OIHK Pentesting Agent Learns from Past Failures to Improve Future Security Scans
A developer has released a major rebuild of OIHK-Pentesting, an open-source multi-agent framework designed to run authorized penetration tests using a large language model planner called Baron. The updated system can split assessment plans into parallel subtasks, launching up to seven simultaneous AI agent loops inside a governed Kali Linux sandbox. A key new feature records missed or failed scan attempts into a local JSONL ledger, automatically injecting weighted lessons into Baron's future prompts so the agent improves over time without retraining. Safety guardrails include strict scope enforcement, a closed-egress network allowlist, mandatory evidence for every finding, and a resource budget system that prevents hardware overload by capping active Docker containers. The tool is intended solely for use by security professionals with written authorization over their target systems.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in