Open source · Apache 2.0 · Local-first
Autonomous security assessment. Operator supervised.
Open-source agentic operator for authorized testing — plans, verifies, and reports with evidence, target-locked and audited.
Authorized testing only — safety model · docs
curl -fsSL https://breachpilot.dev/install.sh | bashTarget — authorized lab only
127.0.0.1 · lab
allowlist: 127.0.0.1 · LOCKED
- Recon
- Initial Access
- Verify
- Report
Agent activity
- recon › run_full_recon → 443/http open
- vuln › CVE-2024-xxxx ↔ web module (87/100)
- critic › BLOCKED egress to non-allowlist host · denied
- exploit › craft_exploit → attempt A-12
Evidence
- H-03 PROBECONFIRMED
- audit chain · sha2569f3a…c41d
Illustrative lab run against 127.0.0.1 — BreachPilot tests only allowlisted targets and blocks everything else.
- 139
- advisory skills
- 153
- MCP tools
- 15
- attack families
- 6
- swarm agents
- 33
- tool families
Live counts from the repository catalog.
Why BreachPilot
A full assessment lifecycle, under supervision
Recon to report in one supervised engine, with proof.
Adversarial planning
Structured AttackPlan DAG with retries and failure recovery.
decision_log.jsonl per run
Target-locked execution
Allowlist + mission scope gate on every action.
off-allowlist BLOCKED · SCOPE_DENIED logged
Evidence-based verification
Execution success and evidential success are separate.
CONFIRMED / REFUTED / EXHAUSTED + oracle probes
Domain-aware recon
Domain in, scope-aware attack surface out.
CT / DNS / subfinder · takeover flags
Persistent knowledge
Lessons survive the run.
139 skills · semantic + Bayesian scoring
Multi-agent orchestration
Six specialists, one shared blackboard
Parallel dispatch with battle logs and cross-phase negotiation — plus a persistent orchestrator for extended campaigns.
Shared blackboard + battle log
Swarm Orchestrator
parallel dispatch · cross-phase negotiation
Attack graph
A structured plan, not a prompt chain
Every run builds an AttackPlan DAG — ready/blocked steps and evidence, live in the WebUI graph.
- Target127.0.0.1 · allowlisted
- Reconports · services · OS
- HTTP :443fingerprint · WAF check
- Web Analysissurface scoring
- HypothesisH-03 · testable claim
- Verificationoracle probe · evidence
- FindingCONFIRMED / REFUTED
- Reporttimeline · CVSS · chains
prerequisites · hypotheses · blocked steps · evidence-linked outcomes
Inside BreachPilot
Mission control for the whole run
Loopback-only console at 127.0.0.1:8765 — wizard, stream, graph, evidence and more in one place.
- recon › run_full_recon → 4 ports
- vuln › CVE-2024-xxxx ↔ module 87/100
- critic › scope PASS · in-allowlist
Screenshots
The real WebUI
Console captures from a local lab run — not mockups.
screenshot pending
Add public/screenshots/run-creation.png
screenshot pending
Add public/screenshots/attack-graph.png
screenshot pending
Add public/screenshots/evidence-findings.png
screenshot pending
Add public/screenshots/final-report.png
Built for authorized security testing
Only test systems you own or have explicit written permission to assess.
Attack mode auto-approves in-scope actions — the safeties are the target-IP allowlist lock and the mission scope gate, with every action in a tamper-evident audit chain.