Armur-Ai/Pentest-Swarm-AI
Autonomous penetration testing using a swarm of AI agents. Orchestrates recon, classification, exploitation, and reporting specialists with ReAct reasoning — supports bug bounty, continuous monitoring, and CTF modes. Built with Go and 7+ native security tools.
About the project
Open-source XBOW alternative: an autonomous API and web-app pentester where dozens of AI agents run recon, exploitation, and reporting in parallel via a shared blackboard. For pentesters, bug bounty hunters, and red teamers.
Useful for
- Run an autonomous pentest across a subdomain list overnight
- Test an API for BOLA/IDOR, JWT forgery, and SSRF in a bug bounty scope
- Run the swarm in CTF mode to find and prove vulnerabilities
README summarized by DeepSeek V4.1 Flash. Details may be inaccurate.
Why it’s trending
- 13 stars so far today, about 24 expected by the end of the day. The usual pace is 6 per day, so that's 3.8× as much.
- Over the last two days the pace is 4× that of the previous week and a half.
- GitHub Trending Go today: #5, +35 stars.
- Recent forks include notable developers: @attacker-codeninja (209 followers).
Stars per day
Bars are daily stars, the line is the usual pace. Red marks spike days.
Numbers
- Total stars
- 2,608
- Today
- 13 · ≈ 24 by evening
- Forks
- 479
- Issues and pull requests
- 73
- Watchers
- 21
- Language
- Go
- License
- AGPL-3.0
- Latest release
- v0.2.26 · September 25, 2026
- Created
- March 26, 2024
- Last push
- September 25, 2026
Star trust
Growth looks organic: forks and discussion are in line with active projects, and stars arrive unevenly, the way people give them.
These are heuristics, not a verdict: we judge by the repository’s behavior, not by a list of stargazers.
Spotted in
- September 25, 2026GitHub Trending Go today: #5, +35 stars
Similar by description
-
0.2
Zyrexnn/Cybermes
Framework for automating authorized bug bounty and red teaming: the autonomous Hermes agent performs reconnaissance, orchestrates tools and validates vulnerabilities, and is also available as an MCP server for AI…
-
1.3
elder-plinius/T3MP3ST
Multi-agent red-teaming platform that turns an existing AI coding agent into a vulnerability-hunting harness, automating the recon → exploit → report kill chain for web apps, CTFs, smart contracts, and source code.
-
1.8
vxcontrol/pentagi
Autonomous multi-agent system in Go for automated penetration testing: AI agents plan and execute steps in an isolated Docker sandbox with 20+ tools (nmap, metasploit, sqlmap).