The AI whitebox pentesting assistant, built by pentesters for engagement workflows
Project description
kalibur
The AI whitebox pentesting assistant, built by pentesters for engagement workflows.
Kalibur scans a codebase the way a skilled pentester would: reading every file, tracing data flows from entry points to sinks, and identifying complex exploitable paths across authentication, authorisation, injection, and cryptographic weaknesses. Findings are significantly deeper than what automated scanners surface.
Results land in an editable report.md, structured and ready for manual review. Kalibur does not replace the pentester: it handles the time-consuming groundwork so you can focus on validation, context, and client communication. Triage findings, add notes, mark issues resolved. When you are done, kalibur report proofreads the content, generates an executive summary, and produces a branded PDF in seconds.
The full engagement lifecycle is covered: save and restore snapshots between sessions or across teammates with push and pull, and cleanly close out an engagement with end, which permanently deletes all associated data.
Requirements
- Python 3.9 or later
- A Kalibur API key (kalibur.ai)
Installation
pip install kalibur
Use pip3 or python3 -m pip if pip points to Python 2 on your system:
pip3 install kalibur
# or
python3 -m pip install kalibur
If the kalibur command is not found after installation, run it as python3 -m kalibur.
Authentication
kalibur login
Prompts for your API key, validates it, and saves it to ~/.config/kalibur/key. You can also pass -k <key> to any command or set the KALIBUR_API_KEY environment variable.
Commands
kalibur scan
Run a whitebox security assessment of a codebase.
kalibur scan
kalibur scan -t /path/to/project
| Flag | Description |
|---|---|
-t PATH |
Directory to scan (default: .) |
-k KEY |
API key |
Results are written to a timestamped folder inside a kalibur/ directory in the scanned project:
<target>/kalibur/
2026-05-03_14-23-45/
report.md
Add kalibur/ to your .gitignore to keep scan output out of version control.
kalibur report
Generate a branded PDF pentest report from a completed report.md.
kalibur report \
-r ./kalibur/2026-05-03_14-23-45/report.md \
-f "Scapin Ltd" \
-a "Jane Doe" \
-c "Acme Corp" \
-l ./logo.png \
-v "1.0"
| Flag | Description |
|---|---|
-r FILE |
Path to report.md (required) |
-f NAME |
Assessor firm name (required) |
-a NAME |
Assessor name (required) |
-c NAME |
Client name (required) |
-l FILE |
Logo file, .png or .jpg (required) |
-v VER |
Report version, e.g. 1.0 (required) |
-k KEY |
API key |
The PDF is saved alongside report.md as report-<timestamp>.pdf.
Before generating, review findings in report.md and set each triage status:
# Triage
Status: Open # finding needs fixing
Status: Accepted # risk accepted, no fix planned
Status: Resolved # finding has been fixed
kalibur push
Save a snapshot of your local kalibur/ folder to the cloud.
kalibur push
kalibur pull
Restore a saved snapshot to your local kalibur/ folder.
kalibur pull
kalibur pull -e <project>
| Flag | Description |
|---|---|
-e PROJECT |
Project name (skip interactive picker) |
kalibur end
End an engagement and permanently delete all its data: remote scans, snapshots, and the local kalibur/ folder. This cannot be undone.
kalibur end
Project details
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file kalibur-0.1.2.tar.gz.
File metadata
- Download URL: kalibur-0.1.2.tar.gz
- Upload date:
- Size: 23.4 kB
- Tags: Source
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/6.2.0 CPython/3.13.8
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
e831b3c56bd6866e0fe3777f6d839371a6373e7fb5710ce1d269919bf3893488
|
|
| MD5 |
5db78a74852ce142310a758e8aa6c2f6
|
|
| BLAKE2b-256 |
4f8e6ee979555a507515ada227a92cbb5a58e269e88e77a7dfc3817cb8984a4f
|
File details
Details for the file kalibur-0.1.2-py3-none-any.whl.
File metadata
- Download URL: kalibur-0.1.2-py3-none-any.whl
- Upload date:
- Size: 25.0 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/6.2.0 CPython/3.13.8
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
7977d2e48b61e6d8c9c4eb41bafebf92a7de828a8c7952c27de3de6595f83dbd
|
|
| MD5 |
2b8c9892eac2f72cd21c9f2193a1f14e
|
|
| BLAKE2b-256 |
106342da15d33d224e9841111ce36a4a5924600005ae0397d28489c1bc74da33
|