Skip to content

Latest commit

 

History

230 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

BugTraceAI

BugTraceAI

Autonomous, self-hosted security testing for authorized bug bounty and pentesting

Website Wiki DeepWiki Live Demo Discord Demo Report License API Version CLI Version WEB Version Launcher Version

Python React FastAPI Go Playwright Docker

Watch the BugTraceAI demo on YouTube Explore the live demo Explore the BugStore practice target Star BugTraceAI on GitHub Join the BugTraceAI Discord

Watch the BugTraceAI DEF CON 34 product demo on YouTube

Jump To


Proven in the Security Community

CVEs Disclosed

Product CVE CVSS
Wallos CVE-2026-27479 7.7 High
ZoneMinder CVE-2026-27470 8.8 High
Piwigo CVE-2026-27834 7.2 High

Presented On Stage

See It Working

CLI 4.0.16-beta · interactive terminal workspace

BugTraceAI terminal workspace with Recon, Discovery, Strategy, Exploit, Validate and Report

The real TUI has five views: Pipeline, Findings, Agents, Timeline and Logs. Configure the target, crawl limits, Provider/F7 and Auth/F8 from the workspace. The terminal capture uses the built-in offline demo with sample data. Open the CLI screenshot gallery and installation guide.

WEB · API discovery
BugTraceAI WEB API discovery workspace
WEB · specialist graph
BugTraceAI WEB graph showing scan phases and specialist activity
WEB · scan console
BugTraceAI WEB target controls, scan pipeline and event console
WEB · report explorer
BugTraceAI WEB findings explorer displaying a practice-target report

WEB captures show the scan and reporting interfaces using the BugStore practice target. Report counts in screenshots describe those example sessions.

BugTraceAI combines AI-guided investigation with deterministic security tools. The AI prioritizes and reasons about hypotheses; tools and evidence validate what is real.

Disclaimer

This platform is provided for educational and authorized security testing purposes only.

  • Only test applications for which you have explicit, written authorization
  • AI output may contain inaccuracies, false positives, or false negatives
  • It is not a substitute for professional security auditing
  • The creators assume no liability for misuse or damage

Always verify findings manually.


What is BugTraceAI?

BugTraceAI is an opensource, self-hosted framework for bug bounty hunting and penetration testing. It combines autonomous AI agents with real security tools to discover, analyze, exploit, and validate vulnerabilities independently.

Its agents plan and prioritize checks, route work to specialists and collect evidence through the scanning tools and validation stages.

Core Principles

Principle Description
Privacy-First Self-hosted scanning and report storage; analysis uses your configured LLM provider
Opensource Apache-2.0 licensed public product repositories
Self-Hosted Scan reports and local services stay on your infrastructure
Modular Use components independently or together
Deployment Local or Docker CLI profiles; full-platform setup through Launcher

The Ecosystem

BugTraceAI is composed of 4 independent but interconnected components, plus a dedicated practice target:

Component Description Tech Stack Repository
BugTraceAI-API Standalone evidence-first API security testing service over REST and MCP Python + FastAPI + Docker BugTraceAI-API
BugTraceAI-CLI Autonomous security scanner with a Textual terminal workspace, REST API and MCP. Multi-agent pipeline with specialist tools and browser validation Python + Textual + FastAPI + Go + Playwright BugTraceAI-CLI
BugTraceAI-WEB Web dashboard with 20+ AI security tools, real-time scan monitoring, and CLI control center React + Express + PostgreSQL BugTraceAI-WEB
BugTraceAI-Launcher Guided deployment with CLI TUI/API profiles, local or Docker runtime, optional global btai, service management and an optional AI Setup & Repair Assistant Bash + Python + Docker Compose BugTraceAI-Launcher
MCP Ecosystem Extensible agent framework using the Model Context Protocol. Includes integrated Kali Linux and ReconFTW agents MCP + Docker + Python reconftw-mcp
BugStore Deliberately vulnerable practice target used in demos and walkthroughs. Full-featured shop riddled with 32 planted OWASP vulnerabilities Python + FastAPI + SQLite BugTraceAI/BugStore

Use the CLI TUI locally, its API/MCP for automation, or the Launcher to install independent products or a combination. The WEB connects to the appropriate scanning backend for each engine; API scans use BugTraceAI-API and web scans use the CLI API.


Architecture

flowchart LR
    TUI[CLI terminal workspace] --> Engine[CLI scan engine]
    WEB[WEB dashboard] --> REST[CLI REST API]
    MCP[CLI MCP clients] --> Engine
    REST --> Engine
    WEB --> API[BugTraceAI-API]
    Engine --> Tools[Specialists and browser validation]
    Engine --> Reports[Scan reports]
    API --> Reports
Loading

The CLI stores scan metadata in SQLite and writes report artifacts to disk. The WEB uses PostgreSQL for its own chats, settings and analysis. The Launcher configures service connections and selected ports. Standalone local TUI setup opens the engine without starting an API server.

See the component documentation for deployment details.


Scanning Pipeline

The CLI terminal and WEB display the same six scan phases:

Phase Purpose
Recon Crawl the target and discover endpoints
Discovery Analyze URLs and collect initial findings
Strategy Consolidate findings and route work to specialists
Exploit Run specialist checks and collect evidence
Validate Verify findings through the validation stage
Report Generate structured and human-readable deliverables

Target authentication supports Bearer tokens and login YAML with optional TOTP/2FA. In the TUI, configure it through Auth/F8, separately from the LLM provider's API key in Provider/F7. See the CLI installation guide.

Current Public Releases

Component Version Highlights
CLI 4.0.31-beta Terminal TUI, web-scanning API/MCP, provider/auth setup and optional global btai
WEB 2.0.32-beta Browser workspace for both scanning engines and reports
API 1.4.11-beta Independent API-target engine with REST and MCP
Launcher 3.3.26 Universal TUI installer, independent module selection and Wizard or AI setup

Launcher 3.3.26 passed its focused installer tests and clean Lubuntu VM startup checks. Full component installation and a live scan were not completed in this release check. macOS and ARM runtime validation are not included.

Demo Report

Want to see what BugTraceAI produces? Try the live demo or download a real scan report generated against BugStore -- our deliberately vulnerable practice app.

Live Demo   Download Demo Report

Benchmark note: This demo report was produced with an earlier scanner build. Results are useful for exploring the workflow, but should not be treated as a current performance claim for the latest CLI release until re-run under a versioned benchmark protocol.

The zip includes the full markdown report, validated findings JSON, specialist agent results with WET/DRY traceability, reconnaissance data, and PoC enrichment output.


CI/CD Integration Proposal

For CI/CD, automation can call the CLI REST/MCP interfaces for web scans or BugTraceAI-API for API-target testing. Reports and evidence are available for review in the WEB workspace. The diagram below proposes downstream AI review and ticketing integrations; connect them to the selected engine's supported interfaces.

BugTraceAI CI/CD architecture with API, CLI, WEB, reporting, AI review, and ticketing

This keeps external automation, autonomous scanning, evidence-rich reporting, human review, and remediation coordination connected without hard-coding deployment-specific service endpoints.


Quick Start

Choose your setup

  • Terminal workspace: Linux and Python 3.10+ for local installation; some specialist tools also use Docker when scanning.
  • API/MCP or full WEB platform: select the relevant profile and runtime in the installer. Docker deployments need Docker Engine, Compose and Git.
  • Real scans: configure a supported provider's API key. Opening the TUI or its offline demo does not require starting a scan.

One-Command Install

One-liner (recommended):

curl -fsSL https://raw.githubusercontent.com/BugTraceAI/BugTraceAI-Launcher/main/install.sh | bash

Or clone and run manually:

git clone https://github.com/BugTraceAI/BugTraceAI-Launcher.git ~/bugtraceai-launcher
~/bugtraceai-launcher/launcher.sh

From this ecosystem checkout, ./install.sh opens the same universal menu with full suggested. Component ./install.sh entry points suggest their own product in that menu; they do not deploy a profile without your review.

Enter and verify a provider API key on the first screen, then choose Install with Wizard or Install with AI. Both stay in the TUI. Wizard supports every module combination. AI setup uses provider tokens and currently supports API-only or the full WEB + CLI + API selection, including the CLI TUI, with OpenRouter or Anthropic. Use Wizard for other combinations and for Z.ai. The review shows selected modules, runtime, ports and optional WEB toolboxes. Terminal profiles can register a global btai command.

Let your AI coding agent run setup

If you use Codex, Claude Code, Cursor or another local terminal agent, give it this prompt:

Help me install BugTraceAI using the official universal Launcher.

First read:
https://github.com/BugTraceAI/BugTraceAI#readme
https://github.com/BugTraceAI/BugTraceAI-Launcher#readme

Follow those instructions using the official installer:
https://raw.githubusercontent.com/BugTraceAI/BugTraceAI-Launcher/main/install.sh

Ask which independent modules I want: BugTraceAI-WEB, BugTraceAI-CLI,
BugTraceAI-API, or a combination. Install only the modules I choose. Let me
choose Wizard or the built-in AI installer when my selection is supported;
use Wizard for other combinations.

Preserve any existing installation, configuration and data. Run the
Launcher in my local interactive terminal. I will enter and verify the
provider API key there, choose ports and review the plan before installation.
Keep credentials out of chat and logs. Do not start a scan.

Verify the selected services on their configured ports. If I enable the
global btai command, check it from a fresh shell. Report the installation
location, launch commands, checks completed and any checks still pending.
Profile Installed products Runtime
terminal CLI terminal TUI Local Python or Docker
web WEB is preselected; add either or both scanning engines if needed Docker
full WEB + both scanning engines + CLI terminal TUI Docker
server CLI web-scanning API/MCP Local Python or Docker
terminal-server CLI TUI + web-scanning API/MCP, without WEB Local Python or Docker
api Independent BugTraceAI-API target engine, REST + MCP Docker

For direct component installation, use each checkout's explicit scripts/install-runtime.sh backend or the documented Python/Compose commands. Follow INSTALLATION.md; a bare WEB docker compose up is not a complete configuration step.

Component entry points suggest their own module. A suggestion only sets the initial checkboxes; review the exact modules before installation.


Documentation

Full documentation is available in the Project Wiki:


Community & Support

Resource Link
Website bugtraceai.com
Wiki GitHub Wiki
DeepWiki AI-powered docs
Issues GitHub Issues
Discord Join the BugTraceAI community
Twitter @yz9yt

Contributing

We welcome contributions: bug reports, feature requests, PRs, documentation improvements, and community tools. Open an issue on the respective repository to get started.


License

Apache License 2.0 — BugTraceAI-owned material is free to use, modify, and distribute under the terms of the Apache License, Version 2.0.

See LICENSE file in each repository.


BugTraceAI -- Build your own self-hosted pentesting platform.
If BugTraceAI helps your authorized security research, consider giving the project a star or joining the community on Discord.
Albert C (@yz9yt)

Releases

Packages

Contributors

Languages