Show HN: Redthread – autonomous LLM pentesting with proof-of-concept exploits MILLENIUMS.AI launched Redthread, an AI-Native Application Protection Platform (ANAPP) that autonomously pentests chatbots, agents and RAG endpoints against the OWASP LLM Top 10, mapped to MITRE ATLAS, with every finding carrying a reproducible proof of concept. The agentless platform builds one graph of an organization's agents, applications, code, cloud accounts, identities, controls and reachable data, and runs per-workspace modules including Shadow-AI discovery, cloud and infrastructure posture, CI/CD gating, and an Agent Trust Fabric that assigns each agent a SPIFFE id and broadcasts signed, TTL'd safe/unsafe/revoked trust-state events. A browser quickstart at scan.millenniums.ai/app requires no install or card, and the platform is detection-first, with any prevention or blocking action a signed, opt-in, customer-owned exception rather than a default. MILLENNIUMS.AI documentation MILLENNIUMS.AI is an AI-Native Application Protection Platform ANAPP , powered by Redthread . It is agentless-first — it installs nothing to deliver its core value — and every capability is a module you switch on per workspace from one console. Redthread starts by building the map — because until you know how your agents, code, cloud and infrastructure connect, a list of findings is just a list. It assembles one graph of your whole estate — agents, applications, code, cloud accounts, identities, the security controls you already run, and the data they can reach — and every module reads and writes that same graph, so the risk you see first is the one that spans layers, not an isolated finding on a list. On top of that map, the platform runs as modules you enable per workspace: - Assess & Consolidate — the agentless front door: connect agentless and get a posture score, the AI surfaces nothing is watching, and a replace-map of the incumbent tools a Redthread module can retire, with input-driven consolidation ROI . - AI application pentesting — autonomous agents probe your chatbots, agents and RAG endpoints against the OWASP LLM Top 10 mapped to MITRE ATLAS ; every finding carries a reproducible proof of concept. - Shadow-AI discovery — inventory every AI-powered feature across your estate, including the ones nobody registered. - Cloud & infrastructure posture — connect a cloud agentless nothing installed to map assets, identities and data, classify sensitive stores DSPM , and surface cross-cloud attack paths. - Endpoint telemetry detect-only — an optional, in-core thin agent on OS-safe surfaces reports on-host inventory and posture. It never blocks; real-time prevention is a partnered add-on on the roadmap. - Agent Trust Fabric — give every agent/identity a SPIFFE id and broadcast signed, TTL'd trust-state events safe/unsafe/revoked off proven exploits, so orchestrators, gateways and SIEMs react in seconds. See Agent Trust Fabric trust-signal . - CI/CD gating — scan on every pull request and block a merge that would introduce a proven attack path. - Continuous platform — scheduled re-assessment with drift and trend, so coverage reflects what is in production this week. - Remediation & reports — plain fixes and draft pull requests; a Letter of Attestation, the full technical report, and a machine-readable twin, mapped to the frameworks your auditors ask about. - Identity & access — SSO, SCIM provisioning, roles and audit logs for your workspace. Proven, not inferred. A finding is something the engine actually reached or exploited, with the exact steps to reproduce it; coverage is only claimed where the graph carries it. The platform is agentless and detection-first — any prevention/blocking action is a signed, opt-in, customer-owned exception, never a default, and every update we push to a sensor is staged behind the always-on AI Rollout Safety safety-gate gate so it can never take a fleet down. This documentation covers getting started , the platform architecture architecture , the core concepts behind how the platform works, task-based guides , and the full API reference so you can drive every module from CI or your own scripts. New here? Start with the browser quickstart quickstart-browser — you'll have a real, provable finding in a few minutes, no code required. Quickstart — in the browser The fastest way to see a result. No install, no card. 1. Create your account. Go to scan.millenniums.ai/app https://scan.millenniums.ai/app and sign up with your email. A work email is best; a personal one works too. No card. 2. Connect your estate. You land on Estate Scan . Connect as much or as little as you like — a website URL needs no credentials, GitHub is one click, and a read-only cloud role or a pasted read-only inventory JSON is the single biggest jump in coverage. Discovery across all of it is free and unlimited; the meter shows what's still dark and nothing blocks the scan. 3. Verify your email. Click the link we send you. This unlocks active scanning. Didn't arrive? Use "Resend" in the app. 4. Point a pentest at one target. For the active, exploit-proving scan, paste your app's staging URL target — the live address where it's running not production . Optionally drag in your code a .zip for a deeper scan. Press Start a scan . 5. Watch it work. The scan runs in an isolated sandbox and typically finishes in minutes. You'll see it probe each category live. 6. Read the findings. Each proven vulnerability comes with its severity, impact, and a plain remediation. On a paid plan, every finding also includes a working proof of concept and a draft fix. Prefer an app? Redthread is also available for Mac and Windows from the download page https://millenniums.ai/download . It is the same product in its own window; your data stays on the server, so the app and the browser always show the same workspace. To sign in, enter your email in the app and open the emailed link — your browser asks to open Redthread and hands the sign-in to the app the millenniums:// link is single-use and expires in 15 minutes . The installers are not yet signed with an Apple or Microsoft certificate, so a downloaded copy is blocked until you confirm it once. On a Mac, the one-line Terminal install on the download page https://millenniums.ai/download avoids the prompt entirely; with the .dmg you confirm once via System Settings → Privacy & Security → Open Anyway . On Windows, click More info → Run anyway . Only scan what you're allowed to. The tool actively tries to exploit whatever you point it at. Use it against your own apps, or ones you have explicit permission to test. See Terms https://millenniums.ai/terms . Quickstart — with the API Prefer to drive it from a terminal or CI? Everything the app does is a REST call. Your access token is created at signup and shown in the app; it goes in an Authorization: Bearer header. 1. Check your account Confirm your token works and see your plan and remaining quota. curl https://scan.millenniums.ai/api/me \ -H "Authorization: Bearer YOUR ACCESS TOKEN" { "tenant": "acme-3f9a2c", "plan": "starter", "plan display": "Starter", "poc": true, "scans used": 1, "scans limit": 5, "apps used": 1, "apps limit": 1, "verified": true } 2. Start a scan Give it a target . Optionally add source a repo or path for a much deeper white-box scan, and a budget spend cap. curl -X POST https://scan.millenniums.ai/api/scan \ -H "Authorization: Bearer YOUR ACCESS TOKEN" \ -H "Content-Type: application/json" \ -d '{"target":"https://staging.yourapp.com/chat","budget":10}' { "run id": "20260731-abc123" } 3. Read the results Poll the run until running is false , then read its findings. curl https://scan.millenniums.ai/api/runs/20260731-abc123 \ -H "Authorization: Bearer YOUR ACCESS TOKEN" That's the whole loop: me → scan → runs/