Open-source project
Armur-Ai/Pentest-Swarm-AI avatar
Armur-Ai/Pentest-Swarm-AI

Pentest Swarm AI: An Open-Source Swarm Harness for Autonomous Pentesting

Autonomous penetration testing using a swarm of AI agents. Orchestrates recon, classification, exploitation, and reporting specialists with ReAct reasoning — supports bug bounty, continuous monitoring, and CTF modes. Built with Go, Claude API, and 7+ native security tools.

2,702 stars494 forksGoAGPL-3.0

At a glance

What is it?
Pentest Swarm AI orchestrates dozens of AI agents through a stigmergic blackboard, not a fixed pipeline. Built in Go with Claude API support and local model options, it targets authorized pentests, bug bounty, and CTFs, but its AGPL license and early-stage maturity demand scrutiny.
Who is it for?
Adopt Pentest Swarm AI if you need an open-source, swarm-based pentesting harness that can run fully local with Ollama and supports authorized testing, bug bounty, or CTF scenarios. Do not use it if you require a stable, production-grade tool with extensive documentation, or if you cannot comply with AGPL-3.0 obligations.
Can I use it commercially?
Yes, with strict conditions. AGPL-3.0 is a network copyleft licence: if people use a modified version over a network, for example as a hosted service, you must offer them its source code under the same licence.
Is it still maintained?
Yes. The repository last received commits 6 days ago.
What is it written in?
Mainly Go, according to GitHub's language statistics.

Answers come from the project's GitHub data, last synced on October 2, 2026, and from our analysis. They are not legal advice.

Editorial analysis

What Problem This Solves and Who It Is For

Pentest Swarm AI addresses the gap between automated scanners that produce thousands of unverified findings and human consultants who exploit but are expensive and infrequent. The README frames this as a race against attackers who automate, while most pentests do not. The intended users are security teams running authorized penetration tests, bug bounty hunters, CTF participants, and researchers who want to experiment with AI-driven offensive security. The tool aims to exploit findings and prove them with captured evidence, then generate a report, all without a central planner dictating the order of operations. This is not a tool for casual or unauthorized scanning; the legal disclaimer is explicit about requiring written permission from target owners.

Swarm vs. Pipeline: The Core Architectural Claim

The project distinguishes itself from other multi-agent tools by claiming a real swarm rather than a pipeline. In a pipeline, a single planner LLM dispatches agents in a fixed order: recon, classify, exploit, report. Pentest Swarm AI uses three swarm-intelligence primitives. Stigmergy means agents coordinate by reading and writing findings on a shared blackboard, not through central instructions. Each finding carries a pheromone weight that biases other agents toward it and decays over time, so stale paths fade. Emergence means attack chains can appear that no single agent planned; a recon finding wakes the classifier, a high-severity classification wakes the exploit agent, and results feed back to the report agent. Decentralization means each agent runs its own trigger predicate, so adding a new agent does not require rewriting the orchestrator. This is a genuine architectural difference from linear chains, but the README does not provide implementation details beyond referencing IMPLEMENTATION_PLAN.md.

How the Swarm Works: Blackboard, Pheromones, and Triggers

The mechanism relies on a shared blackboard, which the README describes as Postgres-backed, though the truncated material does not show the schema or API. Agents read and write findings to this board. A finding's pheromone weight biases other agents toward it, and the weight decays per-finding-type. For example, a PORT_OPEN finding stays hot for hours, while other types may decay faster. Each agent has a trigger predicate that determines when it wakes. When a finding lands, the relevant agents are activated. This allows a 1,000-subdomain target to be worked in parallel, as multiple agents can process different parts of the surface concurrently. The README claims this achieves machine speed, but no benchmark numbers are provided to substantiate that. The implementation is in Go, and the codebase includes 7+ native security tools, though the specific tools are not enumerated in the provided material.

Getting Started: Commands, Providers, and the Lab Mode

Installation offers three paths: Homebrew with brew install Armur-Ai/tap/pentestswarm, Go with go install github.com/Armur-Ai/Pentest-Swarm-AI/cmd/pentestswarm@latest, or Docker with docker run --rm ghcr.io/armur-ai/pentestswarm:latest --help. The quick start emphasizes a no-key, local option: pentestswarm scan --lab --provider ollama --swarm --follow spins up OWASP Juice Shop locally, points the swarm at it, and tears it down after. For a real target with a local model, the command is pentestswarm scan <authorized-target> --scope <target> --provider ollama --swarm --follow. For cloud models, set the environment variable PENTESTSWARM_ORCHESTRATOR_API_KEY and run a similar command without --provider ollama. There is also a demo command, pentestswarm demo, that plays the whole campaign offline. The README mentions a GitHub Actions workflow in deploy/github-action/example-workflow.yml, but the file is not shown.

Model Flexibility and Local Operation

The tool claims to run on any model: Claude, anything OpenAI-compatible, security-tuned open models like Pentest-R1, or fully local Ollama and LM Studio. This is a significant advantage for organizations that need air-gapped operation or zero API cost. The README states that not one byte of your data leaves your box when using local models. However, the quality of results likely depends on the model's capability; the README suggests cloud models offer 'max quality' but provides no comparison. The harness provides tools, swarm coordination, scope safety, and evidence-backed reports, positioning itself as the layer that gives models hands. This modularity is useful, but it also means users must manage model selection and possibly tune prompts, which the README does not detail.

Limitations and Failure Modes

The project is at version v0.1.0 with a single release, so it is early-stage. The README is promotional, using phrases like 'the only open-source pentester built on a real swarm' and 'the category was empty,' which invite skepticism. No performance data, success rates, or false-positive rates are provided. The reliance on LLM reasoning means results are probabilistic; a model may miss vulnerabilities or produce false positives. The blackboard design, while elegant, introduces complexity: if the Postgres backend fails or pheromone decay is misconfigured, agents may not coordinate correctly. Scope safety is mentioned, but the README does not explain how it enforces boundaries beyond the --scope flag. For unauthorized testing, the tool is clearly the wrong choice; the legal disclaimer is strong, but a tool that automates exploitation could be misused, so users must have explicit authorization. The AGPL-3.0 license also imposes obligations if you modify and distribute the code, which may be a barrier for some organizations.

Alternatives and Different Approaches

The README credits several projects as inspiration, including PentestGPT, PentAGI, Strix, and HackingBuddyGPT. PentAGI is a fully autonomous agent architecture, but it likely uses a single agent or a more centralized planner. HackingBuddyGPT is described as LLM hacking in 50 lines of code, which suggests a simpler, script-driven approach rather than a swarm. The key difference is that these alternatives typically use a single LLM or a fixed pipeline, whereas Pentest Swarm AI uses decentralized agents with stigmergic coordination. If you need a lightweight, quick prototype, HackingBuddyGPT might be easier to adopt. If you need a more mature, community-supported framework, PentAGI may have more documentation and stability. The README claims that no other tool uses a real swarm, but that is a bold assertion that users should verify by inspecting the code and comparing with newer projects.

Maintenance, Upgrade Cost, and License Implications

The project is actively maintained, with the last push and v0.1.0 release on 2026-05-07, but that is only one release. The roadmap is in IMPLEMENTATION_PLAN.md, which is referenced but not included in the material. Upgrade cost is unknown; as a v0.1.0, breaking changes are likely. The AGPL-3.0 license means that if you modify the code and provide it as a network service, you may need to release your modifications under the same license. This is a significant consideration for commercial use. The README does not discuss how to contribute or whether there is a stable API. For a security tool, the lack of detailed documentation is a risk; users must rely on the README and the code itself. Before adopting, verify that the tool's behavior matches the claims, especially the swarm coordination, by running the lab mode and inspecting the generated reports.

Editorial conclusion

Adopt Pentest Swarm AI if you need an open-source, swarm-based pentesting harness that can run fully local with Ollama and supports authorized testing, bug bounty, or CTF scenarios. Do not use it if you require a stable, production-grade tool with extensive documentation, or if you cannot comply with AGPL-3.0 obligations. Before adoption, verify the current state of the codebase, test the --lab mode against OWASP Juice Shop, and confirm that your target scope is explicitly authorized. The project is at v0.1.0 with a single release, so treat it as an experimental framework rather than a mature replacement for commercial pentesting services.

Frequently asked questions

Is running Pentest Swarm AI against a site legal?

Only with written permission. The project states it is designed exclusively for authorized security testing, bug bounty programs, CTF competitions, and educational research, that you must obtain explicit written permission from the target system owner before running any scan, and that it must not be used against systems you do not own or have explicit authorization to test. It cites the Computer Fraud and Abuse Act, the Computer Misuse Act, and equivalent laws worldwide, and accepts no liability.

Which model does Pentest Swarm AI need, and can it run offline?

The module pins the Anthropic Go SDK, and the project says it also runs on anything OpenAI compatible, on hosted Llama, Qwen, and DeepSeek models through Together AI, on security tuned open models such as Pentest-R1, and on a fully local Ollama or LM Studio setup. In the container the orchestrator key is passed as the PENTESTSWARM_ORCHESTRATOR_API_KEY environment variable.

What does Pentest Swarm AI claim that a scanner does not?

That its agents exploit what they find and prove it with captured evidence before reporting, rather than emitting unverified findings. The three coordination primitives are a shared blackboard whose pheromone weights decay over time, attack chains that emerge from blackboard state rather than being scripted, and a trigger predicate per agent so a new agent can join without the orchestrator being rewritten.

Does Pentest Swarm AI have a dry run or a way to stop a scan?

No documented option. The commands the project gives name a config directory, a list of config names, and an orchestrator API key, and none of them offers a dry run, a target allowlist, or an abort switch. Since agents are woken by findings landing on a shared blackboard, new work is generated by the target's own responses. Find out how scope is enforced in your own configuration before pointing it at anything.

Official sources

  1. Official README
  2. Project repository
  3. Release notes
Add this badge to your README

If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.

Add this badge to your README

markdown
[![Hysen Labs](https://hysenlabs.com/badge/armur-ai-pentest-swarm-ai.svg)](https://hysenlabs.com/projects/armur-ai-pentest-swarm-ai)