120+Pentest skills
Specialized playbooks covering most pentest scopes, giving the agent practical guidance throughout your assessment.
Describe your objective and investigate with an agent that finds the tools, runs the commands, and keeps the evidence.
Specialized playbooks covering most pentest scopes, giving the agent practical guidance throughout your assessment.
The agent searches its catalogue, installs the tools your task needs, uses them, and cleans up afterward. No manual toolbox setup.
A Linux environment for your pentest tools. Run them in Docker and keep reports, scripts, and evidence in your local engagement folder.
The Grepleaks key plugs you into three unrestricted reasoning models. Add it once and move between all three from inside Grepleaks.
Unrestricted models keep working on legitimate, authorized security tasks that aligned models refuse, so an engagement never stalls mid-run.
curl -fsSL https://raw.githubusercontent.com/grepleaks/grepleaks/main/scripts/install.py | python3 - --repository grepleaks/grepleaksThe environment is free and runs locally. Model access uses the Grepleaks key, one key for the unrestricted models. Model usage is billed through the key.
Yes. Grepleaks runs its Linux toolset in a disposable container, so nothing security-related installs on your machine. Plan about 4 GB of disk for the first build.
Launchers for macOS, Windows and Linux are included; Docker does the heavy lifting. Host commands are validated on macOS today, and native Windows/Linux pairing stays in preview until it passes the same checks.
Run the install command again. Docker’s cache makes updates fast, and grepleaks --version shows what you run. Your keys, sessions and engagement files are never touched.
Tools run in the local container and engagements stay on your machine. Prompts and tool output go to the model that runs your session: with the Grepleaks key they pass through Grepleaks to the model provider. Host commands always ask before they run.
The source is available under the Grepleaks license: free to use, including paid pentests; resale and paid hosted access require permission. It is not OSI open source, and OpenCode keeps its MIT license.