Open Kritt is an open-source platform for building AI-powered security research workflows. Orchestrate LLMs, tools, and custom agents into reusable pipelines for vulnerability research, code analysis, and automation. Used internally to discover more than 60 High & Critical security vulnerabilities, Open Kritt is now available for the community to build, extend, and share workflows.
Hi Product Hunt! 👋
We're excited to finally share **Open-Kritt** with the community.
Over the past nine months, we've been building an internal platform to orchestrate AI workflows for security research. During that time, it helped us discover more than 60 High & Critical vulnerabilities across bug bounty programs and audit competitions.
As the platform matured, we realized the infrastructure itself could be valuable to other researchers. Instead of keeping it internal, we decided to open source it.
Open-Kritt is designed to help you build AI-powered workflows by combining LLMs, tools, custom code, branching logic, and reusable components into flexible pipelines.
This launch is just the beginning. We've open-sourced the platform and are releasing example workflows today, with many more workflows and improvements planned over time.
We'd love to hear what you think! Whether it's feedback, feature requests, ideas for workflows, or contributions - we're excited to build Open-Kritt together with the community.
Thanks for checking it out!
Most existing AI tools work well when you're analyzing a closed-source codebase that only your team has access to. But bug bounty targets, specifically the open source ones, makes things much harder. Everyone has access to the same code and the same AI models, so the obvious, low-hanging fruit gets found very quickly.
We needed a different approach - one that goes beyond simple prompting and enables more structured, iterative workflows capable of uncovering deeper, more complex vulnerabilities :)
Report
@gabi_controlz Really enjoyed your explanation. The shift from "better prompts" to structured security research workflows feels like a much bigger positioning advantage than just another AI security tool.
I had a couple of thoughts on where that narrative could become even stronger as the space matures. If you're open to it, what's the best email to send them to?
Report
Reviews
No reviews yetBe the first to leave a review for kritt.ai
kritt.ai
Really like the open-source direction here. Curious—what kind of security research workflow made you realize existing AI tooling wasn't enough?
@aryan787544 Doing bug bounties.
Most existing AI tools work well when you're analyzing a closed-source codebase that only your team has access to. But bug bounty targets, specifically the open source ones, makes things much harder. Everyone has access to the same code and the same AI models, so the obvious, low-hanging fruit gets found very quickly.
We needed a different approach - one that goes beyond simple prompting and enables more structured, iterative workflows capable of uncovering deeper, more complex vulnerabilities :)
@gabi_controlz Really enjoyed your explanation. The shift from "better prompts" to structured security research workflows feels like a much bigger positioning advantage than just another AI security tool.
I had a couple of thoughts on where that narrative could become even stronger as the space matures. If you're open to it, what's the best email to send them to?