Backend-first enumeration assistant for authorized pentesters.
Project description
PenPal
PenPal is a local-first assistant for authorized enumeration. It turns services and tool output into stored evidence, clear next checks, and visible command syntax. The Python core is deterministic; PI is the optional conversational cockpit.
PenPal does not execute exploits, hide commands, use credentials automatically, or provide C2 tasking.
Start With PI
Download a release archive or clone the repository. You need Python 3.11 through 3.13, Node.js 22.19 or newer, and npm.
git clone https://github.com/yousifnazhat/penpal.git
cd penpal
./scripts/setup-pi.sh
pi
On Windows PowerShell, run ./scripts/setup-pi.ps1 instead. The setup script installs the tested PI version when it is missing.
Inside PI, approve project-local files if prompted and run /login when a provider is not configured. Create a target by stating that it is authorized:
Create authorized target 10.10.11.42 named new-box.
Run Nmap or another enumeration tool, then paste its output into the same conversation:
This is Nmap evidence for new-box:
PORT STATE SERVICE
22/tcp open ssh
80/tcp open http
PenPal stores the pasted text through its deterministic core, recognizes Nmap service lines, masks sensitive evidence, and returns evidence-backed suggestions. Paste each new result the same way. Run /penpal-status for a provider-free connection check.
PenPal presents one primary next step and up to two alternatives. After a complete pass produces no new supporting evidence, tell PI:
Mark that suggestion exhausted.
PenPal suppresses the path until you explicitly reopen it or its supporting inputs change, preventing the same dead end from being recommended repeatedly.
Other Paths
Connect an MCP client
Use this path when your existing agent supports MCP rather than PI. Install the optional local server, then configure the client to start the shown command over stdio:
python3 -m pip install "penpal-enum[mcp]"
penpal --workspace penpal-workspace mcp
The MCP server exposes seven read-only workflows. It masks sensitive values and does not execute commands or modify your workspace.
Use the Python core only
The core works without PI. Install it and create a target:
python3 -m pip install penpal-enum
penpal doctor
penpal init 10.10.10.5 --name demo
penpal parse-nmap demo ./scan.xml
penpal suggest demo
The release wheel and source archive also include the Python core and bundled playbooks. Add the PI cockpit to a registry installation with:
pi install npm:@yousif_nazhat/penpal-pi
Diagnose setup
penpal doctor
penpal doctor --json
Doctor checks the Python version, playbooks, workspace schemas, scope, plaintext sensitive parameters, missing environment variables, and PI status. It does not modify the workspace. Include the redacted JSON output in bug reports.
What PenPal Does
- Stores scoped targets, services, evidence, parameters, notes, and jobs in a local workspace.
- Parses Nmap XML and ingests pasted or saved tool output.
- Masks credential-like evidence and sensitive parameters by default.
- Uses deterministic suggestions, service modules, and reviewed playbooks to explain the next authorized check.
- Remembers exhausted investigation paths and reopens them when their supporting inputs change.
- Uses environment references for secrets so values are not persisted in workspace JSON.
- Provides a loopback-only JSON API for local integrations.
Everyday Commands
penpal doctor
penpal init <host> --name <name>
penpal scope set --include <host-or-cidr> [--exclude <host-or-cidr>]
penpal parse-nmap <name> <nmap.xml>
penpal ingest <name> --file <output.txt> --source <tool-name> --service <proto/port>
penpal services <name>
penpal evidence <name>
penpal suggest <name>
penpal focus <name> <suggestion-id> exhausted|reopened
penpal context <name> --json
penpal mcp
penpal playbooks playbooks
penpal modules list
penpal modules plan <name> <module>
scan prints commands by default. It runs them only with --execute. Use params set-env for passwords, tokens, and keys; params set keeps sensitive values in local plaintext for compatibility.
Safety
Configure engagement scope before a real assessment. Text pasted into PI is sent to the configured model provider; use an approved or local provider for sensitive engagement data. Keep the local API on its default loopback address. Review every suggested command and remain responsible for authorization. Playbooks require authorized use and operator approval.
Help And Contributing
Run the contributor checks with:
python3 -m pip install ".[dev]"
python3 scripts/check.py
Project details
Release history Release notifications | RSS feed
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file penpal_enum-1.0.1.tar.gz.
File metadata
- Download URL: penpal_enum-1.0.1.tar.gz
- Upload date:
- Size: 71.8 kB
- Tags: Source
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/6.1.0 CPython/3.13.12
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
5befd59f561cc9672f54130ea6d399204c1fcbd533a2664190b45da1031ac7e7
|
|
| MD5 |
3b7e225255a312a495e01fc34b3246d8
|
|
| BLAKE2b-256 |
77cc67158abf180be1011825bf44fdef80441dfec6e1c3b8a961d4ee6596ef2f
|
Provenance
The following attestation bundles were made for penpal_enum-1.0.1.tar.gz:
Publisher:
publish-pypi.yml on yousifnazhat/penpal
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
penpal_enum-1.0.1.tar.gz -
Subject digest:
5befd59f561cc9672f54130ea6d399204c1fcbd533a2664190b45da1031ac7e7 - Sigstore transparency entry: 2166787656
- Sigstore integration time:
-
Permalink:
yousifnazhat/penpal@03b666a5373c554111593125e6e42eba9939564b -
Branch / Tag:
refs/tags/v1.0.1 - Owner: https://github.com/yousifnazhat
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
publish-pypi.yml@03b666a5373c554111593125e6e42eba9939564b -
Trigger Event:
release
-
Statement type:
File details
Details for the file penpal_enum-1.0.1-py3-none-any.whl.
File metadata
- Download URL: penpal_enum-1.0.1-py3-none-any.whl
- Upload date:
- Size: 60.8 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/6.1.0 CPython/3.13.12
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
209c79db9cc7bc91d856df96d11801e61a6ab21ac0261ff572f9ccedef56a869
|
|
| MD5 |
4f446e94cc9465c6bb210584458e2e6e
|
|
| BLAKE2b-256 |
73a32d6176ca739f8808d639c886ac37a02f05bb6c57fc06b7cf70da8fa271e6
|
Provenance
The following attestation bundles were made for penpal_enum-1.0.1-py3-none-any.whl:
Publisher:
publish-pypi.yml on yousifnazhat/penpal
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
penpal_enum-1.0.1-py3-none-any.whl -
Subject digest:
209c79db9cc7bc91d856df96d11801e61a6ab21ac0261ff572f9ccedef56a869 - Sigstore transparency entry: 2166787667
- Sigstore integration time:
-
Permalink:
yousifnazhat/penpal@03b666a5373c554111593125e6e42eba9939564b -
Branch / Tag:
refs/tags/v1.0.1 - Owner: https://github.com/yousifnazhat
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
publish-pypi.yml@03b666a5373c554111593125e6e42eba9939564b -
Trigger Event:
release
-
Statement type: