Model or dataset
NoDataFound/hackGPT avatar
NoDataFound/hackGPT

hackGPT ships a jailbreak prompt file and documents writing fixes back into your issue tracker, so it belongs on systems you are authorised to test

I leverage OpenAI and ChatGPT to do hackerish things

1,216 stars308 forksJupyter NotebookLicense varies

At a glance

What is it?
hackGPT is a Jupyter notebook project that drives OpenAI and ChatGPT for security work, and it has accumulated a decade of generations in one repository root. This article is a description of what the repository actually contains and where its own instructions contradict themselves. Nothing here is a procedure, and the project is not something to point at a machine you have not been authorised to test.
Who is it for?
hackGPT is worth a look as an artefact if you are studying how prompt-driven security tooling accretes over years, because the repository root documents its own drift better than any retrospective would.
Can I use it commercially?
Not without permission. GitHub finds no licence file in the repository, and without a licence all rights are reserved by default: you may read the code but not reuse it. Check the README, or ask the authors, before using it.
Is it still maintained?
Yes. The repository last received commits 53 days ago.
What is it written in?
Mainly Jupyter Notebook, according to GitHub's language statistics.

Answers come from the project's GitHub data, last synced on October 4, 2026, and from our analysis. They are not legal advice.

Editorial analysis

The documented clone step names a different repository

The installation section has one step labelled clone this repo, and the command under it is:

code
git clone https://github.com/NoDataFound/PwnAI.git

The alternative method immediately below it, labelled clone via SSH, clones this repository instead. So the two ways offered fetch two different projects, and the one presented as the default is not the one you are reading about. The same drift appears at run time. The Use Python section gives `python3 PwnAI.py` for a single search and `python3 PwnAI_bulk.py` for bulk searches, and neither filename appears among the repository's top-level entries. The mobile demo also links to a Colab notebook at a repository-root path that the directory listing does not contain. Follow the README top to bottom and the last thing you are told to run belongs to something you did not download.

Eighteen dependencies, none of them pinned

requirements.txt is eighteen lines with no version constraints at all. The heavyweight entries are `torch`, `transformers`, `gradio`, `huggingface-hub`, and `openai`. The rest are small and mostly community-maintained: `streamlit-chat`, `streamlit-extras`, `hugchat`, `directory_structure`, `alive_progress`, `fade`, `inquirer`, `ipywidgets`, `prettytable`, `jira`, `python-dotenv`, `tqdm`, and `pathlib`. That last one is the problem. `pathlib` has been part of the Python standard library since 3.4, so a line asking pip to install it either resolves to a third-party package that happens to share the name or fails outright, and either way it is a sign the file was assembled by appending names rather than by resolving them. With no floors anywhere, the environment you end up with is whichever versions happened to be current on the day you ran the install.

One root, several generations of the same tool

The top-level listing is the clearest thing about this project. Alongside the README and the requirements file sit `hackGPT.py`, `hackGPTv23.py`, `JIRA_hackGPT.py`, a `hackGPT_local/` directory, a `hackerParents/` directory, a `hackthropic/` directory named after a different model vendor, a `dev_hackGPTp/` directory, and a `PwnAI_depreciated/` directory whose name misspells deprecated. Then the supporting material: `chatbot/`, `mobile/`, `notebooks/`, `personas/`, `res/`, `slidedecks/`, `input/`, `output/`, and a `.devcontainer/`. Two entry points for the same idea, one name misspelled, one folder named for a competitor, one for a parent process, one for development. The current version is not identified anywhere in the README, and the repository has no GitHub releases, so nothing tells you which of these is meant to be run.

A jailbreak prompt file sits at the repository root

`jailbreaks.csv` is in the top-level listing, next to `README.md` and `requirements.txt`. Whatever is inside it, a file with that name at the root of a public repository is a prompt collection built to get a model to ignore its own boundaries, and it is versioned alongside the code. A `personas/` directory sits beside it, which in an agent project usually means role definitions the model is asked to adopt. Neither is explained in the README, which is around 180 words of body text once the code blocks are removed. That is worth stating plainly, because the risk profile of this repository is not obvious from its description, which is a single first-person sentence about leveraging OpenAI and ChatGPT to do hackerish things.

The README is a list of captions and hosted videos

Almost every line of the README is a short label followed by a link to an mp4 or mov file hosted on a GitHub user-images URL. The labels include PrettyTable for logging with the chatbot opening in a new browser tab, hackGPT enabled Siri, hackGPT being superduper wrong, the chatbot on mobile via Colab, and a clip titled ask ChatGPT to print its own source. The substantive claims are two. One advertises automating the parsing and analysis of JSON threat data from CyberDefense tools, pointing at a separate SecurityScorecard ASI API repository. The other advertises automating CVE exploit creation and CyberDefense protections, with results linked into a `PwnAI/output` directory. Whether that output directory is populated, current, or reproducible is not stated, and the release history that would tell you is absent.

One documented flow writes into a shared issue tracker

The first line of the README describes hunting for JIRA issues filtered by type, fixing them, and committing the fix back to the ticket as a comment. That is an authenticated outbound write to a tracker your team reads, driven by generated text, and it is the single most consequential behaviour the project documents. The dependency list corroborates it with `jira` in the install set. The bundled input sample that the README tells you to inspect with `head -n 10 input/malware/malware_sample && head -n 10 input/sample_sources` is shaped for that flow: it is a bug-record document with fields for an issue title, an author, a vendor homepage, affected and tested-on versions, a CVE identifier, and links out to a write-up and to a payload repository. This article does not reproduce the sample's contents. The point for a reader deciding whether to trust the tool is the shape of the record and the direction of the write.

Licence, versions, and identity are all left open

Three things a reader would look for first are absent. The licence resolves to nothing in the repository metadata and there is no LICENSE file among the top-level entries, so the terms are undetermined rather than merely unlabelled. There are no GitHub releases and no version marker in the README, so the two entry-point scripts that do exist cannot be tied to a release. And the identity is inconsistent at the smallest level: the metadata homepage is written as `http://hackGPT.com`, while the README's live-demo link is written `https://hackgpt.com`. That last point matters for more than tidiness. The project name collides with a separate, commercial product of a similar name, and the surrounding search results are mostly about that other product rather than this notebook, so anything you read about hackGPT elsewhere is unlikely to describe the code in this repository.

Editorial conclusion

hackGPT is worth a look as an artefact if you are studying how prompt-driven security tooling accretes over years, because the repository root documents its own drift better than any retrospective would. It is not something to run outside a lab: point it only at systems you have written authorisation to test, treat any key you give it as compromised, and keep it away from production issue trackers, because one documented flow commits generated fixes back into shared tickets as comments. Before running anything, read the licensing position yourself, since no licence file is present and the repository metadata does not resolve one, and check that the code you actually got is the code you meant to clone, because the README's own clone step names a different repository.

Frequently asked questions

What is hackGPT and what does it do?

hackGPT is a Jupyter notebook project that drives OpenAI and ChatGPT for security tasks. Its README claims two capabilities: parsing and analysing JSON threat data from CyberDefense tools, and automating CVE exploit creation and CyberDefense protections. It is a research and demonstration artefact, and its own documentation asks for a sandbox.

Is hackGPT safe to run?

Only on systems you have written authorisation to test. The project drives a language model that produces and runs security tooling, its documentation includes a flow that commits generated fixes back into shared JIRA tickets, and the repository root contains a jailbreak prompt collection. Treat any API key given to it as exposed, and keep it away from production trackers and production data.

How do I install hackGPT?

The README's own steps are inconsistent: the step labelled clone this repo clones the PwnAI repository, while the SSH alternative clones hackGPT. After that it suggests an optional virtual environment with `python3 -m venv env` and `source env/bin/activate`, then `python3 -m pip install -r requirements.txt`, and finally `pip3 install jupyter notebook` to open the notebook.

What license is hackGPT under?

It is not stated. No licence value appears in the repository metadata, and there is no LICENSE file among the top-level entries, which include the README, requirements.txt, the Python entry points, and the input and output directories. There are also no GitHub releases, so there is no release to inspect for a licence either.

What files are in the hackGPT repository?

The top level holds `hackGPT.py`, `hackGPTv23.py`, `JIRA_hackGPT.py`, a `hackGPT_local/` directory, a `hackerParents/` directory, a `hackthropic/` directory, a `dev_hackGPTp/` directory, a `PwnAI_depreciated/` directory whose name misspells deprecated, plus `chatbot/`, `mobile/`, `notebooks/`, `personas/`, `res/`, `slidedecks/`, `input/`, `output/`, `jailbreaks.csv`, and a `.devcontainer/`.

Official sources

  1. Issues
  2. NoDataFound/hackGPT on GitHub
  3. Project website
  4. README
Add this badge to your README

If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.

Add this badge to your README

markdown
[![Hysen Labs](https://hysenlabs.com/badge/nodatafound-hackgpt.svg)](https://hysenlabs.com/projects/nodatafound-hackgpt)