cain-agent
Real-world AI penetration testing engineer for authorized assessments — built-in cloud module covering AWS/Azure/GCP + Aliyun/Tencent/Huawei clouds. Built on Claude Agent SDK
Cain is an AI-powered penetration testing agent designed for authorized real-world security assessments of enterprise systems and cloud infrastructure. Built on the Claude Agent SDK, it executes deterministic attack pipelines with hard-coded scope enforcement and safety constraints, targeting business-logic vulnerabilities, authentication chains, and cloud misconfigurations rather than static CTF challenges. The agent includes specialized modules for AWS, Azure, GCP, and Chinese cloud providers (Aliyun, Tencent Cloud, Huawei Cloud), producing auditable evidence chains, reproducible proof-of-concept exploits, and remediation advice.
Key Features
Use Cases
- 01Authorized penetration testing of enterprise web applications and APIs
- 02Cloud security assessments across multi-cloud environments including Chinese providers
- 03Bug bounty program reconnaissance and vulnerability discovery
- 04IAM privilege-escalation path analysis in cloud environments
- 05Automated security audits with auditable evidence chains for compliance
- 06Real-world WAF and rate-limiting evasion testing with dynamic strategy adjustment
Related Agents
View morehermes-agent
The agent that grows with you
agency-agents
A complete AI agency at your fingertips - From frontend wizards to Reddit community ninjas, from whimsy injectors to reality checkers. Each agent is a specialized expert with personality, processes, and proven deliverables.
openinterpreter
A coding agent for open models like Kimi K3
cline
Autonomous coding agent as an SDK, IDE extension, or CLI assistant.
cain-agent — FAQ
What is cain-agent?+
Cain-agent is an AI penetration testing engineer built on the Claude Agent SDK for authorized real-world security assessments. It executes deterministic attack pipelines against enterprise systems and cloud infrastructure, enforcing scope through engineering constraints rather than AI behavior.
How do I install cain-agent?+
Clone the GitHub repository, then install in editable mode with `pip install -e .` or `uv pip install -e .`. For cloud module support (AWS S3, Huawei OBS, Kubernetes checks), run `pip install -e ".[cloud]"`. Verify installation with `cain-agent --version`.
What API keys or credentials does cain-agent require?+
You need an ANTHROPIC_API_KEY for the default Claude backend. For the pi backend, you need Node.js 20+ and the appropriate API key for your chosen provider (OPENAI_API_KEY, GEMINI_API_KEY, DEEPSEEK_API_KEY, or OPENROUTER_API_KEY). Cloud testing requires read-only credentials for the target cloud providers.
Which AI clients does cain-agent work with?+
Cain-agent is a standalone AI agent that runs from the command line, not a plugin for other AI assistants. It uses the Claude Agent SDK internally and supports multiple LLM backends including Anthropic Claude, OpenAI, Google Gemini, DeepSeek, and OpenRouter.
Is cain-agent free to use?+
The software is open-source under the Apache-2.0 license and free to use. However, you will incur costs from your chosen LLM provider (Anthropic, OpenAI, etc.) based on token usage during penetration testing runs.
What safety measures does cain-agent have?+
Cain enforces scope through a PreToolUse hook that blocks out-of-scope targets, uses read-only tools by default with dangerous-operation blacklists, runs separate finder and validator agent sessions to prevent self-confirmation, and redacts credentials before persisting any data.
How do I install cain-agent?+
Open the source repository on GitHub and follow its README. cain-agent is a agent — MCP Agents Market links you directly to the official repo.
Is cain-agent free?+
cain-agent is an open-source project hosted on GitHub. Check the repository for its license and any usage requirements.