Overview
LuaN1aoAgent is an open-source autonomous agent for authorized penetration testing and security research. You give it a goal and an authorized scope (IPv4 addresses, CIDRs or domains) and it plans the engagement, runs tools against the in-scope targets and records what it finds. Version 2, released in July 2026, is a complete rewrite in TypeScript on the Pi SDK; the earlier Python implementation is kept on the project's v1 branch and v1.0.0 release.
The work is split across three roles. A Planner keeps an evolving Task Graph of goals, dependencies, budgets and scope, patching the affected tasks when new evidence arrives instead of regenerating a linear checklist. Executors each take one bounded task and choose their own tool loop inside an isolated workspace. An Observer runs in two modes: a Supervisor that decides whether an Executor should continue, checkpoint or hand control back, and a Projector that turns observations into a Reasoning Graph linking evidence to hypotheses, confirmed vulnerabilities and successful exploits. Confirmed vulnerabilities and exploits cannot be written to the graph without evidence references.

Every run is persisted as a session on disk — a SQLite state store, an append-only execution log, replayable graph deltas and content-addressed artifacts — so a run can be resumed and inspected later from an interactive terminal timeline or an authenticated web workbench. The project states that it is intended only for authorized security testing, controlled research and education: you must have explicit authorization from the owner of every tested system, and should run it on an isolated host, VM or container because Executor tools can run shell commands. It is licensed AGPL-3.0, with a commercial licence available from the maintainer.
What it does
- Planner–Executor–Observer architecture with schema-validated hand-offs, dependency-aware parallel task scheduling and per-task and global run-time budgets
- Causal graph reasoning: a Reasoning Graph that traces evidence into hypotheses, confirmed vulnerabilities and exploits, cross-linked to an Operation Graph of concrete hosts and services

- Sandboxed execution: a per-task Docker Executor on a private network whose only exit is a Gateway that enforces the authorized scope, with macOS Seatbelt and Linux Bubblewrap as fallbacks
- Built-in research tools — web_fetch, web_search, vulnerability_search against NVD and public advisories, and browser_render for post-JavaScript DOM inspection
- Traffic capture of HTTP flows from Executors, viewable in the web workbench, with administrator-only replay of captured requests
- Resumable sessions plus two observation surfaces: an interactive terminal timeline and an authenticated web workbench with live trace, task, reasoning and operation graph views
Getting started
LuaN1aoAgent runs on macOS or Linux with Node.js 25 or later and an OpenAI-compatible LLM API; Docker is recommended for the sandboxed Executor backend. Only point it at systems you are explicitly authorized to test, from an isolated host, VM or container.
Clone and build
Install dependencies, build the project, and build the two Docker images used by the preferred backend. Alternatively, ./install.sh does all of this and also installs the recommended community security skill collections.
git clone https://github.com/SanMuzZzZz/LuaN1aoAgent.git
cd LuaN1aoAgent
npm ci
npm run build
# Required for the preferred Docker backend
npm run build:executor-image
npm run build:network-imageConfigure the LLM
Create a local .env file with your OpenAI-compatible endpoint and model. The file is git-ignored and must never be committed.
LLM_API_KEY=your-api-key
LLM_API_BASE_URL=https://api.openai.com/v1
LLM_DEFAULT_MODEL=your-model-id
# Optional: openai-completions or openai-responses
LLM_API_TYPE=openai-completionsStart a run against an authorized scope
--scope is the network authorization root; traffic outside it is rejected. In a TTY the interactive timeline starts automatically. Use --jsonl to stream durable events for another process, and --resume <session> to continue an unfinished session.
npm start -- \
--goal "Inspect the authorized target 127.0.0.1" \
--scope "127.0.0.1/32" \
--max-parallel-tasks 2Open the web workbench
Point the authenticated web service at a session directory and open http://127.0.0.1:8787. The first registered user becomes the administrator.
npm run web -- --runtime-dir .agent-runtime/sessions/<session> --port 8787Commands and code are distilled from the project's own documentation — always check the official repo for the latest.
When to use it
- Run an autonomous, scope-restricted assessment of a lab network or host you are authorized to test, with parallel recon and validation tasks
- Keep an auditable record of an engagement, where each confirmed vulnerability links back to the events and artifacts that support it
- Work through CTF and training-range targets with community security skill collections loaded into the Executor
- Research how graph-based planning and evidence projection behave in an autonomous security agent, using the persisted sessions and graph deltas
How LuaN1aoAgent compares
LuaN1aoAgent alongside other open-source security agents tools AI/TLDR tracks, ranked by GitHub stars.
| Tool | Stars | What it does |
|---|---|---|
| PentAGI | ★ 25.2k | PentAGI is a self-hosted AI security platform that plans and runs penetration tests autonomously using a team of agents and 20+ built-in pentesting tools. |
| PentestGPT | ★ 15.7k | An open-source agent that uses large language models to run penetration tests and solve security challenges, either fully autonomously or with a human in the loop. |
| IDA Pro MCP | ★ 12.4k | An MCP server and IDA Pro plugin that exposes decompilation, cross-references, renaming and type editing to an LLM client, letting an agent read and annotate a binary inside your IDA database. |
| HexStrike AI | ★ 12.3k | An MCP server that gives an AI agent a single interface to 150+ installed security tools — Nmap, Nuclei, SQLMap, Ghidra, Hashcat and more — so it can drive reconnaissance, scanning and binary analysis itself. |
| CAI | ★ 9.8k | CAI (Cybersecurity AI) is an open-source Python framework for building AI agents that automate offensive and defensive security tasks like recon, vulnerability discovery, and exploitation. |
| AI-Infra-Guard | ★ 6.7k | Tencent Zhuque Lab's AI red teaming platform: scans agents, Agent Skills and MCP servers, checks AI infra against a CVE library, fingerprints API relays and runs jailbreak evaluations. |
| T3MP3ST | ★ 6.3k | A multi-agent offensive-security harness for authorised testing that drives an already-installed coding agent, or a local OpenAI-compatible model, through recon, exploitation and reporting from a localhost War Room or the CLI. |
| LuaN1aoAgent | ★ 1.3k | An autonomous penetration-testing agent for authorized targets that plans on a task graph and backs every finding with a traceable chain of evidence |