AgentGG
Open-source agentic SAST scanner whose AI agents find, validate, and score vulnerabilities across repositories and pull requests.
At a Glance
Apache 2.0 licensed CLI engine; bring your own model keys (external provider costs apply).
Engagement
Available On
Alternatives
Listed Oct 2026
About AgentGG
AgentGG is an agentic static application security testing (SAST) tool from agentgg-dev. Its agents read code, follow imports, and confirm findings before reporting them. It is available as an Apache 2.0 CLI and as a hosted platform that scans repositories and pull requests. The GitHub README marks the CLI as in beta.
What It Is
AgentGG is a white-box security scanner that uses AI agents instead of pattern-matching rules. Each agent is a readable markdown file with YAML frontmatter that declares where to look and an optional precondition, plus a prompt body describing the bug class and what counts as proof. The CLI can scan a whole repository or only a git diff for pull request review, and every scan begins with a recon pass that briefs the agents on what the project is. Interrupted scans resume when re-run with the same output directory.
How a Scan Works
After running agentgg init to choose a provider, users run agentgg scan on a directory, optionally with a diff range. Output is a summary.md plus one markdown file per finding, along with a state directory that supports resume, status, and revalidation. A local web viewer lets users browse findings. Findings go through a second validation pass that assigns a CVSS severity. The agent catalog of 100+ open-source agents downloads automatically on first scan, and agentgg create turns a past incident report into a reusable agent.
Hosted Platform and Custom Agents
The hosted platform runs the same scanner as a service. Users install the GitHub App, pick repositories, or scan a ZIP or git URL. Pull request scans return as a GitHub check run with inline comments on diff lines. Full-repo baseline scans run on demand. A dashboard offers deduplicated, CVSS-scored findings with roles, workspaces, and filters by severity, verdict, or agent. A guided custom-agent service builds agents from a team's past security reports, pentest findings, and product context.
Model Providers and Disclosures
The CLI works with Anthropic, OpenAI, OpenRouter, AWS Bedrock, Google Vertex AI, or a local Ollama setup, and requires Node.js 20+. The vendor says its agents have found hundreds of previously unknown vulnerabilities in open-source projects, reported privately to maintainers and published after fixes ship. Its advisories page lists examples.
Community Discussions
Be the first to start a conversation about AgentGG
Share your experience with AgentGG, ask questions, or help others learn from your insights.
Pricing
Open Source CLI
Apache 2.0 licensed CLI engine; bring your own model keys (external provider costs apply).
- Apache 2.0 CLI with over 100 open source agents
- Bring your own model keys (Anthropic, OpenAI, OpenRouter, Bedrock, Vertex AI) or run local with Ollama
- Install via npm install -g agentgg
Solo
Pay as you go for individual developers; no monthly fee. Per-scan rate not published.
- Unlimited pull request scans with no monthly cap
- Unlimited full repository scans
- Usage-based pricing with no monthly commitment
- Continuous monitoring through the GitHub App
- Findings ranked by severity with triage
Team
For teams scanning across several repositories.
- 500 pull request scans and 50 full repository scans included each month
- Up to 10 members on one plan
- Your own model key so token cost stays on your provider account
- $1 per extra scan taken from your credit balance
- Continuous monitoring through the GitHub App
- Findings ranked by severity with triage
Enterprise
Custom pricing for organisations needing their own security and procurement rules.
- Everything in Team
- Scan volume and seats set to your usage, no fixed quota
- Single sign-on and directory sync
- Deployment in your own cloud or inside your network
- Custom integrations
- Priority support with an agreed SLA
Capabilities
Key Features
- Agentic SAST that reads code, follows imports, and checks the call graph
- Full-repository and git diff (pull request) scans
- Recon pass before each scan
- Resumable scans
- Second validation pass with CVSS severity scoring
- 100+ open-source agents catalog
- Agents defined as markdown files with YAML frontmatter
- Create agents from past incident reports
- Local web viewer for findings
- GitHub App with PR check runs and inline comments
- Dashboard with roles, workspaces, and filters
- Custom agents service built from security history
- Bring your own model provider including local Ollama
