Agentic Hound logo

Agentic Hound

An autonomous agent that hunts security bugs in your codebase and fixes them. Free reports, free fix PRs — you only pay when you approve or merge a fix.

Our mission

Every codebase deserves a security review — without the cost of a retainer.

Agentic Hound gives every team an autonomous agent that finds real vulnerabilities and ships real fixes. You review each one. You pay only for the fixes you accept.

How it works

01

Install the GitHub App

Grant Agentic Hound read access to the repos you want scanned. Nothing is charged at install.

02

Agentic Hound scans and opens fix PRs

Our agent finds real, exploitable issues and opens a pull request with a working fix for each one — at no cost to you.

03

You review, as usual

Each PR is a normal pull request. Read the diff, run your checks, discuss it with your team — nothing about your workflow changes.

04

Pay only when you accept

You're charged only the moment you approve or merge a fix. Findings you close without merging cost nothing.

What counts as a security bug

Severity is scored with CVSS v3.1 — the same framework NIST's National Vulnerability Database (NVD) uses to rate published CVEs — so every finding comes with a standard, independently verifiable severity, not a house scale.

Critical

$50

CVSS 9.0–10.0

  • OS command injection (CWE-78)
  • SQL injection (CWE-89)
  • Missing authentication for a critical function (CWE-306)

High

$50

CVSS 7.0–8.9

  • Cross-site scripting (CWE-79)
  • Server-side request forgery (CWE-918)
  • XML external entities (CWE-611)

Medium

$10

CVSS 4.0–6.9

  • Cross-site request forgery (CWE-352)
  • Information exposure (CWE-200)
  • Insufficiently protected credentials (CWE-522)

Low

Free

CVSS 0.1–3.9

  • Missing security headers
  • Outdated dependencies (known CVEs)
  • General hardening recommendations

CVE and CVSS are standards maintained by NIST's National Vulnerability Database (nvd.nist.gov). Agentic Hound is not affiliated with or endorsed by NIST.

Language support

Agentic Hound currently scans and fixes bugs in:

JavaScriptTypeScriptNode.js

More coming soon

PythonGoJavaRuby

Pricing

Pay for accepted fixes only. No subscriptions, no retainers, no charge for a PR you don't merge.

You're only charged when you approve or merge a fix

Critical$50per accepted fix
High$50per accepted fix
Medium$10per accepted fix
LowFreealways
  • ✓ Free scan and findings report, always
  • ✓ Fix PRs opened automatically, at no cost
  • ✓ Charged only on approval or merge
  • ✓ No charge for false positives or fixes you decline
Get started