Autonomous, self-hosted security testing for authorized bug bounty and pentesting
- Proven in the Security Community
- What is BugTraceAI?
- The Ecosystem
- Architecture
- Scanning Pipeline
- Current Public Releases
- Demo Report
- CI/CD Integration Proposal
- Quick Start
- Documentation
- Community & Support
| Product | CVE | CVSS |
|---|---|---|
| Wallos | CVE-2026-27479 | 7.7 High |
| ZoneMinder | CVE-2026-27470 | 8.8 High |
| Piwigo | CVE-2026-27834 | 7.2 High |
- RootedCON 2026, Madrid, Spain
- HKOSCon 2026, Hong Kong
- DEF CON 34, Las Vegas, USA
CLI 4.0.16-beta · interactive terminal workspace
The real TUI has five views: Pipeline, Findings, Agents, Timeline and Logs. Configure the target, crawl limits, Provider/F7 and Auth/F8 from the workspace. The terminal capture uses the built-in offline demo with sample data. Open the CLI screenshot gallery and installation guide.
| WEB · API discovery |
WEB · specialist graph |
| WEB · scan console |
WEB · report explorer |
WEB captures show the scan and reporting interfaces using the BugStore practice target. Report counts in screenshots describe those example sessions.
BugTraceAI combines AI-guided investigation with deterministic security tools. The AI prioritizes and reasons about hypotheses; tools and evidence validate what is real.
This platform is provided for educational and authorized security testing purposes only.
- Only test applications for which you have explicit, written authorization
- AI output may contain inaccuracies, false positives, or false negatives
- It is not a substitute for professional security auditing
- The creators assume no liability for misuse or damage
Always verify findings manually.
BugTraceAI is an opensource, self-hosted framework for bug bounty hunting and penetration testing. It combines autonomous AI agents with real security tools to discover, analyze, exploit, and validate vulnerabilities independently.
Its agents plan and prioritize checks, route work to specialists and collect evidence through the scanning tools and validation stages.
| Principle | Description |
|---|---|
| Privacy-First | Self-hosted scanning and report storage; analysis uses your configured LLM provider |
| Opensource | Apache-2.0 licensed public product repositories |
| Self-Hosted | Scan reports and local services stay on your infrastructure |
| Modular | Use components independently or together |
| Deployment | Local or Docker CLI profiles; full-platform setup through Launcher |
BugTraceAI is composed of 4 independent but interconnected components, plus a dedicated practice target:
| Component | Description | Tech Stack | Repository |
|---|---|---|---|
| BugTraceAI-API | Standalone evidence-first API security testing service over REST and MCP | Python + FastAPI + Docker | BugTraceAI-API |
| BugTraceAI-CLI | Autonomous security scanner with a Textual terminal workspace, REST API and MCP. Multi-agent pipeline with specialist tools and browser validation | Python + Textual + FastAPI + Go + Playwright | BugTraceAI-CLI |
| BugTraceAI-WEB | Web dashboard with 20+ AI security tools, real-time scan monitoring, and CLI control center | React + Express + PostgreSQL | BugTraceAI-WEB |
| BugTraceAI-Launcher | Guided deployment with CLI TUI/API profiles, local or Docker runtime, optional global btai, service management and an optional AI Setup & Repair Assistant | Bash + Python + Docker Compose | BugTraceAI-Launcher |
| MCP Ecosystem | Extensible agent framework using the Model Context Protocol. Includes integrated Kali Linux and ReconFTW agents | MCP + Docker + Python | reconftw-mcp |
| BugStore | Deliberately vulnerable practice target used in demos and walkthroughs. Full-featured shop riddled with 32 planted OWASP vulnerabilities | Python + FastAPI + SQLite | BugTraceAI/BugStore |
Use the CLI TUI locally, its API/MCP for automation, or the Launcher to install independent products or a combination. The WEB connects to the appropriate scanning backend for each engine; API scans use BugTraceAI-API and web scans use the CLI API.
flowchart LR
TUI[CLI terminal workspace] --> Engine[CLI scan engine]
WEB[WEB dashboard] --> REST[CLI REST API]
MCP[CLI MCP clients] --> Engine
REST --> Engine
WEB --> API[BugTraceAI-API]
Engine --> Tools[Specialists and browser validation]
Engine --> Reports[Scan reports]
API --> Reports
The CLI stores scan metadata in SQLite and writes report artifacts to disk. The WEB uses PostgreSQL for its own chats, settings and analysis. The Launcher configures service connections and selected ports. Standalone local TUI setup opens the engine without starting an API server.
See the component documentation for deployment details.
The CLI terminal and WEB display the same six scan phases:
| Phase | Purpose |
|---|---|
| Recon | Crawl the target and discover endpoints |
| Discovery | Analyze URLs and collect initial findings |
| Strategy | Consolidate findings and route work to specialists |
| Exploit | Run specialist checks and collect evidence |
| Validate | Verify findings through the validation stage |
| Report | Generate structured and human-readable deliverables |
Target authentication supports Bearer tokens and login YAML with optional TOTP/2FA. In the TUI, configure it through Auth/F8, separately from the LLM provider's API key in Provider/F7. See the CLI installation guide.
| Component | Version | Highlights |
|---|---|---|
| CLI | 4.0.31-beta | Terminal TUI, web-scanning API/MCP, provider/auth setup and optional global btai |
| WEB | 2.0.32-beta | Browser workspace for both scanning engines and reports |
| API | 1.4.11-beta | Independent API-target engine with REST and MCP |
| Launcher | 3.3.26 | Universal TUI installer, independent module selection and Wizard or AI setup |
Launcher 3.3.26 passed its focused installer tests and clean Lubuntu VM startup checks. Full component installation and a live scan were not completed in this release check. macOS and ARM runtime validation are not included.
Want to see what BugTraceAI produces? Try the live demo or download a real scan report generated against BugStore -- our deliberately vulnerable practice app.
Benchmark note: This demo report was produced with an earlier scanner build. Results are useful for exploring the workflow, but should not be treated as a current performance claim for the latest CLI release until re-run under a versioned benchmark protocol.
The zip includes the full markdown report, validated findings JSON, specialist agent results with WET/DRY traceability, reconnaissance data, and PoC enrichment output.
For CI/CD, automation can call the CLI REST/MCP interfaces for web scans or BugTraceAI-API for API-target testing. Reports and evidence are available for review in the WEB workspace. The diagram below proposes downstream AI review and ticketing integrations; connect them to the selected engine's supported interfaces.
This keeps external automation, autonomous scanning, evidence-rich reporting, human review, and remediation coordination connected without hard-coding deployment-specific service endpoints.
- Terminal workspace: Linux and Python 3.10+ for local installation; some specialist tools also use Docker when scanning.
- API/MCP or full WEB platform: select the relevant profile and runtime in the installer. Docker deployments need Docker Engine, Compose and Git.
- Real scans: configure a supported provider's API key. Opening the TUI or its offline demo does not require starting a scan.
One-liner (recommended):
curl -fsSL https://raw.githubusercontent.com/BugTraceAI/BugTraceAI-Launcher/main/install.sh | bashOr clone and run manually:
git clone https://github.com/BugTraceAI/BugTraceAI-Launcher.git ~/bugtraceai-launcher
~/bugtraceai-launcher/launcher.shFrom this ecosystem checkout, ./install.sh opens the same universal menu
with full suggested. Component ./install.sh entry points suggest their
own product in that menu; they do not deploy a profile without your review.
Enter and verify a provider API key on the first screen, then choose
Install with Wizard or Install with AI. Both stay in the TUI. Wizard
supports every module combination. AI setup uses provider tokens and currently
supports API-only or the full WEB + CLI + API selection, including the CLI TUI,
with OpenRouter or Anthropic. Use Wizard for other combinations and for Z.ai.
The review shows selected modules, runtime, ports and optional WEB toolboxes.
Terminal profiles can register a global btai command.
If you use Codex, Claude Code, Cursor or another local terminal agent, give it this prompt:
Help me install BugTraceAI using the official universal Launcher.
First read:
https://github.com/BugTraceAI/BugTraceAI#readme
https://github.com/BugTraceAI/BugTraceAI-Launcher#readme
Follow those instructions using the official installer:
https://raw.githubusercontent.com/BugTraceAI/BugTraceAI-Launcher/main/install.sh
Ask which independent modules I want: BugTraceAI-WEB, BugTraceAI-CLI,
BugTraceAI-API, or a combination. Install only the modules I choose. Let me
choose Wizard or the built-in AI installer when my selection is supported;
use Wizard for other combinations.
Preserve any existing installation, configuration and data. Run the
Launcher in my local interactive terminal. I will enter and verify the
provider API key there, choose ports and review the plan before installation.
Keep credentials out of chat and logs. Do not start a scan.
Verify the selected services on their configured ports. If I enable the
global btai command, check it from a fresh shell. Report the installation
location, launch commands, checks completed and any checks still pending.
| Profile | Installed products | Runtime |
|---|---|---|
terminal |
CLI terminal TUI | Local Python or Docker |
web |
WEB is preselected; add either or both scanning engines if needed | Docker |
full |
WEB + both scanning engines + CLI terminal TUI | Docker |
server |
CLI web-scanning API/MCP | Local Python or Docker |
terminal-server |
CLI TUI + web-scanning API/MCP, without WEB | Local Python or Docker |
api |
Independent BugTraceAI-API target engine, REST + MCP | Docker |
For direct component installation, use each checkout's explicit
scripts/install-runtime.sh backend or the documented Python/Compose commands. Follow
INSTALLATION.md; a bare WEB docker compose up is not a
complete configuration step.
Component entry points suggest their own module. A suggestion only sets the initial checkboxes; review the exact modules before installation.
Full documentation is available in the Project Wiki:
- Overview -- What BugTraceAI is and who it's for
- Architecture -- System design and communication protocols
- BugTraceAI-CLI -- Autonomous scanner documentation
- BugTraceAI-WEB -- Web dashboard documentation
- BugTraceAI-API -- REST/MCP API-security service, evidence artifacts, and deployment guidance
- BugTraceAI-API on DeepWiki -- AI-powered codebase documentation and architecture exploration
- BugTraceAI-Launcher -- Deployment guide
- CLI API Reference -- CLI REST API and WebSocket endpoints
- Getting Started -- Installation and first scan
| Resource | Link |
|---|---|
| Website | bugtraceai.com |
| Wiki | GitHub Wiki |
| DeepWiki | AI-powered docs |
| Issues | GitHub Issues |
| Discord | Join the BugTraceAI community |
| @yz9yt |
We welcome contributions: bug reports, feature requests, PRs, documentation improvements, and community tools. Open an issue on the respective repository to get started.
Apache License 2.0 — BugTraceAI-owned material is free to use, modify, and distribute under the terms of the Apache License, Version 2.0.
See LICENSE file in each repository.
BugTraceAI -- Build your own self-hosted pentesting platform.
If BugTraceAI helps your authorized security research, consider giving the project a star or joining the community on Discord.
Albert C (@yz9yt)