<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Intelliflame</title>
    <description>The latest articles on DEV Community by Intelliflame (@intelliflame).</description>
    <link>https://dev.to/intelliflame</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F4166631%2F6e94406f-3b12-4026-bae3-d9383f9a230f.png</url>
      <title>DEV Community: Intelliflame</title>
      <link>https://dev.to/intelliflame</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/intelliflame"/>
    <language>en</language>
    <item>
      <title>Meet BugTraceAI: an open-source, self-hosted agentic pentester</title>
      <dc:creator>Intelliflame</dc:creator>
      <pubDate>Wed, 07 Oct 2026 03:33:36 +0000</pubDate>
      <link>https://dev.to/intelliflame/meet-bugtraceai-an-open-source-self-hosted-agentic-pentester-4ln0</link>
      <guid>https://dev.to/intelliflame/meet-bugtraceai-an-open-source-self-hosted-agentic-pentester-4ln0</guid>
      <description>&lt;p&gt;Every security team knows the pattern: you want a proper assessment of an app, but the options are waiting weeks for a consultancy slot, or stitching together a dozen tools and babysitting them for days. Bug bounty hunters know a variant of the same problem — the toolchain is powerful but fragmented, and every judgement call is on you.&lt;/p&gt;

&lt;p&gt;We are building a third option. &lt;strong&gt;BugTraceAI&lt;/strong&gt; is an open-source, self-hosted framework for authorized bug bounty and penetration testing. It runs an autonomous agentic pipeline: AI agents plan and prioritize the work, specialist tools and browser validation collect the evidence, and every finding comes out with something you can verify before you file it.&lt;/p&gt;

&lt;h2&gt;
  
  
  Why "agentic" matters here
&lt;/h2&gt;

&lt;p&gt;Plenty of scanners already automate checks. The gap BugTraceAI aims at is the layer above: deciding what to test, in what order, and what to do with ambiguous signals.&lt;/p&gt;

&lt;p&gt;In BugTraceAI, agents drive a six-phase pipeline:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;
&lt;strong&gt;Recon&lt;/strong&gt; — crawl the target and discover endpoints&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Discovery&lt;/strong&gt; — analyze URLs and collect initial findings&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Strategy&lt;/strong&gt; — consolidate findings and route work to specialists&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Exploit&lt;/strong&gt; — run specialist checks and collect evidence&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Validate&lt;/strong&gt; — verify findings before they reach the report&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Report&lt;/strong&gt; — generate structured, human-readable deliverables&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;The AI reasons and prioritizes; deterministic security tools (including Go fuzzers and browser-based validation via Playwright) adjudicate. The design principle in one line: &lt;strong&gt;AI output is a hypothesis — evidence makes it a finding.&lt;/strong&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  Four components, one ecosystem
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;BugTraceAI-CLI&lt;/strong&gt; — the autonomous scanner: terminal workspace (TUI), REST API and MCP, multi-agent pipeline with specialist tools&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;BugTraceAI-WEB&lt;/strong&gt; — browser dashboard with 20+ AI security tools, real-time scan monitoring and a CLI control center&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;BugTraceAI-API&lt;/strong&gt; — evidence-first API security testing service over REST and MCP&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;BugTraceAI-Launcher&lt;/strong&gt; — guided deployment: Wizard or AI-assisted setup, local or Docker runtime&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Plus &lt;strong&gt;BugStore&lt;/strong&gt; — a deliberately vulnerable practice shop with 32 planted OWASP vulnerabilities, so you can try the whole workflow legally.&lt;/p&gt;

&lt;p&gt;Everything is self-hosted and Apache-2.0 licensed. Scans, reports and evidence stay on your infrastructure, and analysis runs with your own LLM provider key.&lt;/p&gt;

&lt;h2&gt;
  
  
  Does it actually find things?
&lt;/h2&gt;

&lt;p&gt;Three CVEs disclosed so far, found with BugTraceAI:&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Product&lt;/th&gt;
&lt;th&gt;CVE&lt;/th&gt;
&lt;th&gt;CVSS&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Wallos&lt;/td&gt;
&lt;td&gt;CVE-2026-27479&lt;/td&gt;
&lt;td&gt;7.7 High&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;ZoneMinder&lt;/td&gt;
&lt;td&gt;CVE-2026-27470&lt;/td&gt;
&lt;td&gt;8.8 High&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Piwigo&lt;/td&gt;
&lt;td&gt;CVE-2026-27834&lt;/td&gt;
&lt;td&gt;7.2 High&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;The project was presented on stage at DEF CON 34 (Las Vegas), RootedCON 2026 (Madrid) and HKOSCon 2026 (Hong Kong). Component versions are currently in beta — treat outputs as leads to verify, not verdicts. (That is the point of the evidence-first design.)&lt;/p&gt;

&lt;h2&gt;
  
  
  Try it
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Live demo (a real scan):&lt;/strong&gt; &lt;a href="https://demo.bugtraceai.com/bugtraceai" rel="noopener noreferrer"&gt;demo.bugtraceai.com&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Self-host in minutes:&lt;/strong&gt; one-command Launcher install — see the Quick Start in the &lt;a href="https://github.com/BugTraceAI/BugTraceAI#quick-start" rel="noopener noreferrer"&gt;GitHub README&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Practice target:&lt;/strong&gt; &lt;a href="https://bugstore.bugtraceai.com/" rel="noopener noreferrer"&gt;BugStore&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Code:&lt;/strong&gt; &lt;a href="https://github.com/BugTraceAI" rel="noopener noreferrer"&gt;github.com/BugTraceAI&lt;/a&gt; — if this is useful, a star helps other security folks find it&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;em&gt;BugTraceAI is built for authorized security testing only. Only test applications you have explicit written permission to test.&lt;/em&gt;&lt;/p&gt;

</description>
      <category>security</category>
      <category>opensource</category>
      <category>ai</category>
      <category>cybersecurity</category>
    </item>
  </channel>
</rss>
