An AI pentest environment built for pentesters, red teamers, and security researchers.

Describe your objective and investigate with an agent that finds the tools, runs the commands, and keeps the evidence.

I’ll map the lab organization’s public assets, correlate exposed services, and prioritize potential entry points.

$ subfinder -d atlas.test -silent
api.atlas.test
staging.atlas.test
vpn.atlas.test

Staging and the remote-access portal deserve further investigation. I’ll verify their configuration before treating either as an entry point.

Wrote /engagement/atlas/attack-surface.md
▣ Build · Grepleaks
Build · Grepleaks grepleaks
tab to enable Auto modectrl+p commands

Less setup.
More investigation.

120+Pentest skills

Specialized playbooks covering most pentest scopes, giving the agent practical guidance throughout your assessment.

900+Tools on demand

The agent searches its catalogue, installs the tools your task needs, uses them, and cleans up afterward. No manual toolbox setup.

DockerA ready-to-work environment

A Linux environment for your pentest tools. Run them in Docker and keep reports, scripts, and evidence in your local engagement folder.

One key.
Three unrestricted models.

The Grepleaks key plugs you into three unrestricted reasoning models. Add it once and move between all three from inside Grepleaks.

Unrestricted models keep working on legitimate, authorized security tasks that aligned models refuse, so an engagement never stalls mid-run.

Your next investigation
starts here.

macOS / Linux
curl -fsSL https://raw.githubusercontent.com/grepleaks/grepleaks/main/scripts/install.py | python3 - --repository grepleaks/grepleaks

A few things
worth knowing.

Is Grepleaks free?

The environment is free and runs locally. Model access uses the Grepleaks key, one key for the unrestricted models. Model usage is billed through the key.

Do I need Docker?

Yes. Grepleaks runs its Linux toolset in a disposable container, so nothing security-related installs on your machine. Plan about 4 GB of disk for the first build.

Which systems are supported?

Launchers for macOS, Windows and Linux are included; Docker does the heavy lifting. Host commands are validated on macOS today, and native Windows/Linux pairing stays in preview until it passes the same checks.

How do I update?

Run the install command again. Docker’s cache makes updates fast, and grepleaks --version shows what you run. Your keys, sessions and engagement files are never touched.

Where does my data go?

Tools run in the local container and engagements stay on your machine. Prompts and tool output go to the model that runs your session: with the Grepleaks key they pass through Grepleaks to the model provider. Host commands always ask before they run.

Is it open source?

The source is available under the Grepleaks license: free to use, including paid pentests; resale and paid hosted access require permission. It is not OSI open source, and OpenCode keeps its MIT license.