pen-tester-agent
A penetration testing agent powered by local LLMs via Ollama.
pen-tester-agent gives a locally-running language model the ability to propose and execute shell commands on your machine — with your approval on every step. It's designed for structured penetration testing workflows across six key domains.
Penetration Testing Domains
- OSINT — Open source intelligence gathering (WHOIS, DNS, subdomain enumeration, email harvesting)
- Enumeration — Service enumeration, directory brute-forcing, SMB/LDAP/SNMP enumeration
- OS/Application Identification — Version detection, OS fingerprinting, web technology fingerprinting
- CVE/Vulnerability Search — Looking up known CVEs, searching exploit databases
- Vulnerability Testing — Active testing for SQL injection, XSS, misconfigurations, default credentials
- Documentation — Writing penetration test reports, documenting findings, saving evidence
Installation
# From PyPI
pip install pen-tester-agent
# Or with pipx (isolated install)
pipx install pen-tester-agent
# Or directly from GitHub
pip install git+https://github.com/fdsimoes-git/pen-tester-agent.git
Prerequisites
- Ollama installed and running
- A model pulled (default:
qwen3.6:35b):ollama pull qwen3.6:35b
Usage
# Interactive mode — prompts you for a task
pen-tester-agent
# Pass a task directly
pen-tester-agent "scan open ports on 192.168.1.1"
# Use a different model
pen-tester-agent --model llama3.1:8b "review nginx access.log for suspicious requests"
# Limit iterations
pen-tester-agent --max-iterations 5 "enumerate subdomains of example.com"
# Running from source (development)
uv run pen-tester-agent
Interactive CLI
When launched without a task, the agent presents an interactive menu (navigate with arrow keys):
- New penetration test task — describe a task and the agent works through it step by step
- Quit
During a session, every tool call is shown for approval via an arrow-key menu (approve / reject / edit args). Bash command output streams in real-time. A spinner indicates when the LLM is thinking or a non-bash tool is running.
At any interaction point during a session you can choose to generate a report from the session history or quit.
How it works
- You describe a task in natural language.
- The agent first drafts a numbered plan for the task, which stays pinned in context for the whole session (skip with
--no-plan). - The agent (running locally via Ollama) reasons about the next step and proposes a tool call (shell command, CVE lookup, file read/write, etc.).
- You review and approve/edit/reject the action via arrow-key menu.
- Bash output streams live to the terminal; the full output is fed back to the agent.
- Repeat until the task is complete or you stop. If it reaches
--max-iterations, it asks whether to continue, generate a report, or quit. - Generate a structured pentest report from the session at any time.
Disclaimer
This tool executes shell commands on your machine. Always review proposed commands before approving them. Use responsibly and only on systems you own or have explicit written authorization to test. The authors are not responsible for any misuse or damage.
Metadata
Release files for pen-tester-agent 1.1.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| pen_tester_agent-1.1.0.tar.gz | 32.7 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| pen_tester_agent-1.1.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 75.3 kB
Release files / pen_tester_agent-1.1.0.tar.gz
| Download URL | pen_tester_agent-1.1.0.tar.gz |
|---|---|
| Size | 32.7 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
c4c36a1f78ad4adae171765b418486fd9a9496b95ad851b765599139901d3be7
|
|
BLAKE2b-256 checksum How to use checksums |
e3528943375687cbaa9d98371e4321d2dc567548c47d9ca147e3fd75a297a1a8
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.12
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Jun 18, 2026.
Transparency logRelease files / pen_tester_agent-1.1.0-py3-none-any.whl
| Download URL | pen_tester_agent-1.1.0-py3-none-any.whl |
|---|---|
| Size | 42.7 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
8f590c6745ac7cf84808963ca22813d39ec2d8b86c7c31bc165a2836bf6476c0
|
|
BLAKE2b-256 checksum How to use checksums |
e22233aa01d09ddb36b31a25c4667043a795a3123a406777839379d45e82cd31
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.12
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Jun 18, 2026.
Transparency log