# PurpleAILAB/Decepticon

Autonomous Hacking Agent for Red Team

Repository: https://github.com/PurpleAILAB/Decepticon
Canonical: https://ross.abutalabs.com/products/decepticon
Homepage: https://decepticon.red
Language: Python
License: Apache-2.0
License Family: permissive
Topics: agent, ai, cybersecurity, hacking, langchain, langgraph, llm, generative-ai, pentesting, pentest
Last push: 2026-08-26T10:21:06+00:00

## Health v2 (maintenance only)
Score: 80/100 (v2, computed 2026-09-03T02:39:23.370411+00:00)
- activity 99, release rhythm 83, longevity 32
- inputs: {"age_days": 453, "days_push": 7, "days_rel": 37, "gap_med": 1.0, "n_releases_24m": 61}
- flags: none
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 5335, forks 1030 (observed 2026-08-28T04:09:15.720323+00:00)

## What it is
Decepticon is an autonomous AI red-team hacking agent that uses LLMs (built on LangChain/LangGraph) to plan and execute context-aware offensive security engagements under enforced scope, rules of engagement, and an OPPLAN. It is open source and self-hostable via Docker, with an optional managed cloud control plane.

## Use cases
- run autonomous red team engagements against authorized targets
- simulate realistic attacker behavior to test blue team detection
- discover logical and context-based vulnerabilities beyond checklist scanners
- orchestrate LLM-driven pentest agents with scope and OPSEC controls
- generate evidence-backed findings and reports for security assessments
- self-host an AI offensive security agent in Docker

## When to choose
- you need autonomous, context-aware red teaming rather than static vulnerability scanning
- you want runtime-enforced scope, rules of engagement, and OPSEC for AI agents
- you prefer self-hosting with your own LLM provider keys (BYOK)
- you want evidence and transcripts from real attack chains like SQL injection to cross-tenant access

## When to avoid
- you need a traditional compliance-oriented vulnerability scanner with static checklists
- you lack authorization to attack the target systems
- you want a fully free managed service without any LLM token costs
- you need a simple one-shot nmap-style scanning script

## Facets
- artifact type: application
- maturity: active
- function: agent-framework, penetration-testing, llm-inference, security, cli
- domain: security, penetration-testing, artificial-intelligence, large-language-models
- platform: windows, python, self-hosted
- tags: red-team, autonomous-hacking, langgraph, pentesting, offensive-security, llm-agent, cybersecurity, ai-agents, docker, linux, macos, web-server

## Member repositories
- PurpleAILAB/Decepticon (main) score 80

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:09:15.720323+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-29T17:58:51.652461+00:00, confidence not recorded.
  - readme: https://github.com/PurpleAILAB/Decepticon (fetched 2026-08-28T04:09:15.720323+00:00, sha cd55584be8b4)
  - homepage: https://decepticon.red (fetched 2026-08-29T08:53:25.770622+00:00, sha 1decdd78b862)
  - site_page: https://docs.decepticon.red/ (fetched 2026-08-29T08:53:25.780043+00:00, sha 7e24278e74f0)
  - registry_pypi: https://pypi.org/pypi/decepticon/json (fetched 2026-08-29T08:53:25.785832+00:00, sha e80e5293dd69)
  - site_page: https://app.decepticon.red/pricing (fetched 2026-08-29T08:53:25.782016+00:00, sha 09672eac3a33)
- Data as of 2026-08-30T08:39:29.467469+00:00.
