Abstract
Open Kritt is an open-source Cybersecurity & Ethical Hacking project. Open-source, self-hosted AI vulnerability research tool that orchestrates agents to find and validate security issues in code. An open-source, self-hosted security and vulnerability research platform that turns focused AI analysis into de-duplicated, ranked findings with configurable validation and enrichment. It is built using JavaScript. Key capabilities include: Build workflows — chain focused prompts into reusable security research playbooks; Run scans — analyze remote or local repositories and their dependencies with Codex,; Verify findings — use post-scripts to validate issues, build proofs of concept, and. The complete source code is publicly available on GitHub under the GNU Affero General Public License v3.0, making it a useful reference for students building a Cybersecurity & Ethical Hacking mini project or final-year project.
1. Introduction
An open-source, self-hosted security and vulnerability research platform that turns focused AI analysis into de-duplicated, ranked findings with configurable validation and enrichment.
Pointing a model at an entire repository and asking it to find vulnerabilities rarely works well. open·kritt takes a focused approach: break the research into small, well-defined tasks, run them across AI agents in parallel, and combine their output into findings you can validate and prioritize.
It is built for security researchers and security-minded developers who want control over their prompts, workflows, model providers, and infrastructure.
2. Objective
Open-source, self-hosted AI vulnerability research tool that orchestrates agents to find and validate security issues in code.
This project demonstrates how JavaScript can be applied to a real-world Cybersecurity & Ethical Hacking problem.
3. Key Features / Modules
- Build workflows — chain focused prompts into reusable security research playbooks.
- Run scans — analyze remote or local repositories and their dependencies with Codex,
- Verify findings — use post-scripts to validate issues, build proofs of concept, and
- Export scan results — package canonical findings, structured data, post-processing
- Prioritize results — apply custom severity rankers, a consistent finding schema,
- Bring your own model access — use a Codex login or connect through OpenAI,
4. Technology Stack
5. System Requirements
General requirements for this technology stack — check the README for exact versions.
- Node.js (LTS) and npm
- A modern web browser
- VS Code or any code editor
- Git (to clone the repository)
6. Installation & Setup
git clone https://github.com/Kritt-ai/open-kritt.git
cd open-krittgit clone https://github.com/Kritt-ai/open-kritt
cd open-kritt
./kritt setup
./kritt start./kritt-headlessFull setup instructions are in the project README.
7. Future Enhancements
Suggested extensions you can add to make this your own project.
- Add logging and alert notifications (email / Telegram)
- Write a threat model document for the tool
- Package it with Docker for safe lab testing
8. Viva / Review Questions
Common questions examiners ask for projects in this domain.
- Which threat or attack does this project defend against?
- What detection or protection technique is used and what are its limits?
- How are false positives and false negatives handled?
- Which cryptographic algorithms or security standards are involved?
- What legal and ethical rules apply when testing a tool like this?
9. Source Code & License
This project is developed by Kritt-ai and published on GitHub under the GNU Affero General Public License v3.0. Please follow the license terms and credit the original author when you use or modify this code.
Want to build this as your internship project?
Work on a Cybersecurity & Ethical Hacking project like this with mentor guidance, weekly reviews and an internship certificate from Training Trains, Erode — online or offline.
Apply for Cybersecurity & Ethical Hacking Internship