finds.dev← search

// the find

elder-plinius/T3MP3ST

★ 6,253 · TypeScript · AGPL-3.0 · updated Sep 2026

autonomous red teaming platform; multi-agent offensive-security meta-harness

T3MP3ST is a multi-agent orchestration layer for offensive security testing — it drives an AI coding agent you already have running (Claude Code, Codex, etc.) or a local LLM through a recon-exploit-report kill chain against authorized targets. It's aimed at pentesters and security researchers who want to automate parts of an engagement without paying for a separate model API.

The verify-claims script re-derives every benchmark number from committed JSON rather than asking you to trust a README, and the status table is unusually blunt about what's stable vs. experimental vs. just a stub in src/stubs/. The keyless design (reusing an already-authenticated coding agent session) is a genuinely useful cost/friction reduction. Egress-scope containment that refuses off-scope hosts by default is a real safety control, not just a warning in the docs.

The 8-operator 'swarm' that's central to the project's name and pitch is unproven — every headline benchmark (XBEN, Cybench, CVE-Zero) was run single-agent, not through the coordinated cell, which the README admits but buries under a wall of marketing copy and ASCII art. Several advertised domains (cloud, mobile, binary/RE) are static-detection scaffolding only, not working exploitation, despite being listed as coverage areas. Reusing a live Claude Code/Codex session hands the tool ambient tool authority outside its own sandbox boundary, which the maintainers themselves flag as a risk and disable by default — worth reading closely before opting in.

View on GitHub →

// want more like this?

We dig through GitHub every week and send a few repos picked for what you actually care about — each with an honest take like this one.

Get finds in your inbox → Search again →