An agentic network pentest tool you talk to.
Open a terminal session and chat with an agent that discovers hosts, fingerprints services, checks for known issues and reports what it confirms. It runs on your own model or a deterministic fallback, stays locked to the scope you set, and asks before anything intrusive. Read-only by default. Your model, your machine.
Authorized testing only. Every tool is locked to the target you name, and intrusive actions need your approval. Read the rules
network ├─ 10.0.0.5 │ ├─ 22 ssh OpenSSH 8.9 │ ├─ 80 http nginx 1.18 │ └─ [HIGH] exposed admin panel └─ 10.0.0.8 └─ 445 smb
The live map the agent builds as it goes, hosts to ports to service and version to findings. Call it up in-session with /topology.
- runs on
- Python 3.10+macOSLinuxwraps nmap + nuclei
- your model
- OpenAIDeepSeekAnthropicGeminiOllama (local)none, deterministic(must support tool calling)
- output
- full-screen terminal TUIfindings: severity + evidence + fixJSON (
--json)(example list)
A conversation with an agent on a leash.
pwner opens a full-screen terminal session you talk to in plain language. Ask it to scan a host or a range and it reasons about what it sees, calls the right tool, reads the result and keeps going, streaming its thinking as it works. It runs on your own model, local or hosted, or a deterministic fallback with no model at all.
Every tool is locked to the target you named and enforced outside the model, so the agent cannot wander off scope. Discovery, fingerprinting and detection are read-only; brute-force and anything active are denied by default and need your approval. It ships no exploits and no implants.
Authorized testing only. If you do not have written permission to test a network, do not point pwner at it.
scope lockEvery host-targeting tool refuses any address outside the target you named, enforced at the tool layer, not by the prompt.consent gatesBrute-force and other intrusive actions are denied by default and need your y/N. The agent cannot approve itself.read-only by defaultDiscovery, fingerprinting and detection only. No exploits or implants ship, and the raw nmap escape hatch blocks intrusive scripts.Set a key once, then just talk to it.
Install, run pwner once to set your provider and key, then open a session against a lab range and tell the agent what to do. The full walkthrough is in the docs.
pip install -e .
Examples, not live. The PyPI name, Docker image and registry paths are placeholders; nmap and nuclei are separate system binaries.
pwner # first run: set provider + key, opens the session pwner chat 10.0.0.0/24 # talk to the agent; it scans when you ask pwner scan 10.0.0.5 --no-ai # deterministic suite, no model needed