T3MP3ST
autonomous red teaming platform; multi-agent offensive-security meta-harness
T3MP3ST is an MCP server and autonomous offensive-security framework that transforms AI coding agents into penetration testing platforms. It provides a multi-agent architecture (recon, scanner, exploiter, infiltrator, exfiltrator, ghost, coordinator, analyst) that conducts security assessments across web applications, CTFs, smart contracts, source code repositories, and embedded systems. The framework operates keylessly through connected local agents like Claude Code, Codex, or Hermes, or runs fully offline with Ollama/LM Studio. It includes 36 built-in security tools (111 with full arsenal mode) and emphasizes reproducible benchmarks with every claim verifiable via committed test data.
Key Features
Use Cases
- 01Black-box penetration testing of web applications and APIs with automated recon-to-exploit chains
- 02CTF challenge solving with hint-free, sandbox-jailed autonomous agents
- 03White-box source code auditing across Python, JavaScript, TypeScript, Go, Java, C, and C++
- 04Vulnerability research in robotics, embedded systems, and OT/IoT open-source projects
- 05DeFi smart contract security testing against known exploit patterns
- 06Security training and authorized red team exercises with reproducible tool-backed evidence
Related MCP Servers
View moremarkitdown
Python tool for converting files and office documents to Markdown.
firecrawl
The context API to search, scrape, and interact with the web at scale. 🔥
prompts.chat
f.k.a. Awesome ChatGPT Prompts. Share, discover, and collect prompts from the community. Free and open source — self-host for your organization with complete privacy.
langflow
Langflow is a powerful tool for building and deploying AI-powered agents and workflows.
T3MP3ST — FAQ
What is T3MP3ST?+
T3MP3ST is an MCP server and autonomous red-teaming framework that turns AI coding agents into offensive security platforms. It orchestrates multi-agent penetration testing across web apps, CTFs, source code, smart contracts, and embedded systems with tool-backed reconnaissance and exploitation.
How do I install and run T3MP3ST?+
Clone the repository, run 'npm install', then 'npm run server' to launch the War Room at http://127.0.0.1:3333/ui/. Connect a local coding agent (Claude Code, Codex, Hermes) via Settings or export API keys for OpenRouter, Venice, Anthropic, or OpenAI. For MCP server mode, run 'node dist/mcp-server.js'.
Which AI clients work with T3MP3ST?+
T3MP3ST works with Claude Code, Codex, Hermes, OpenCode, Oh My Pi as keyless local agents. It also supports API-based providers (OpenRouter, Venice, Anthropic, OpenAI) and fully offline models via Ollama, LM Studio, vLLM, or llama.cpp.
Do I need API keys to use T3MP3ST?+
No, T3MP3ST operates keylessly by connecting to a local AI coding agent already running on your machine. Optionally, you can provide API keys for cloud providers (OPENROUTER_API_KEY, VENICE_API_KEY, ANTHROPIC_API_KEY, OPENAI_API_KEY) or run completely offline with a local model.
Is T3MP3ST free and legal to use?+
T3MP3ST is free and open-source under AGPL-3.0. However, it is an offensive security tool that must only be used on systems you own or have explicit written authorization to test. Unauthorized access is illegal in most jurisdictions; users are solely responsible for lawful use.
What security domains does T3MP3ST support?+
Core stable support includes web applications (90.1% XBEN pass rate), CTF challenges (58% Cybench), and source code auditing (8/10 held-out CVEs identified). Experimental support covers smart contracts, embedded/IoT systems, and cloud infrastructure. Mobile, binary reverse engineering, and Active Directory are in development.
How do I install T3MP3ST?+
Open the source repository on GitHub and follow its README. T3MP3ST is a mcp server — MCP Agents Market links you directly to the official repo.
Is T3MP3ST free?+
T3MP3ST is an open-source project hosted on GitHub. Check the repository for its license and any usage requirements.