> For the complete documentation index, see [llms.txt](https://bugrecon.gitbook.io/docs/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://bugrecon.gitbook.io/docs/features-list/scopes-overview/ai-scan.md).

# AI scan

The **AI scan** analyzes your existing reconnaissance data and gives you a **prioritized list of the most promising targets** for bug bounty or penetration testing. Think of it as an expert assistant: it reviews your subdomains and HTTP results, then highlights what is worth investigating first-outdated technologies, admin panels, staging environments, and possible vulnerabilities-with short explanations and suggested next steps.

## What you get

* **Prioritized targets** - Domains and URLs ranked by interest (critical, high, medium, low), with technologies detected, why they were flagged, and when relevant, known CVEs or default credentials to try.
* **Summary** - A short overview of the main findings and a suggested approach.
* **Stats** - How many subdomains and HTTP results were analyzed, how many targets were found, and how long the analysis took.

All of this appears on the scan detail page in the **AI results** section. You can expand each target to see the full details.

![AI results](https://1075470145-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FV2n4UTcrS4SHhY2NTi0v%2Fuploads%2Fgit-blob-50793bb54ef624a907ec4ba311f150dfeb4c93f1%2Fai.png?alt=media)

## What you need before running it

1. **Data in the scan** - The AI only looks at what is already in your scan. Run a **Subdomain scan** and an **HTTP scan** first so it has something to analyze. If the scan has no subdomains or HTTP results, the AI scan will tell you to run those scans first.
2. **An AI provider key** - You must add at least one AI key in **API Keys** (OpenAI, Anthropic, or OpenRouter). Without it, you will see a message asking you to add a key. See [API Keys](/docs/features-list/api-keys.md) for where to manage them.

## Options when running

* **Use HackerOne trending CVEs** - When this is on (default), the AI also considers currently trending CVEs from HackerOne to prioritize targets and suggest relevant vulnerabilities. You can turn it off for a more generic analysis.
* **Model** - In API Keys you can choose which AI provider and model to use (e.g. GPT-4o, Claude Sonnet). You can mark one key as default so it is used automatically.

## What the AI looks for

The AI is tuned to focus on things that often lead to findings: outdated or end-of-life software, exposed admin or debug interfaces, non-production environments (dev, staging, test), sensitive files or endpoints, and services where default credentials are common. It suggests known CVEs and default logins when it recognizes technologies in your data. Results are limited to a manageable number of top targets so you can act on them quickly.

## Where to run it

* **On the scan** - Open your scan, go to the **AI scan** section, set the options you want, and click **Run**. When it finishes, the **AI results** block shows the targets and summary. Progress and logs work like other scan types.

## Availability and quota

* **Plans:** Available on all plans

## Collaboration

If you share the scan with others, **writers** can run the AI scan and see the results; **read-only** collaborators can only view the results. See [Collaboration](/docs/features-list/collaboration.md).


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://bugrecon.gitbook.io/docs/features-list/scopes-overview/ai-scan.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
