# HackAgent ships three tags in one afternoon and an archive without a browser

> A security testing toolkit for AI agents, with ten attack techniques, an LLM generator and judge, and local SQLite reporting. Its release cadence and its Playwright exception say more about how to use it than the threat table does.

**AISecurityLab/hackagent** — HackAgent is an open-source security toolkit to detect vulnerabilities of your AI Agents

- Repository: https://github.com/AISecurityLab/hackagent
- Website: https://docs.hackagent.dev
- Stars: 520 · Forks: 111
- Language: Python
- License: Apache-2.0
- Published: 2026-09-10 · Updated: 2026-09-10 · Language: en
- Canonical page: https://hysenlabs.com/projects/aisecuritylab-hackagent

## Three tags in under three hours, including a minor version

The release history compresses a week of work into an afternoon. v0.13.0 was tagged at 14:15 on 2026-09-21, v0.13.1 at 14:28 the same day, and v0.14.0 at 17:00, also the same day. So a patch release and then a full minor version went out within about three hours of each other, with the patch landing thirteen minutes after the minor version it would follow. The manifest version matches the newest tag at 0.14.0, and the package classifiers declare Development Status 4, Beta. If you are pinning, note that the two 0.13 tags are almost certainly not worth distinguishing, and that a minor version increment on the same afternoon as its own patch release is a signal about the pre-1.0 cadence rather than about breaking changes. The package also requires Python 3.10 or newer.

## The self-contained archive still needs a browser installed

Every release ships a per-platform archive so you can skip Python entirely. The table lists four: a tar.gz for Linux on x86_64, a tar.gz for macOS on arm64, a tar.gz for macOS on x86_64, and a zip for Windows on x86_64. You extract it and run the launcher inside, with no Python, pip or uv required. One filesystem constraint follows from that design: keep the extracted folder intact, because the launcher loads the libraries sitting next to it rather than resolving them from an installed environment. The documented exception to self-contained is the web provider, which drives a real browser through Playwright. Those browser binaries cannot be embedded in the archive or in the PyPI package, so you install them once with:

```bash
playwright install
```

Do that before touching any web-based target, since the failure otherwise appears at the point you expect the tool to work.

## An API key exists for reporting and the browser never receives it

Local mode stores results in SQLite and reads offline, and the quick install says no API key is required because the toolkit works locally out of the box. Cloud mode exists as an alternative: when a key is configured, runs sync to the remote platform. The web dashboard makes the boundary explicit. Running the web command serves the same application as the hosted one, from your own machine, pointed at cloud data when a key is configured and at the local SQLite database in read-only mode when it is not. The key stays in the CLI process and is never exposed to the browser, so the dashboard never holds a credential that a page script could read. That command is behind an extra rather than the base install:

```bash
pip install 'hackagent[web]'
```

The read-only fallback is the part worth remembering, because it means the dashboard is safe to run with no key and simply cannot mutate anything.

## Ten techniques behind one engine, judged by a second model

The pipeline has five components. The attack engine orchestrates ten named techniques: AdvPrefix, AutoDAN-Turbo, PAIR, TAP, FlipAttack, BoN, h4rm3l, CipherChat, PAP and a static template. The generator is an LLM role whose job is to create adversarial prompts aimed at the target agent. The judge is a second LLM role that decides whether an attack actually bypassed safety measures. The target agent is yours, run across the supported frameworks, which the badges identify as Google ADK, OpenAI, LiteLLM and LangChain. Datasets supply pre-built benchmark presets plus custom ones from HuggingFace, a file or a URL in JSON. Separately, the threat table names four categories: prompt injection as malicious inputs that hijack behaviour, jailbreaking as bypassing guardrails and content filters, goal hijacking as manipulating the agent toward unintended objectives, and tool misuse as exploiting capabilities for unauthorised actions.

## Playwright and a vector index are base dependencies, not extras

The dependency list is worth reading before you install, because it is larger than the local-tooling framing implies. Alongside the expected clients and CLI libraries, the core includes Playwright, Pillow, a CPU build of faiss, the datasets library, Flask and Litellm. So the browser automation driver is mandatory at install time even though the web provider that uses it is an extra, and a vector search index plus a dataset library are core rather than optional. That matters for two situations: a locked-down machine where an unpinnable transitive dependency blocks the whole install, and a container image where the size of a vector index you never use is pure overhead. The base also carries an email extra on pydantic and lower bounds only, with no upper bound anywhere in the runtime set, so a resolver is free to pick the newest release of each.

## Two development dependencies exclude Windows outright

The development group contains two entries gated on the platform. One is a local inference server pinned to a minimum version with a marker excluding Windows entirely, and the other is the transformers library with a range bounded above at version six and the same exclusion. One dependency in that group is the only one with an upper bound rather than a floor, the async pytest plugin. The consequence is an asymmetry between what contributors can test and what users can run. There is a Windows x86_64 release archive, so end users on Windows get the toolkit, but the local model stack that some attack techniques lean on cannot be exercised there during development. When a technique depends on a locally served model rather than a hosted one, expect the Windows asset to cover the pipeline around it rather than the technique itself.

## Responsible use is scoped to systems you have permission to test

The section is short and has no hedging. The toolkit is designed for authorised security testing only, and the instruction is to always obtain explicit permission before testing any AI system. The do list is: test your own agents, conduct authorised penetration testing, follow coordinated disclosure, and share security knowledge responsibly. The do not list is: test systems without permission, exploit vulnerabilities maliciously, violate terms of service, and share harmful exploit instructions irresponsibly. The full guidance sits in a responsible disclosure document in the repository rather than only in the README, and a separate disclaimer states the authors are not responsible for misuse. For a tool whose value depends on running real attacks against real agents, that framing is the actual usage boundary, since nothing in the code prevents the opposite.

## Conclusion

Use HackAgent when you own the agent or have written authorisation to test it, since the four threat categories it covers, prompt injection, jailbreaking, goal hijacking and tool misuse, are exactly the failures that appear once an agent has tools. Before you start, install the Playwright browsers if you intend to use the web provider, because the binary archives and the PyPI package deliberately cannot carry them. Budget for a heavier base install than the local framing implies, since Playwright, a vector index and a dataset library are core dependencies rather than extras, and note that the local inference stack used by some attacks is excluded on Windows.

## FAQ

### Do I need an API key to use hackagent?

No. The toolkit works locally out of the box, storing results in SQLite readable offline. An API key is only needed for cloud mode, where it stays in the CLI process and is never exposed to the browser.

### Which attack techniques does hackagent run?

Ten, orchestrated by the attack engine: AdvPrefix, AutoDAN-Turbo, PAIR, TAP, FlipAttack, BoN, h4rm3l, CipherChat, PAP and a static template.

### Can I run hackagent without installing Python?

Yes. Every release ships a self-contained archive for Linux x86_64, macOS arm64, macOS x86_64 and Windows x86_64. Extract it, keep the folder intact, and run the launcher, which loads libraries from beside itself.

### Why does hackagent ask me to run playwright install?

The web provider drives a real browser through Playwright, and those browser binaries cannot be embedded in the release archive or in the PyPI package. Install them once before using any web-based target.

### Which agent frameworks can hackagent test?

Google ADK, OpenAI, LiteLLM and LangChain are the supported frameworks named in the documentation links. Datasets come from pre-built benchmark presets or from custom HuggingFace, file or URL JSON.

### What Python version does hackagent need?

3.10 or newer, with classifiers through 3.13. Two development dependencies, a local inference server and the transformers library, are excluded on Windows, so some techniques are not exercised there during development.

## Sources

- [AISecurityLab/hackagent on GitHub](https://github.com/AISecurityLab/hackagent)
- [License: Apache-2.0](https://github.com/AISecurityLab/hackagent/blob/main/LICENSE)
- [Project website](https://docs.hackagent.dev)
- [README](https://github.com/AISecurityLab/hackagent/blob/main/README.md)
- [Releases](https://github.com/AISecurityLab/hackagent/releases)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/aisecuritylab-hackagent
