Registry › Compare › open-kritt vs REA

open-kritt vs REA

REA leads on trust: 73.3/100 (Grade B) against 57.7/100 (Grade C), a 15.6-point gap. open-kritt leads on maintenance; REA leads on supply-chain integrity and provenance, and rests on broader evidence.

C open-kritt 57.7

Open-source, self-hosted AI vulnerability research tool that orchestrates agents to find and validate security issues in code.

Kritt-ai/open-kritt · #704 overall · #8 Security & Guardrails · coverage C (2/5)

Choose open-kritt if maintenance matters most.

  • +5.9Maintenance: last push today, against 20d ago
B REA 73.3

Reverse engineer anything with agents, from app behavior down to native binaries.

morluto/rea · #258 overall · #4 Security & Guardrails · coverage B (3/5)

Choose REA if supply-chain integrity and provenance matter most.

  • +7.4Safety / Integrity: OSSF Scorecard 4.9 against 4.8
  • +7.2Identity / Provenance: package provenance attested, against none
  • +1.1Adoption
  • B vs CEvidence coverage: 3 of 5 independent signal types, against 2

Where they differ

8.5
Safety / IntegrityREA +7.4
15.9
10.8
Identity / ProvenanceREA +7.2
18.0
12.6
TransparencyREA +0.1
12.7
17.8
Maintenanceopen-kritt +5.9
11.9
8.0
AdoptionREA +1.1
9.1
+0.0
Runtime calibrationREA +5.7
+5.7

Full evidence table

An independent, evidence-based trust comparison of open-kritt and REA, two Security & Guardrails projects in the HVTracker registry. Scores come from public, checkable signals — supply-chain provenance, OSSF Scorecard, maintenance, and adoption — not popularity.

Full evidence

Signal open-krittKritt-ai/open-kritt REAmorluto/rea
HVTrust score 57.7 73.3
Evidence grade C B
Coverage grade C B
Overall rank #704 #258
Rank in Security & Guardrails #8 #4
GitHub stars 2.2k 416
Last updated today 20d ago
Build provenance No Yes
OSSF Scorecard 4.8 / 10 4.9 / 10
License AGPL-3.0 MIT
Downloads — 129/wk
Trust dimensions (points earned)
Safety / integrity / 25 8.5 15.9
Identity & provenance / 18 10.8 18.0
Transparency / 17 12.6 12.7
Maintenance / 20 17.8 11.9
Adoption / 20 8.0 9.1
Runtime capability surface (full matrix)
MCP server — Implemented
External providers — —
Requires API keys No No
Plugin surface — —
Provenance drift — Match
Open in the live compare tool → open-kritt profile REA profile More Security & Guardrails →

How to read this: HVTrust (0–100) weighs supply-chain signals (provenance, OSSF Scorecard, signed commits, open license) alongside real-world adoption, scaled by an evidence-confidence factor. Grade bands: A ≥ 80, B ≥ 65, C ≥ 50, D < 50. Signals refresh daily. Full methodology v4.3 →