Skip to main content

The AI whitebox pentesting assistant, built by pentesters for engagement workflows

Project description

kalibur

The AI whitebox pentesting assistant, built by pentesters for engagement workflows.

Kalibur scans a codebase the way a skilled pentester would: reading every file, tracing data flows from entry points to sinks, and identifying complex exploitable paths across authentication, authorisation, injection, and cryptographic weaknesses. Findings are significantly deeper than what automated scanners surface.

Results land in an editable report.md, structured and ready for manual review. Kalibur does not replace the pentester: it handles the time-consuming groundwork so you can focus on validation, context, and client communication. Triage findings, add notes, mark issues resolved. When you are done, kalibur report proofreads the content, generates an executive summary, and produces a branded PDF in seconds.

The full engagement lifecycle is covered: save and restore snapshots between sessions or across teammates with push and pull, and cleanly close out an engagement with end, which permanently deletes all associated data.

Requirements

  • Python 3.9 or later
  • A Kalibur API key (kalibur.ai)

Installation

pip install kalibur

Use pip3 or python3 -m pip if pip points to Python 2 on your system:

pip3 install kalibur
# or
python3 -m pip install kalibur

If the kalibur command is not found after installation, run it as python3 -m kalibur.

Authentication

kalibur login

Prompts for your API key, validates it, and saves it to ~/.config/kalibur/key. You can also pass -k <key> to any command or set the KALIBUR_API_KEY environment variable.

Commands

kalibur scan

Run a whitebox security assessment of a codebase.

kalibur scan
kalibur scan -t /path/to/project
Flag Description
-t PATH Directory to scan (default: .)
-k KEY API key

Results are written to a timestamped folder inside a kalibur/ directory in the scanned project:

<target>/kalibur/
  2026-05-03_14-23-45/
    report.md

Add kalibur/ to your .gitignore to keep scan output out of version control.

kalibur report

Generate a branded PDF pentest report from a completed report.md.

kalibur report \
  -r ./kalibur/2026-05-03_14-23-45/report.md \
  -f "Scapin Ltd" \
  -a "Jane Doe" \
  -c "Acme Corp" \
  -l ./logo.png \
  -v "1.0"
Flag Description
-r FILE Path to report.md (required)
-f NAME Assessor firm name (required)
-a NAME Assessor name (required)
-c NAME Client name (required)
-l FILE Logo file, .png or .jpg (required)
-v VER Report version, e.g. 1.0 (required)
-k KEY API key

The PDF is saved alongside report.md as report-<timestamp>.pdf.

Before generating, review findings in report.md and set each triage status:

# Triage
Status: Open       # finding needs fixing
Status: Accepted   # risk accepted, no fix planned
Status: Resolved   # finding has been fixed

kalibur push

Save a snapshot of your local kalibur/ folder to the cloud.

kalibur push

kalibur pull

Restore a saved snapshot to your local kalibur/ folder.

kalibur pull
kalibur pull -e <project>
Flag Description
-e PROJECT Project name (skip interactive picker)

kalibur end

End an engagement and permanently delete all its data: remote scans, snapshots, and the local kalibur/ folder. This cannot be undone.

kalibur end

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

kalibur-0.1.3.tar.gz (23.5 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

kalibur-0.1.3-py3-none-any.whl (25.1 kB view details)

Uploaded Python 3

File details

Details for the file kalibur-0.1.3.tar.gz.

File metadata

  • Download URL: kalibur-0.1.3.tar.gz
  • Upload date:
  • Size: 23.5 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.13.8

File hashes

Hashes for kalibur-0.1.3.tar.gz
Algorithm Hash digest
SHA256 01f868ec2d0beb43082a242cbacf0ee40f2025f20853503a18606d3e9f7a4d5c
MD5 3a751b179b8362f3bef3b2fa225ebc51
BLAKE2b-256 8f8374bb73fe9cc573e1353069d2b448a0b5398ac3f0b70217e3e7af27fca967

See more details on using hashes here.

File details

Details for the file kalibur-0.1.3-py3-none-any.whl.

File metadata

  • Download URL: kalibur-0.1.3-py3-none-any.whl
  • Upload date:
  • Size: 25.1 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.13.8

File hashes

Hashes for kalibur-0.1.3-py3-none-any.whl
Algorithm Hash digest
SHA256 21540fe129bfcc514208fefa08d66ea22814f895fecf90813c869ccf4b77f659
MD5 ea91140a9e7bdee02c5c93ac92247cd1
BLAKE2b-256 8813eab4039f26e4da0fe1167500c2f2aef6a5060efad19a26b51cd55e5c3528

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page