Full-scale web, network & API penetration testing with AI on demand — reserved for insom.ai.
Project description
pentester
██████╗ ███████╗███╗ ██╗████████╗███████╗███████╗████████╗███████╗██████╗
██╔══██╗██╔════╝████╗ ██║╚══██╔══╝██╔════╝██╔════╝╚══██╔══╝██╔════╝██╔══██╗
██████╔╝█████╗ ██╔██╗ ██║ ██║ █████╗ ███████╗ ██║ █████╗ ██████╔╝
██╔═══╝ ██╔══╝ ██║╚██╗██║ ██║ ██╔══╝ ╚════██║ ██║ ██╔══╝ ██╔══██╗
██║ ███████╗██║ ╚████║ ██║ ███████╗███████║ ██║ ███████╗██║ ██║
╚═╝ ╚══════╝╚═╝ ╚═══╝ ╚═╝ ╚══════╝╚══════╝ ╚═╝ ╚══════╝╚═╝ ╚═╝
full-scale web · network · api pentesting — AI on demand
pentester is a full-scale offensive security toolkit that brings web,
network, and API penetration testing under one command line — with
AI on demand to drive recon, mutate requests, and triage findings.
🚧 Name reserved for insom.ai. This release secures the package on PyPI and ships a working CLI shell. The full dynamic-analysis engine lands in upcoming releases — watch this space.
What it will do
| Surface | Capabilities (shipping incrementally) |
|---|---|
| Web | Crawling & spidering, authenticated sessions, fuzzing, OWASP-class detection (injection, XSS, SSRF, auth flaws), tech/CMS fingerprinting |
| Network | Host & port discovery, service fingerprinting, protocol enumeration, known-CVE matching, misconfiguration checks |
| API | REST / GraphQL / gRPC discovery, schema-aware fuzzing, auth / BOLA / mass-assignment testing |
| AI on demand | Attack-surface reasoning, request mutation, exploit-path suggestion, finding triage, and natural-language report narration — opt-in, bring-your-own model |
Install
pip install pentester
# or, isolated and always on PATH:
pipx install pentester
Usage
pentester --version
pentester scan https://example.com # engine coming soon
If the pentester command isn't found after a pip install --user, run it as
a module (works regardless of PATH):
python -m pentester --version
Roadmap
- Live web/network/API target fingerprinting
- Active scanning & fuzzing engine
- Component & dependency vulnerability detection
- AI-assisted request mutation and finding triage
- HTML / JSON / SARIF reports with CI exit-code gating
License
MIT — see LICENSE.
© CQR Cybersecurity LLC · part of the insom.ai security platform.
Project details
Release history Release notifications | RSS feed
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file pentester-0.0.2.tar.gz.
File metadata
- Download URL: pentester-0.0.2.tar.gz
- Upload date:
- Size: 4.5 kB
- Tags: Source
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/6.1.0 CPython/3.13.12
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
011e86fb85f6ae8cd95a801e2cb52fbbf56ca98506bb1325246e2a3f2f2d8753
|
|
| MD5 |
1208e798d62f5602473725b6f4141d48
|
|
| BLAKE2b-256 |
87aea5444af05c70529d86014c0daa3795a43344f7c003726526f5603cc847ed
|
Provenance
The following attestation bundles were made for pentester-0.0.2.tar.gz:
Publisher:
ci.yml on vulnz/pentester
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
pentester-0.0.2.tar.gz -
Subject digest:
011e86fb85f6ae8cd95a801e2cb52fbbf56ca98506bb1325246e2a3f2f2d8753 - Sigstore transparency entry: 1788484712
- Sigstore integration time:
-
Permalink:
vulnz/pentester@9bda1a778b8034bf3c49910afc14bffe7dad14ba -
Branch / Tag:
refs/tags/v0.0.2 - Owner: https://github.com/vulnz
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
ci.yml@9bda1a778b8034bf3c49910afc14bffe7dad14ba -
Trigger Event:
push
-
Statement type:
File details
Details for the file pentester-0.0.2-py3-none-any.whl.
File metadata
- Download URL: pentester-0.0.2-py3-none-any.whl
- Upload date:
- Size: 5.2 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/6.1.0 CPython/3.13.12
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
b087d14566b91bbb027481e92d300e316c106dd0d75a9b163b9ab31311cf79ba
|
|
| MD5 |
1cddee28b957cbf9e9528f946e60c37e
|
|
| BLAKE2b-256 |
eeb592409bc24c9f144fa0bdfb6ff680dcb3cd8252c45a4c07a1e7812061a240
|
Provenance
The following attestation bundles were made for pentester-0.0.2-py3-none-any.whl:
Publisher:
ci.yml on vulnz/pentester
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
pentester-0.0.2-py3-none-any.whl -
Subject digest:
b087d14566b91bbb027481e92d300e316c106dd0d75a9b163b9ab31311cf79ba - Sigstore transparency entry: 1788484754
- Sigstore integration time:
-
Permalink:
vulnz/pentester@9bda1a778b8034bf3c49910afc14bffe7dad14ba -
Branch / Tag:
refs/tags/v0.0.2 - Owner: https://github.com/vulnz
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
ci.yml@9bda1a778b8034bf3c49910afc14bffe7dad14ba -
Trigger Event:
push
-
Statement type: