PentAGI vs REA
REA leads on trust: 79.2/100 (Grade B) against 57.5/100 (Grade C), a 21.7-point gap. PentAGI leads on adoption and transparency; REA leads on provenance and maintenance, and rests on broader evidence.
Fully autonomous AI Agents system capable of performing complex penetration testing tasks
Choose PentAGI if adoption and transparency matter most.
- +1.4Adoption: 25.1k GitHub stars against 422
- +0.7Transparency: OSSF Scorecard 5.6 against 4.8
Reverse engineer anything with agents, from app behavior down to native binaries.
Choose REA if provenance and maintenance matter most.
- +7.2Identity / Provenance: package provenance attested, against none
- +6.8Maintenance
- +1.8Safety / Integrity: package provenance attested, against none
- B vs CEvidence coverage: 3 of 5 independent signal types, against 2
Where they differ
An independent, evidence-based trust comparison of PentAGI and REA, two Security & Guardrails projects in the HVTracker registry. Scores come from public, checkable signals — supply-chain provenance, OSSF Scorecard, maintenance, and adoption — not popularity.
Full evidence
| Signal | PentAGIvxcontrol/pentagi | REAmorluto/rea |
|---|---|---|
| HVTrust score | 57.5 | 79.2 |
| Evidence grade | C | B |
| Coverage grade | C | B |
| Overall rank | #710 | #161 |
| Rank in Security & Guardrails | #8 | #3 |
| GitHub stars | 25.1k | 422 |
| Last updated | today | today |
| Build provenance | No | Yes |
| OSSF Scorecard | 5.6 / 10 | 4.8 / 10 |
| License | MIT | MIT |
| Downloads | — | 142/wk |
| Trust dimensions (points earned) | ||
| Safety / integrity / 25 | 11.9 | 13.7 |
| Identity & provenance / 18 | 10.8 | 18.0 |
| Transparency / 17 | 13.3 | 12.6 |
| Maintenance / 20 | 13.2 | 20.0 |
| Adoption / 20 | 10.6 | 9.2 |
| Runtime capability surface (full matrix) | ||
| MCP server | Implemented | Implemented |
| External providers | 7 — Anthropic, DeepSeek, Firecrawl, … | — |
| Requires API keys | Yes | No |
| Plugin surface | plugins | — |
| Provenance drift | — | Match |
How to read this: HVTrust (0–100) weighs supply-chain signals (provenance, OSSF Scorecard, signed commits, open license) alongside real-world adoption, scaled by an evidence-confidence factor. Grade bands: A ≥ 80, B ≥ 65, C ≥ 50, D < 50. Signals refresh daily. Full methodology v4.4 →