EveryDev.ai
Subscribe
Home
Developers

3,795+ AI companies

  • Radar
  • Trending
AI Tools by Topic
  • AI Coding Assistants
  • Agent Frameworks
  • MCP Servers
  • AI Prompt Tools
  • Vibe Coding Tools
  • AI Design Tools
  • AI Database Tools
  • AI Website Builders
  • AI Testing Tools
  • LLM Evaluations
Follow Us
  • X / Twitter
  • LinkedIn
  • Reddit
  • Discord
  • Threads
  • Bluesky
  • Mastodon
  • YouTube
  • GitHub
  • Instagram
Get Started
  • Users
  • Rate Tools
  • About
  • Editorial Standards
  • Corrections & Disclosures
  • Community Guidelines
  • Advertise
  • Contact Us
  • Newsletter
  • Submit a Tool
  • Start a Discussion
  • Write A Blog
  • Share A Build
  • Terms of Service
  • Privacy Policy
Explore with AI
  • ChatGPT
  • Gemini
  • Claude
  • Grok
  • Perplexity
Agent Experience
  • llms.txt
Theme
With AI, Everyone is a Dev. EveryDev.ai © 2026
    1. Home
    2. Developers
    3. AgentGG

    AgentGG

    AgentGG is an agentic static application security testing (SAST) project that uses AI agents to read source code, follow imports and call graphs, and validate vulnerabilities rather than merely pattern-match. Its open-source CLI and hosted platform scan repositories and pull requests, while its processing layer can turn a customer's past security issues and product context into custom security agents.

    Visit Website

    At a Glance

    1Tool Listed
    4Products
    10Capabilities
    Discussions
    Focus Areas
    Application Security
    Code Security
    Security Testing
    Connect
    Latest News
    AgentGG repository added live validation support to the Ollama provider.Oct 8, 2026
    agentgg npm package reached version 0.1.26.Oct 7, 2026
    Markets
    • Individual developers
    • Open-source maintainers and projects
    • Application security and security engineering teams
    • DevSecOps and SAST platform teams
    • +2 more

    AI Tools by AgentGG

    (1)
    View AgentGG
    AgentGG tool icon

    AgentGG

    Agentic SAST Security Scanner

    App SecurityCode SecuritySecurity Testing

    Discussions

    No discussions yet

    Be the first to start a discussion about AgentGG

    Latest News

    10/08/2026

    AgentGG repository added live validation support to the Ollama provider.

    github.com
    10/07/2026

    agentgg npm package reached version 0.1.26.

    npmjs.com
    09/24/2026

    AgentGG published Redash advisories for alert-update authorization and enabled-by-default custom JavaScript visualizations.

    github.com
    09/16/2026

    AgentGG published a Valhalla advisory for unbounded exclude_polygons vertex counts enabling CPU/memory denial of service.

    github.com

    Products & Services

    4
    agentgg CLI
    May 2026 public repository; npm 0.1.26 published October 7, 2026

    Apache-2.0 open-source agentic SAST scanner for whole repositories or git diffs/pull requests. It performs recon, runs readable markdown security agents, validates findings, produces markdown reports, supports resumable scans, and includes status/view commands.

    AgentGG platform
    2026

    Hosted version of the scanner. It connects repositories through GitHub, scans every pull request or runs full-repository baselines, returns GitHub checks with inline comments, and provides a team dashboard for validated, CVSS-scored, deduplicated findings.

    AgentGG security-agent catalog
    2026

    A public catalog of more than 100 open-source security agents, each represented as a readable markdown file describing the bug class, scope, and evidence requirements.

    Custom agents / processing service
    2026

    A guided platform service that turns past security reports, pentest findings, incident write-ups, product context, and business logic into generalized, tested agents that run across an organization's repositories and changes.

    Market Position

    AgentGG positions itself against traditional pattern-matching SAST and generic AI scanners by using white-box, inspectable agents that investigate surrounding code, follow call graphs, confirm findings, and run a validation pass to reduce false positives. Its differentiators are an open-source engine and agent catalog, reproducible readable methodology, PR-native workflow, and custom agents learned from a customer's own incidents. Comparable categories include Semgrep, CodeQL, Snyk Code, and other AI-assisted code-security scanners, but AgentGG emphasizes transparent agent prompts and adaptable incident-derived coverage.

    Leadership

    Founders

    PG

    Philip Garabandic

    Security engineer at TikTok, with a Master of Science in Computer Science from the Georgia Institute of Technology; GitHub profile PhilipPhil links directly to agentgg.dev and LinkedIn profile /in/garabandic. He is an initial public repository co-author and the author of AgentGG security-research articles.

    GG

    Gracia Gu

    Software engineer at Amazon/Amazon Web Services, with Georgia Institute of Technology affiliation according to LinkedIn search results. GitHub profile gracia-gu pins the AgentGG repository and is the other co-author of the initial public commit.

    Founding Story

    AgentGG began as an open-source effort to make AI-assisted vulnerability research reproducible and useful in normal engineering workflows. The initial vision was a white-box, CI-ready scanner whose readable agents investigate code and confirm findings, with the same engine available locally through the CLI and as a hosted service.

    Business Model

    Revenue Model

    The open-source CLI/engine is free under Apache 2.0 and can be run with the customer's own model credentials. The hosted platform monetizes scans through usage-based pricing, a monthly team subscription, credit-based overage, and custom enterprise contracts; custom-agent work is offered as a guided platform service.

    Pricing Tiers

    Solo
    No monthly fee; usage-based

    For individual developers; unlimited pull-request and full-repository scans, with usage-based pricing and no monthly commitment.

    Team
    $200/month

    Includes 500 pull-request scans and 50 full-repository scans per month, up to 10 members, customer's own model key, and $1 per extra scan from credit balance.

    Enterprise
    Custom pricing

    Custom scan volume and seats, SSO and directory sync, deployment in the customer's cloud or network, custom integrations, and priority support with an SLA.

    Target Markets

    Industries & Segments
    • Individual developers
    • Open-source maintainers and projects
    • Application security and security engineering teams
    • DevSecOps and SAST platform teams
    • Engineering teams managing multiple repositories
    • Enterprises needing private deployment, SSO, directory sync, and custom security workflows
    Use Cases
    • AI-assisted vulnerability research in open-source projects
    • SAST and AppSec review of repositories
    • Security scanning of every pull request before merge
    • Full-repository baseline scans
    • Turning prior vulnerabilities and pentest findings into repeatable detectors
    • Local or CI security scanning with a customer's own model keys

    History & Milestones

    May 19, 2026

    Initial public commit for the agentgg repository, co-authored by Philip Garabandic and Gracia Gu.

    May 28, 2026

    AgentGG published its first four listed security advisories (AGG-001 through AGG-004), covering authentication-bypass issues in openclaw.

    June-August 2026

    The project expanded its public advisory record across openclaw, MapServer, Directus, QGIS, GeoTools, and ZOO-Project, while the open-source CLI and 100+ agent catalog continued to develop.

    September 24, 2026

    AgentGG listed two Redash advisories, including an authorization issue in alert updates and enabled-by-default custom JavaScript visualizations.

    October 7, 2026

    The agentgg npm package reached version 0.1.26; the GitHub repository README describes the CLI as beta.

    Key Capabilities

    10
    White-box AI investigation of source code, imports, and call graphs
    Finding confirmation and a second validation pass before reporting
    Recon pass that briefs agents on the repository
    Whole-repository and pull-request/diff scanning
    Readable, versioned markdown agents that users can inspect and contribute
    Resumable scans with status, revalidation, and local findings viewer

    Integrations & Partnerships

    Platform Integrations

    • GitHub App and GitHub pull-request checks with inline comments
    • Direct scanning of ZIP archives and git URLs
    • CLI installation through npm, requiring Node.js 20+
    • Anthropic, OpenAI, AWS Bedrock, Google Vertex AI, OpenRouter, and local Ollama providers
    • GitHub Actions/CI workflow support documented for pull-request scanning

    Connect

    Website
    agentgg.dev/
    GitHub
    agentgg-dev
    X / Twitter
    AgentGG_dev
    LinkedIn
    agentgg-dev
    Mastodon
    youtube.com/@AgentGG_dev

    AI Topics

    3

    AgentGG focuses on these topics:

    Application Security(1)
    Code Security(1)
    Security Testing(1)
    Back to all developersSuggest an edit