Developer builds multi-agent AI penetration testing engine with strict safety controls
A developer has released OIHK, an autonomous multi-agent AI penetration testing engine designed to go beyond simple LLM-in-a-loop approaches common in existing tools. The system uses a root planner that delegates tasks to specialist agents, requiring verified tool execution and a separate validation record before any result is classified as a finding. Safety is enforced at the infrastructure level, with active tools blocked by policy, network egress restricted to a compiled allowlist within a sandboxed namespace, and a hardened read-only environment with dropped system privileges. OIHK is provider-agnostic and works with any OpenAI-compatible endpoint, including locally hosted models. The project also includes a built-in evaluation suite that tests the engine against 16 deliberately vulnerable scenarios, scoring results programmatically rather than relying on a model to self-assess.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in