# AgentGG

> Open-source agentic SAST scanner whose AI agents find, validate, and score vulnerabilities across repositories and pull requests.

AgentGG is an agentic static application security testing (SAST) tool from agentgg-dev. Its agents read code, follow imports, and confirm findings before reporting them. It is available as an Apache 2.0 CLI and as a hosted platform that scans repositories and pull requests. The GitHub README marks the CLI as in beta.

## What It Is

AgentGG is a white-box security scanner that uses AI agents instead of pattern-matching rules. Each agent is a readable markdown file with YAML frontmatter that declares where to look and an optional precondition, plus a prompt body describing the bug class and what counts as proof. The CLI can scan a whole repository or only a git diff for pull request review, and every scan begins with a recon pass that briefs the agents on what the project is. Interrupted scans resume when re-run with the same output directory.

## How a Scan Works

After running `agentgg init` to choose a provider, users run `agentgg scan` on a directory, optionally with a diff range. Output is a `summary.md` plus one markdown file per finding, along with a state directory that supports resume, status, and revalidation. A local web viewer lets users browse findings. Findings go through a second validation pass that assigns a CVSS severity. The agent catalog of 100+ open-source agents downloads automatically on first scan, and `agentgg create` turns a past incident report into a reusable agent.

## Hosted Platform and Custom Agents

The hosted platform runs the same scanner as a service. Users install the GitHub App, pick repositories, or scan a ZIP or git URL. Pull request scans return as a GitHub check run with inline comments on diff lines. Full-repo baseline scans run on demand. A dashboard offers deduplicated, CVSS-scored findings with roles, workspaces, and filters by severity, verdict, or agent. A guided custom-agent service builds agents from a team's past security reports, pentest findings, and product context.

## Model Providers and Disclosures

The CLI works with Anthropic, OpenAI, OpenRouter, AWS Bedrock, Google Vertex AI, or a local Ollama setup, and requires Node.js 20+. The vendor says its agents have found hundreds of previously unknown vulnerabilities in open-source projects, reported privately to maintainers and published after fixes ship. Its advisories page lists examples.

## Features
- Agentic SAST that reads code, follows imports, and checks the call graph
- Full-repository and git diff (pull request) scans
- Recon pass before each scan
- Resumable scans
- Second validation pass with CVSS severity scoring
- 100+ open-source agents catalog
- Agents defined as markdown files with YAML frontmatter
- Create agents from past incident reports
- Local web viewer for findings
- GitHub App with PR check runs and inline comments
- Dashboard with roles, workspaces, and filters
- Custom agents service built from security history
- Bring your own model provider including local Ollama

## Integrations
GitHub, Anthropic, OpenAI, OpenRouter, AWS Bedrock, Google Vertex AI, Ollama

## Platforms
CLI, WEB

## Pricing
Open Source, Free tier available

## Links
- Website: https://agentgg.dev/
- Documentation: https://docs.agentgg.dev/
- Repository: https://github.com/agentgg-dev/agentgg
- EveryDev.ai: https://www.everydev.ai/tools/agentgg
