Open-source Pentest Copilot runs autonomous pentests on a Kali box, 1.3k GitHub stars
tom_doerr · x · 2026-09-12
Bug Base open-sourced Pentest Copilot (1.3k GitHub stars), a browser-based AI ethical-hacking agent.
- It connects to a Kali attack box, runs security tools autonomously, reads output, and iterates based on the target you describe
- Built for real-world engagements, boot2root boxes, and CTFs
- Demo shows it performing an auth bypass in OWASP Juice Shop
- Deployed via Docker Compose with frontend/backend/kali modules
More from coding & agent
- When Facts Change: How Should an MCP Memory Server Update? Three Approaches Compared — izgorodin · 2026-09-12
- ADSP Ep. 303: Mark Saroufim on Open vs Closed Models, AI GPU Kernels and Autoresearch — blelbach · 2026-09-12
- Google releases free 2-hour course on agent graph & loop engineering — goyalshaliniuk · 2026-09-12
- Gemini CLI nightly patches indirect prompt injection and hardens sandbox filesystem — gemini-cli-robot · 2026-09-12
- Repurpose an old low-VRAM GPU just for mmproj in llama.cpp — an order of magnitude faster — inthesearchof · 2026-09-12
- Ollama vs llama.cpp: same request counts 85k vs 164k tokens in OpenCode — RadianceTower · 2026-09-12