Swarm

SwarmAutonomous penetration testing agent

Point it at a URL. A swarm of language-model agents maps the target, finds vulnerabilities, and reports what it found, running on the ChatGPT subscription you already have.

brew install joloooo/swarm/swarm
View on GitHubOpen source, MIT license

How it works

SwarmAttacker architecture diagramdrawn fromdispatchresultssummaries + hypothesesflag verifiedTargeturl / ipSkill library60+ skillsPlannerthe only decision-makerRecon ×2ports · dns / webExecutor ×4one skill eachWeb searchon demandSummarizerfindings + hypothesesFinal reportaggregated evidenceEndflag verified≤ 50 ROUNDS
DispatchFindings returnFinal output

See the benchmark numbersHow it handles model refusals

01 / 03

Just your $20 ChatGPT plan

It signs in with the ChatGPT Plus or Pro account you already pay for and drives GPT-5.x. No API key, no per-token invoice.

FAQ

Questions, answered.

The things people ask before they point SwarmAttacker at their first target.

Something else? Open an issue

SwarmAttacker is an open-source autonomous penetration testing agent that tests a web application from nothing but its URL. A swarm of language-model agents maps the target, finds vulnerabilities, and writes up what it found. It is MIT licensed, the code is on GitHub, and it runs on the ChatGPT subscription you already pay for.