Agentgg

Open source agentic SAST. The engine behind hundreds of disclosed zero-days. 100+ AI security agents, any repo or PR diff, bring your own model.

Cybersecurity & Ethical HackingTypeScriptApache-2.0

Abstract

Agentgg is an open-source Cybersecurity & Ethical Hacking project. Open source agentic SAST. The engine behind hundreds of disclosed zero-days. 100+ AI security agents, any repo or PR diff, bring your own model. agentgg is an agentic SAST scanner. Its agents read your code and reason about it — they follow imports, check the call graph, and confirm a finding before they report it, instead of pattern-matching the way traditional SAST does. It is built using TypeScript. The complete source code is publicly available on GitHub under the Apache License 2.0, making it a useful reference for students building a Cybersecurity & Ethical Hacking mini project or final-year project.

1. Introduction

agentgg is an agentic SAST scanner. Its agents read your code and reason about it — they follow imports, check the call graph, and confirm a finding before they report it, instead of pattern-matching the way traditional SAST does. Run it over a whole repository, or over a git diff for pull request review. Every scan opens with a fast recon pass that briefs the agents on what the project is, and an interrupted scan resumes on re-run.

A scan writes summary.md and one markdown file per finding into ./out/, plus a state/ directory that makes resume, status, and revalidate work. Re-run with the same -o and unchanged files are skipped; a different -o starts fresh.

2. Objective

Open source agentic SAST. The engine behind hundreds of disclosed zero-days. 100+ AI security agents, any repo or PR diff, bring your own model.

This project demonstrates how TypeScript can be applied to a real-world Cybersecurity & Ethical Hacking problem.

4. Technology Stack

TypeScript

5. System Requirements

General requirements for this technology stack — check the README for exact versions.

  • Node.js (LTS) and npm / yarn / pnpm
  • VS Code or any code editor
  • Git (to clone the repository)

6. Installation & Setup

git clone https://github.com/agentgg-dev/agentgg.git
cd agentgg
npm install -g agentgg
agentgg init                                            # one-time: pick a provider, paste a key
agentgg scan ./src -o ./out                             # scan everything
agentgg scan ./src --diff origin/main...HEAD -o ./out   # PR-style: scan only what changed
agentgg status ./out                                    # what got found and validated
agentgg view ./out                                      # browse findings in a local web UI

Full setup instructions are in the project README.

7. Future Enhancements

Suggested extensions you can add to make this your own project.

  • Add logging and alert notifications (email / Telegram)
  • Write a threat model document for the tool
  • Package it with Docker for safe lab testing

8. Viva / Review Questions

Common questions examiners ask for projects in this domain.

  1. Which threat or attack does this project defend against?
  2. What detection or protection technique is used and what are its limits?
  3. How are false positives and false negatives handled?
  4. Which cryptographic algorithms or security standards are involved?
  5. What legal and ethical rules apply when testing a tool like this?

9. Source Code & License

This project is developed by agentgg-dev and published on GitHub under the Apache License 2.0. Please follow the license terms and credit the original author when you use or modify this code.

Want to build this as your internship project?

Work on a Cybersecurity & Ethical Hacking project like this with mentor guidance, weekly reviews and an internship certificate from Training Trains, Erode — online or offline.

Apply for Cybersecurity & Ethical Hacking Internship