</>MCP Agents Market
MCP Server

T3MP3ST

by elder-plinius5.8kTypeScriptUpdated 2026-08-24

autonomous red teaming platform; multi-agent offensive-security meta-harness

Claude CodeCodexHermesOpenCodeOh My Pi

T3MP3ST is an MCP server and autonomous offensive-security framework that transforms AI coding agents into penetration testing platforms. It provides a multi-agent architecture (recon, scanner, exploiter, infiltrator, exfiltrator, ghost, coordinator, analyst) that conducts security assessments across web applications, CTFs, smart contracts, source code repositories, and embedded systems. The framework operates keylessly through connected local agents like Claude Code, Codex, or Hermes, or runs fully offline with Ollama/LM Studio. It includes 36 built-in security tools (111 with full arsenal mode) and emphasizes reproducible benchmarks with every claim verifiable via committed test data.

Key Features

Multi-agent offensive security framework with 8 specialized operators mapped to MITRE ATT&CK phases
Keyless operation through local AI coding agents (Claude Code, Codex, Hermes, OpenCode) or fully offline with Ollama/LM Studio
MCP server exposing security_recon tool to MCP-compatible clients
Arsenal of 36-111 security tools including nmap, DNS enumeration, HTTP fingerprinting, and optional advanced tools
Reproducible benchmarks: 90.1% pass@1 on XBEN suite, 58% on Cybench CTF challenges, all verifiable via npm run verify-claims
Coordinated disclosure pipeline for vulnerability hunting in OSS robotics, embedded systems, and IoT
Web-based War Room UI and HTTP API for mission control and orchestration
Scope containment enforcing egress restrictions to authorized targets only

Use Cases

  • 01Black-box penetration testing of web applications and APIs with automated recon-to-exploit chains
  • 02CTF challenge solving with hint-free, sandbox-jailed autonomous agents
  • 03White-box source code auditing across Python, JavaScript, TypeScript, Go, Java, C, and C++
  • 04Vulnerability research in robotics, embedded systems, and OT/IoT open-source projects
  • 05DeFi smart contract security testing against known exploit patterns
  • 06Security training and authorized red team exercises with reproducible tool-backed evidence

Related MCP Servers

View more

T3MP3ST — FAQ

What is T3MP3ST?+

T3MP3ST is an MCP server and autonomous red-teaming framework that turns AI coding agents into offensive security platforms. It orchestrates multi-agent penetration testing across web apps, CTFs, source code, smart contracts, and embedded systems with tool-backed reconnaissance and exploitation.

How do I install and run T3MP3ST?+

Clone the repository, run 'npm install', then 'npm run server' to launch the War Room at http://127.0.0.1:3333/ui/. Connect a local coding agent (Claude Code, Codex, Hermes) via Settings or export API keys for OpenRouter, Venice, Anthropic, or OpenAI. For MCP server mode, run 'node dist/mcp-server.js'.

Which AI clients work with T3MP3ST?+

T3MP3ST works with Claude Code, Codex, Hermes, OpenCode, Oh My Pi as keyless local agents. It also supports API-based providers (OpenRouter, Venice, Anthropic, OpenAI) and fully offline models via Ollama, LM Studio, vLLM, or llama.cpp.

Do I need API keys to use T3MP3ST?+

No, T3MP3ST operates keylessly by connecting to a local AI coding agent already running on your machine. Optionally, you can provide API keys for cloud providers (OPENROUTER_API_KEY, VENICE_API_KEY, ANTHROPIC_API_KEY, OPENAI_API_KEY) or run completely offline with a local model.

Is T3MP3ST free and legal to use?+

T3MP3ST is free and open-source under AGPL-3.0. However, it is an offensive security tool that must only be used on systems you own or have explicit written authorization to test. Unauthorized access is illegal in most jurisdictions; users are solely responsible for lawful use.

What security domains does T3MP3ST support?+

Core stable support includes web applications (90.1% XBEN pass rate), CTF challenges (58% Cybench), and source code auditing (8/10 held-out CVEs identified). Experimental support covers smart contracts, embedded/IoT systems, and cloud infrastructure. Mobile, binary reverse engineering, and Active Directory are in development.

How do I install T3MP3ST?+

Open the source repository on GitHub and follow its README. T3MP3ST is a mcp server — MCP Agents Market links you directly to the official repo.

Is T3MP3ST free?+

T3MP3ST is an open-source project hosted on GitHub. Check the repository for its license and any usage requirements.

Related searches