Overview
CAI (Cybersecurity AI) is a lightweight, open-source framework for building and running AI agents focused on security work. It gives researchers, ethical hackers, and IT teams the building blocks to create specialized agents that help with reconnaissance, vulnerability discovery, exploitation, and broader security assessment.
The framework is agent-centric and modular: you assemble agents, attach tools, and connect them with handoffs and reusable patterns. It works with more than 300 models through LiteLLM, so you can plug in providers such as OpenAI, Anthropic, DeepSeek, or a local Ollama model. CAI also includes guardrails against prompt injection and dangerous commands, plus integrated logging and tracing through Phoenix.
CAI ships as the pip package cai-framework and runs on Linux, macOS, Windows (via WSL), and Android. You can run it in open-source mode without an Alias license by setting an environment variable, using your own model provider keys.
What it does
- Agent-based architecture: build modular, specialized agents for different security tasks and connect them with handoffs and reusable patterns
- 300+ model support via LiteLLM, including OpenAI, Anthropic, DeepSeek, and local Ollama models
- Built-in security tools for reconnaissance, exploitation, and privilege escalation, plus easy integration of your own tools
- Guardrails that defend against prompt injection and dangerous command execution
- Integrated logging and tracing through Phoenix for detailed traceability of agent runs
- Human-in-the-loop (HITL) controls so a person can stay in the loop during agent execution
Getting started
CAI is distributed as the cai-framework package on PyPI. Install it into a Python 3.12 virtual environment, then launch the cai command. You can run it in open-source mode without an Alias license and bring your own model provider keys.
Create a virtual environment and install
Set up a Python 3.12 virtual environment, activate it, and install the Community Edition from PyPI.
python3.12 -m venv cai_env
source cai_env/bin/activate && pip install cai-frameworkRun without an Alias license
Set CAI_LICENSE_OFF to bypass the license check and run in open-source mode, then start CAI. The first launch can take up to 30 seconds.
export CAI_LICENSE_OFF=1
caiConfigure your model and keys
CAI loads settings from a .env file at launch. Choose a model with CAI_MODEL and supply the matching provider key. Note that OPENAI_API_KEY must not be left blank; use a placeholder like sk-1234 if you are using another provider.
OPENAI_API_KEY="sk-1234"
CAI_MODEL="openai/gpt-4o"
CAI_STREAM=FalseCommands and code are distilled from the project's own documentation — always check the official repo for the latest.
When to use it
- Building AI agents that assist with bug bounty work, from initial reconnaissance to vulnerability validation
- Running automated security assessments to discover and exploit vulnerabilities in target systems
- Researching and benchmarking how different LLMs perform on offensive and defensive cybersecurity tasks
- Practicing on CTF challenges and security labs with AI agents that keep a human in the loop
How CAI compares
CAI alongside other open-source security agents tools AI/TLDR tracks, ranked by GitHub stars.
| Tool | Stars | What it does |
|---|---|---|
| PentAGI | ★ 25.2k | PentAGI is a self-hosted AI security platform that plans and runs penetration tests autonomously using a team of agents and 20+ built-in pentesting tools. |
| PentestGPT | ★ 15.7k | An open-source agent that uses large language models to run penetration tests and solve security challenges, either fully autonomously or with a human in the loop. |
| IDA Pro MCP | ★ 12.4k | An MCP server and IDA Pro plugin that exposes decompilation, cross-references, renaming and type editing to an LLM client, letting an agent read and annotate a binary inside your IDA database. |
| HexStrike AI | ★ 12.3k | An MCP server that gives an AI agent a single interface to 150+ installed security tools — Nmap, Nuclei, SQLMap, Ghidra, Hashcat and more — so it can drive reconnaissance, scanning and binary analysis itself. |
| CAI | ★ 9.8k | Open-source framework for building AI agents that test and defend security |
| AI-Infra-Guard | ★ 6.7k | Tencent Zhuque Lab's AI red teaming platform: scans agents, Agent Skills and MCP servers, checks AI infra against a CVE library, fingerprints API relays and runs jailbreak evaluations. |
| T3MP3ST | ★ 6.3k | A multi-agent offensive-security harness for authorised testing that drives an already-installed coding agent, or a local OpenAI-compatible model, through recon, exploitation and reporting from a localhost War Room or the CLI. |
| RedAmon | ★ 2.9k | A Docker-deployed offensive-security platform for authorised testing that chains parallel recon, exploitation and post-exploitation into a Neo4j attack graph, then triages the findings and opens remediation pull requests on your repository. |
