ZeroDayEvil's AI Security Tool is a free vulnerability scanner that pairs CVE and SBOM lookup with 12 LLM-backed agents
ZeroDayEvil's ai-security-tool is a free MIT-licensed security terminal and vulnerability scanner that runs CVE and SBOM lookups through DeepSeek or OpenAI, with 12 specialised agents and 409 stars in 30 days.

Why it mattersA small security team that wanted an agent-driven CVE triage pass today had to glue together two or three commercial tools; one open-source toolkit that does the whole loop is the first that is cheap enough to try on a weekend.
A small team cannot afford a commercial vulnerability scanner, and a free one with no AI is a shell for a human to drive.
The repository ZeroDayEvil/ai-security-tool is a free open-source security terminal and vulnerability scanner that pairs CVE and SBOM lookup with 12 agents backed by DeepSeek and OpenAI. It is MIT-licensed, carries 409 stars in 30 days, and 133 commits sit on the main branch. The readme describes the shape of the toolkit as a "Free open-source AI-powered security terminal & vulnerability scanner (CVE, SBOM). Supports SSH, SFTP, RDP, VNC, Serial, and 12+ autonomous AI agents."
What the twelve agents actually do
The names in the readme describe a loop rather than a feature list. An IntelligentDecisionEngine picks the next step. A CVEIntelligenceManager pulls records from NVD and OSV against the SBOM. A VulnerabilityCorrelator joins the two: an entry in the SBOM that matches a CVE in NVD or OSV gets flagged, and the correlator decides whether the flag is a real match or a false positive on a version string.
That last step is the one that commercial scanners usually get wrong on an open-source project, because version matching across package ecosystems is noisy. Running it through an LLM is not a magic fix; the agent still has to read a changelog or a release note to be sure a given version is affected. But it is the step that a one-engineer security team was skipping because they did not have the hours.
Who this is for, in one sentence
Someone running a server with a mix of SSH, SFTP and VNC endpoints, who wants to pull an SBOM for the whole thing and get a prioritised list of vulnerabilities that match, without buying a seat on a commercial platform. The tool runs on the user's machine (or a server they control), reads the SBOM, hits NVD and OSV, and the agents hand back a list.
What the readme does not promise
There is no comparison in the readme between this scanner and a commercial one, and the project does not claim to find vulnerabilities a commercial scanner would miss. The star count is the only external signal of use so far, and 409 stars in a month is a real number but not a sign of production deployment.
The LLM dependency is a real cost. The scanner needs DeepSeek or OpenAI credentials to work, which means a scan with a lot of SBOM entries has a measurable API bill. A user comparing it against a free scanner with no AI should expect that trade: more work done per scan, in exchange for a per-scan token cost that scales with the size of the SBOM.
Source
- ZeroDayEvil/ai-security-tool, ZeroDayEvil on GitHub, read 5 October 2026.
This item was written by an AI system from the linked source. Reveneau is responsible for what it publishes.
Get AI News in your inbox
New developer tools, model and agent releases, and how teams are actually using them to release software. Short, and only when there is something worth reading.
