Abstract
Agentgg is an open-source Cybersecurity & Ethical Hacking project. Open source agentic SAST. The engine behind hundreds of disclosed zero-days. 100+ AI security agents, any repo or PR diff, bring your own model. agentgg is an agentic SAST scanner. Its agents read your code and reason about it — they follow imports, check the call graph, and confirm a finding before they report it, instead of pattern-matching the way traditional SAST does. It is built using TypeScript. The complete source code is publicly available on GitHub under the Apache License 2.0, making it a useful reference for students building a Cybersecurity & Ethical Hacking mini project or final-year project.
1. Introduction
agentgg is an agentic SAST scanner. Its agents read your code and reason about it — they follow imports, check the call graph, and confirm a finding before they report it, instead of pattern-matching the way traditional SAST does. Run it over a whole repository, or over a git diff for pull request review. Every scan opens with a fast recon pass that briefs the agents on what the project is, and an interrupted scan resumes on re-run.
A scan writes summary.md and one markdown file per finding into ./out/, plus a state/ directory that makes resume, status, and revalidate work. Re-run with the same -o and unchanged files are skipped; a different -o starts fresh.
2. Objective
Open source agentic SAST. The engine behind hundreds of disclosed zero-days. 100+ AI security agents, any repo or PR diff, bring your own model.
This project demonstrates how TypeScript can be applied to a real-world Cybersecurity & Ethical Hacking problem.
4. Technology Stack
5. System Requirements
General requirements for this technology stack — check the README for exact versions.
- Node.js (LTS) and npm / yarn / pnpm
- VS Code or any code editor
- Git (to clone the repository)
6. Installation & Setup
git clone https://github.com/agentgg-dev/agentgg.git
cd agentggnpm install -g agentggagentgg init # one-time: pick a provider, paste a key
agentgg scan ./src -o ./out # scan everything
agentgg scan ./src --diff origin/main...HEAD -o ./out # PR-style: scan only what changed
agentgg status ./out # what got found and validated
agentgg view ./out # browse findings in a local web UIFull setup instructions are in the project README.
7. Future Enhancements
Suggested extensions you can add to make this your own project.
- Add logging and alert notifications (email / Telegram)
- Write a threat model document for the tool
- Package it with Docker for safe lab testing
8. Viva / Review Questions
Common questions examiners ask for projects in this domain.
- Which threat or attack does this project defend against?
- What detection or protection technique is used and what are its limits?
- How are false positives and false negatives handled?
- Which cryptographic algorithms or security standards are involved?
- What legal and ethical rules apply when testing a tool like this?
9. Source Code & License
This project is developed by agentgg-dev and published on GitHub under the Apache License 2.0. Please follow the license terms and credit the original author when you use or modify this code.
Want to build this as your internship project?
Work on a Cybersecurity & Ethical Hacking project like this with mentor guidance, weekly reviews and an internship certificate from Training Trains, Erode — online or offline.
Apply for Cybersecurity & Ethical Hacking Internship