DEV Community

Intelliflame
Intelliflame

Posted on

Meet BugTraceAI: an open-source, self-hosted agentic pentester

Every security team knows the pattern: you want a proper assessment of an app, but the options are waiting weeks for a consultancy slot, or stitching together a dozen tools and babysitting them for days. Bug bounty hunters know a variant of the same problem — the toolchain is powerful but fragmented, and every judgement call is on you.

We are building a third option. BugTraceAI is an open-source, self-hosted framework for authorized bug bounty and penetration testing. It runs an autonomous agentic pipeline: AI agents plan and prioritize the work, specialist tools and browser validation collect the evidence, and every finding comes out with something you can verify before you file it.

Why "agentic" matters here

Plenty of scanners already automate checks. The gap BugTraceAI aims at is the layer above: deciding what to test, in what order, and what to do with ambiguous signals.

In BugTraceAI, agents drive a six-phase pipeline:

  1. Recon — crawl the target and discover endpoints
  2. Discovery — analyze URLs and collect initial findings
  3. Strategy — consolidate findings and route work to specialists
  4. Exploit — run specialist checks and collect evidence
  5. Validate — verify findings before they reach the report
  6. Report — generate structured, human-readable deliverables

The AI reasons and prioritizes; deterministic security tools (including Go fuzzers and browser-based validation via Playwright) adjudicate. The design principle in one line: AI output is a hypothesis — evidence makes it a finding.

Four components, one ecosystem

  • BugTraceAI-CLI — the autonomous scanner: terminal workspace (TUI), REST API and MCP, multi-agent pipeline with specialist tools
  • BugTraceAI-WEB — browser dashboard with 20+ AI security tools, real-time scan monitoring and a CLI control center
  • BugTraceAI-API — evidence-first API security testing service over REST and MCP
  • BugTraceAI-Launcher — guided deployment: Wizard or AI-assisted setup, local or Docker runtime

Plus BugStore — a deliberately vulnerable practice shop with 32 planted OWASP vulnerabilities, so you can try the whole workflow legally.

Everything is self-hosted and Apache-2.0 licensed. Scans, reports and evidence stay on your infrastructure, and analysis runs with your own LLM provider key.

Does it actually find things?

Three CVEs disclosed so far, found with BugTraceAI:

Product CVE CVSS
Wallos CVE-2026-27479 7.7 High
ZoneMinder CVE-2026-27470 8.8 High
Piwigo CVE-2026-27834 7.2 High

The project was presented on stage at DEF CON 34 (Las Vegas), RootedCON 2026 (Madrid) and HKOSCon 2026 (Hong Kong). Component versions are currently in beta — treat outputs as leads to verify, not verdicts. (That is the point of the evidence-first design.)

Try it

BugTraceAI is built for authorized security testing only. Only test applications you have explicit written permission to test.

Top comments (0)