Ross ROSS = Recommend OSS · open-source software intelligence for agents

PurpleAILAB/Decepticon

Autonomous Hacking Agent for Red Team observed · 2026-08-28

github.com/PurpleAILAB/Decepticon · homepage · Python · Apache-2.0 (permissive) observed · 2026-08-28

Health v2 · maintenance only

80/100

  • Activity 99
  • Release rhythm 83
  • Longevity 32
How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: 1.0
  • age_days: 453
  • days_rel: 37
  • days_push: 7
  • n_releases_24m: 61

Full methodology

Adoption not part of the score

5335 stars · 1030 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded

Decepticon is an autonomous AI red-team hacking agent that uses LLMs (built on LangChain/LangGraph) to plan and execute context-aware offensive security engagements under enforced scope, rules of engagement, and an OPPLAN. It is open source and self-hostable via Docker, with an optional managed cloud control plane.

Use cases

  • run autonomous red team engagements against authorized targets
  • simulate realistic attacker behavior to test blue team detection
  • discover logical and context-based vulnerabilities beyond checklist scanners
  • orchestrate LLM-driven pentest agents with scope and OPSEC controls
  • generate evidence-backed findings and reports for security assessments
  • self-host an AI offensive security agent in Docker

When to choose

  • you need autonomous, context-aware red teaming rather than static vulnerability scanning
  • you want runtime-enforced scope, rules of engagement, and OPSEC for AI agents
  • you prefer self-hosting with your own LLM provider keys (BYOK)
  • you want evidence and transcripts from real attack chains like SQL injection to cross-tenant access

When to avoid

  • you need a traditional compliance-oriented vulnerability scanner with static checklists
  • you lack authorization to attack the target systems
  • you want a fully free managed service without any LLM token costs
  • you need a simple one-shot nmap-style scanning script

Facets

application · maturity active

agent-framework penetration-testing llm-inference security cli security penetration-testing artificial-intelligence large-language-models windows python self-hosted red-team autonomous-hacking langgraph pentesting offensive-security llm-agent cybersecurity ai-agents docker linux macos web-server

5 sources

Member repositories

RepositoryRoleHealth v2
PurpleAILAB/Decepticonmain80

For agents

markdown · JSON · MCP: product_card(name="PurpleAILAB/Decepticon")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem