AgentGG
AgentGG is an agentic static application security testing (SAST) project that uses AI agents to read source code, follow imports and call graphs, and validate vulnerabilities rather than merely pattern-match. Its open-source CLI and hosted platform scan repositories and pull requests, while its processing layer can turn a customer's past security issues and product context into custom security agents.
At a Glance
- Individual developers
- Open-source maintainers and projects
- Application security and security engineering teams
- DevSecOps and SAST platform teams
- +2 more
AI Tools by AgentGG
(1)AgentGG
Agentic SAST Security Scanner
Discussions
No discussions yet
Be the first to start a discussion about AgentGG
Latest News
AgentGG repository added live validation support to the Ollama provider.
agentgg npm package reached version 0.1.26.
AgentGG published Redash advisories for alert-update authorization and enabled-by-default custom JavaScript visualizations.
AgentGG published a Valhalla advisory for unbounded exclude_polygons vertex counts enabling CPU/memory denial of service.
Products & Services
Apache-2.0 open-source agentic SAST scanner for whole repositories or git diffs/pull requests. It performs recon, runs readable markdown security agents, validates findings, produces markdown reports, supports resumable scans, and includes status/view commands.
Hosted version of the scanner. It connects repositories through GitHub, scans every pull request or runs full-repository baselines, returns GitHub checks with inline comments, and provides a team dashboard for validated, CVSS-scored, deduplicated findings.
A public catalog of more than 100 open-source security agents, each represented as a readable markdown file describing the bug class, scope, and evidence requirements.
A guided platform service that turns past security reports, pentest findings, incident write-ups, product context, and business logic into generalized, tested agents that run across an organization's repositories and changes.
Market Position
AgentGG positions itself against traditional pattern-matching SAST and generic AI scanners by using white-box, inspectable agents that investigate surrounding code, follow call graphs, confirm findings, and run a validation pass to reduce false positives. Its differentiators are an open-source engine and agent catalog, reproducible readable methodology, PR-native workflow, and custom agents learned from a customer's own incidents. Comparable categories include Semgrep, CodeQL, Snyk Code, and other AI-assisted code-security scanners, but AgentGG emphasizes transparent agent prompts and adaptable incident-derived coverage.
Leadership
Founders
Philip Garabandic
Security engineer at TikTok, with a Master of Science in Computer Science from the Georgia Institute of Technology; GitHub profile PhilipPhil links directly to agentgg.dev and LinkedIn profile /in/garabandic. He is an initial public repository co-author and the author of AgentGG security-research articles.
Gracia Gu
Software engineer at Amazon/Amazon Web Services, with Georgia Institute of Technology affiliation according to LinkedIn search results. GitHub profile gracia-gu pins the AgentGG repository and is the other co-author of the initial public commit.
Founding Story
AgentGG began as an open-source effort to make AI-assisted vulnerability research reproducible and useful in normal engineering workflows. The initial vision was a white-box, CI-ready scanner whose readable agents investigate code and confirm findings, with the same engine available locally through the CLI and as a hosted service.
Business Model
Revenue Model
The open-source CLI/engine is free under Apache 2.0 and can be run with the customer's own model credentials. The hosted platform monetizes scans through usage-based pricing, a monthly team subscription, credit-based overage, and custom enterprise contracts; custom-agent work is offered as a guided platform service.
Pricing Tiers
For individual developers; unlimited pull-request and full-repository scans, with usage-based pricing and no monthly commitment.
Includes 500 pull-request scans and 50 full-repository scans per month, up to 10 members, customer's own model key, and $1 per extra scan from credit balance.
Custom scan volume and seats, SSO and directory sync, deployment in the customer's cloud or network, custom integrations, and priority support with an SLA.
Target Markets
- Individual developers
- Open-source maintainers and projects
- Application security and security engineering teams
- DevSecOps and SAST platform teams
- Engineering teams managing multiple repositories
- Enterprises needing private deployment, SSO, directory sync, and custom security workflows
- AI-assisted vulnerability research in open-source projects
- SAST and AppSec review of repositories
- Security scanning of every pull request before merge
- Full-repository baseline scans
- Turning prior vulnerabilities and pentest findings into repeatable detectors
- Local or CI security scanning with a customer's own model keys