kpolley

kpolley / redai

Public

AI-driven vulnerability discovery and live validation

76
5
100% credibility
Found Apr 21, 2026 at 76 stars -- GitGems finds repos before they trend. Get early access to the next one.
Sign Up Free
AI Analysis
TypeScript
AI Summary

RedAI is a terminal tool that uses AI to discover vulnerabilities in source code and validates them live in browser or iOS simulator environments, generating detailed reports with evidence.

How It Works

1
🔍 Discover RedAI

You hear about a smart tool that finds security issues in code and tests them live.

2
📦 Get it running

Install the workbench on your computer with a simple command.

3
🧠 Connect smart helpers

Link AI thinkers so they can analyze your code deeply.

4
🎮 Prepare your test world

Set up a real browser or app simulator, log in, and get it ready for testing.

5
🚀 Start the security hunt

Create a scan, pick your code folder and test world, then launch it to watch issues get found and proven.

6
📊 Follow the adventure

See progress as it prioritizes files, scans units, and tests findings live.

Receive proof-packed report

Get a clear report with confirmed problems, reproduction steps, screenshots, logs, and fixes.

Sign up to see the full architecture

5 more

Sign Up Free

Star Growth

See how this repo grew from 76 to 76 stars Sign Up Free
Repurpose This Repo

Repurpose is a Pro feature

Generate ready-to-use prompts for X threads, LinkedIn posts, blog posts, YouTube scripts, and more -- with full repo context baked in.

Unlock Repurpose
AI-Generated Review

What is redai?

RedAI is a terminal-based workbench for AI-driven vulnerability discovery and live validation in web and iOS apps. Point it at a source directory and a running target—like a local webapp or simulator—and it uses Claude or Codex agents to threat-model, prioritize files, scan code units, and produce candidate findings. What sets it apart: validator agents then interact with live environments (bundled Chrome browser or iOS Simulator plugins) to confirm issues via UI clicks, API hits, PoC scripts, screenshots, and logs, outputting Markdown/HTML/JSON reports with ranked, evidence-backed vulns.

Built in TypeScript on Bun, it installs globally via `bun install -g @kpolley/redai` and ships demo vulnerable apps for instant testing.

Why is it gaining traction?

In a sea of AI-driven vulnerability scanners that flag static patterns without proof, RedAI delivers live validation—agents prove exploits in real runtimes, not just hypothesize. Devs love the end-to-end pipeline: threat models guide focused scans, environments are pluggable (add VMs or clusters via simple interfaces), and reports include reproduction steps plus artifacts like HTTP transcripts. With 76 stars, it's early but hooks security-focused teams tired of false positives in ai driven threat detection systems on GitHub.

Who should use this?

AppSec engineers pentesting web backends or iOS apps, where static tools fall short on dynamic exploits. Red teamers validating client-side issues in browsers, or iOS devs auditing simulators without manual scripting. Ideal for ai driven vulnerability assessment in TypeScript/JS/Swift/Go/Python repos needing confirmed PoCs over guesses.

Verdict

Try RedAI if you're building ai driven vulnerability discovery into your workflow—its live validation crushes typical scanners, especially for web/iOS. At 1.0% credibility and 76 stars, it's immature (light tests, solo maintainer) but docs shine with runnable examples; production use needs caution until more adoption. Solid 8/10 for experimenters.

Sign up to read the full AI review Sign Up Free

Similar repos coming soon.