty hunting and penetration testing. It combines autonomous AI agents with real security tools to discover, analyze, exploit, and validate vulnerabilities independently.
This is NOT a wrapper around existing tools. It is an autonomous multi-agent system where AI agents make intelligent decisions about what to test, how to mutate payloads, and when findings are real.
| Principle | Description |
|---|---|
| Privacy-First | Everything runs locally. No telemetry, no tracking, no cloud dependency |
| Opensource | AGPL-3.0 licensed. All code, prompts, and algorithms are public |
| Self-Hosted | Your data stays on your infrastructure |
| Modular | Use components independently or together |
| Docker-Native | One-command deployment via Launcher |
BugTraceAI is composed of 4 independent but interconnected components, plus a dedicated practice target:
| Component | Description | Tech Stack | Repository |
|---|---|---|---|
| BugTraceAI-CLI | Autonomous AI security scanner. Multi-agent pipeline with Go fuzzers, Playwright browser validation, and AI-driven analysis | Python + FastAPI + Go + Playwright | BugTraceAI-CLI |
| BugTraceAI-WEB | Web dashboard with 20+ AI security tools, real-time scan monitoring, and CLI control center | React + Express + PostgreSQL | BugTraceAI-WEB |
| BugTraceAI-Launcher | One-command Docker deployment wizard with interactive setup, service management, and an optional AI Setup & Repair Assistant (DeepSeek V3 with automatic Claude Haiku 4.5 fallback) that can install or repair a deployment | Bash + Python + Docker Compose | BugTraceAI-Launcher |
| MCP Ecosystem | Extensible agent framework using the Model Context Protocol. Includes integrated Kali Linux and ReconFTW agents | MCP + Docker + Python | reconftw-mcp |
| BugStore | Deliberately vulnerable practice target used in demos and walkthroughs. Full-featured shop riddled with 32 planted OWASP vulnerabilities | Python + FastAPI + SQLite | BugTraceAI/BugStore |
Each component works independently. Use the WEB alone for AI analysis, the CLI alone for autonomous scanning, or deploy everything together with the Launcher.
+----------------------------+
| BugTraceAI-WEB |
| React + Express + PgSQL |
| Port 6869 / Port 3001 |
+-------------+--------------+
|
REST API + WebSocket
|
+-------------+-----------------+
| BugTraceAI-CLI |
| FastAPI + SQLite + LanceDB |
| Port 8000 |
+---+--------+-------------+----+
| | |
+----+--+ +---+------+ +----+------+
|Go | |Playwright| |AI Agents |
|Fuzzers| |Browser | |OpenRouter |
+-------+ +----------+ +-----------+
SQLite is the source of truth for all scan data. PostgreSQL is local to each WEB instance for chats, settings, and analysis. They work autonomously OR together -- multiple WEB instances can connect to one CLI over the network.
For detailed architecture documentation, see the Wiki.
The CLI runs a 6-phase autonomous pipeline:
| Phase | Name | Description |
|---|---|---|
| 1 | Discovery | Crawl and spider the target to map the attack surface |
| 2 | Analysis | Multi-persona AI analysis with consensus voting |
| 3 | Consolidation | Deduplicate findings and distribute to specialist queues |
| 4 | Exploitation | 15 specialist agents (XSS, SQLi, SSRF, IDOR, LFI, RCE, XXE, JWT, Open Redirect, Prototype Pollution, CSTI, Mass Assignment, Header Injection, API Security, File Upload) with Go fuzzers and AI-mutated payloads |
| 5 | Validation | Chrome DevTools Protocol + Vision AI screenshot analysis confirms findings |
| 6 | Reporting | PoC enrichment with WET/DRY traceability, AI-generated technical and executive reports |
The pipeline includes a circuit breaker that auto-pauses scanning when the target becomes unresponsive, and supports authenticated scanning via YAML configuration with automatic TOTP/2FA token generation for login-protected targets.
For the full pipeline documentation, see the Wiki.
- AIrepeater — Burp/Caido-style multi-tab HTTP workbench with manual and AI-agent-driven exploitation modes, per-vulnerability playbooks, response search, and report handoff; the exploit model is provider-guarded and a dry-run button verifies the auto-auth macro before you rely on it
- Live Swarm Graph — real-time visualization of reconnaissance, strategy, specialist, validation, and reporting stages, with per-agent L1→L6 escalation ladders that climb live as each agent works
- Model Lab module — standalone sidebar module at
/modellabfor benchmarking OpenRouter models with its own API key: calibratedquick-v3/advanced-v2suites, a "Best per slot" leaderboard (MUTATION / SKEPTICAL / ANALYSIS / REPORTING), an opt-in MUTATION diversity probe, live WebSocket progress, cost visibility, and local history - Anthropic chat provider — Claude (Messages API,
x-api-key) selectable alongside OpenRouter and Z.ai for chat, analysis, and the Repeater, with tool-calling normalized to the shared shape - Curated model pack + Thinking control — a hand-picked, verified OpenRouter model list plus Thinking / High / xHigh entries that enable OpenRouter's reasoning parameter
- Report Enrich + AuthDiscovery visibility — a self-heal "Enrich" button re-runs PoC/CVSS enrichment when a report comes out under-enriched, and AuthDiscovery start, per-URL progress, and JWT/cookie totals surface in the Events feed and Swarm Graph
- Anthropic direct-API provider — Anthropic is a first-class LLM provider via API key (
x-api-key, Messages API); a newapi_formatpreset field decouples the wire format so generation, threaded generation, vision, and connectivity all route to the Anthropic Messages API when active - Integrated Model Lab (model-eval) —
/api/model-evalendpoints with a per-request OpenRouter key and live WebSocket progress; quality-dominant recalibration, newquick-v3/advanced-v2suites, a per-slot leaderboard (MUTATION / SKEPTICAL / ANALYSIS / REPORTING), and an opt-in MUTATION diversity probe - Reporting/enrichment failover + provenance — PoC/CVSS enrichment falls back to a secondary provider (
REPORTING_FAILOVER_ENABLED/REPORTING_FAILOVER_PROVIDER, defaultanthropic) for that call only, never changing the scan's active provider;poc_enrichment_provenanceandreporting_failover_countmake reporting saturation visible in the deliverable - Dedup & detection fixes — RCE-family findings canonicalize to a single type (no double-count), strong-evidence IDORs route to MANUAL_REVIEW instead of being buried, and boolean-blind SQLi diffing is capped/off-thread to prevent event-loop stalls
- Deliverable parity — pending (POTENTIAL) findings appear across Markdown, engagement JSON, and
validated_findings.json, and the "Findings by Severity" totals now match across all deliverables
- Anthropic provider — pick Claude direct API (
sk-ant-..., Messages API) as the LLM provider, both in the standard provider selector (which configures the deployed CLI) and in the AI Setup & Repair Assistant - AI Setup & Repair Assistant — Choose standard guided setup, or let the AI agent install from scratch or diagnose/repair an existing deployment; runs on DeepSeek V3 (OpenRouter) or Claude Haiku 4.5 (Anthropic direct), selected at startup, with an automatic sticky fallback on the OpenRouter path
- Safer & English-only — destructive commands (e.g.
docker compose down -v) are classified and gated, the UI is English-only, and the installer core was hardened with added tests - Hardened & robust — Native Docker build output (no fragile spinner), multi-distro dependency install (apt/dnf/yum/pacman/zypper),
600-permission config files, hidden/masked API-key entry, kernel-enforced command timeouts - macOS Apple Silicon — Full Colima/Docker Desktop support with ARM patches for reconFTW and Kali MCPs
Want to see what BugTraceAI produces? Try the live demo or download a real scan report generated against BugStore -- our deliberately vulnerable practice app.
Scan highlights: 145 findings (43 validated) -- SQL Injection, XSS, LFI, CSTI, IDOR, JWT, RCE, Broken Access Control, Open Redirect, Prototype Pollution, GraphQL, SSRF, and more.
Benchmark note: This demo report was produced with an earlier scanner build. Results are useful for exploring the workflow, but should not be treated as a current performance claim for the latest CLI release until re-run under a versioned benchmark protocol.
The zip includes the full markdown report, validated findings JSON, specialist agent results with WET/DRY traceability, reconnaissance data, and PoC enrichment output.
BugTraceAI can operate as a security testing service in a CI/CD workflow: receive authorized jobs through its API or MCP layer, scan approved targets, publish evidence-rich reports, and pass validated findings into analysis and ticketing workflows.
The WEB workspace supports manual analysis alongside autonomous scans, while the CLI exposes the control and reporting surface needed for automation.
- Docker 24.0+
- Git
- 4 GB RAM (8 GB recommended)
- 10 GB disk space
- OpenRouter API key
One-liner (recommended):
curl -fsSL https://raw.githubusercontent.com/BugTraceAI/BugTraceAI-Launcher/main/install.sh | bashOr clone and run manually:
git clone https://github.com/BugTraceAI/BugTraceAI-Launcher.git ~/bugtraceai-launcher
~/bugtraceai-launcher/launcher.shThe interactive wizard handles deployment mode selection, API key configuration, and port assignment. If anything goes wrong, the optional AI Setup & Repair Assistant (powered by DeepSeek V3 with automatic Claude Haiku 4.5 fallback) can install from scratch or diagnose and repair an existing deployment.
| Mode | What You Get | Use Case |
|---|---|---|
| Full Platform | WEB + CLI auto-connected | Complete scanning + dashboard |
| Standalone CLI | Headless scanner + API | CI/CD pipelines, automation |
| Standalone WEB | Dashboard + AI tools | Manual analysis without scanning |
# CLI only
git clone https://github.com/BugTraceAI/BugTraceAI-CLI.git
cd BugTraceAI-CLI
pip install -r requirements.txt
python -m bugtrace --help
# WEB only
git clone https://github.com/BugTraceAI/BugTraceAI-WEB.git
cd BugTraceAI-WEB
docker compose upFull documentation is available in the Project Wiki:
- Overview -- What BugTraceAI is and who it's for
- Architecture -- System design and communication protocols
- BugTraceAI-CLI -- Autonomous scanner documentation
- BugTraceAI-WEB -- Web dashboard documentation
- BugTraceAI-Launcher -- Deployment guide
- API Reference -- REST API and WebSocket endpoints
- Getting Started -- Installation and first scan
| Resource | Link |
|---|---|
| Website | bugtraceai.com |
| Wiki | GitHub Wiki |
| DeepWiki | AI-powered docs |
| Issues | GitHub Issues |
| Discord | Join the BugTraceAI community |
| @yz9yt |
We welcome contributions: bug reports, feature requests, PRs, documentation improvements, and community tools. Open an issue on the respective repository to get started.
AGPL-3.0 License — Free to use, modify, and distribute. If you modify and distribute or offer as a service, you must share your changes under the same license.
See LICENSE file in each repository.
BugTraceAI -- Build your own self-hosted pentesting platform.
If BugTraceAI helps your authorized security research, consider giving the project a star or joining the community on Discord.
Albert C (@yz9yt)



