Academic system
SwarmAttacker vs AutoPT
A single agent constrained by a finite-state machine that walks scanning, selection, reconnaissance and exploitation states against a known target, seeded by a vulnerability scanner.
- Vendor
- USTC, with QI-ANXIN and Chaitin
- Licence
- No licence file (all rights reserved)
- Pricing
- Free, self-hosted. You bring your own model API key or local model.
- Checked
- September 2, 2026
| Capability | AutoPT1 of 8 | |
|---|---|---|
| Free | Yes. | |
| Runs on a ChatGPT subscription | Not found. | |
| Custom prompts & skills | Partial. | |
| Safety-refusal handling | Partial. | |
| Parallel multi-agent swarm | Not found. | |
| MIT-licensed open source | Not found. | |
| Black-box from a URL | Not found. | |
| Model-agnostic | Partial. |
- yes
- not found or only partly
Hover a mark for the evidence. A cross means the capability was not found, or only partly found, on AutoPT's public pages or repository on September 2, 2026, not that it is technically impossible.
Profile
What is AutoPT?
AutoPT is a research agent from the University of Science and Technology of China, with co-authors at QI-ANXIN and Chaitin, first posted in November 2024 and published in an IEEE journal in 2025. Its contribution is a penetration-testing state machine: a single LLM agent constrained by a finite-state machine with scanning, selection, reconnaissance, exploitation and check states, designed to counter the context-loss and stalling failures of simpler agent loops. A vulnerability scanner seeds the agent's target list.
On the authors' own scanner-based benchmark, AutoPT lifts a small model's completion rate from 22% to 41%. Targets are given as an IP and port together with a benchmark record naming the vulnerability, so runs are informed rather than URL-only black-box, and only a couple of OpenAI models passed the authors' pre-experiment. Refusals are handled with legal-tester role-play and, per the paper, jailbreak prompts.
The public repository has around 50 stars and ships no licence file, so the code is viewable but not legally reusable. The system is single-agent by design and scoped to preconfigured vulnerable environments rather than open web discovery.
In SwarmAttacker's favour
Where it stands out.
- 01A parallel swarm versus AutoPT's single finite-state-machine agent.
- 02A true MIT licence, where AutoPT ships no licence file and cannot be legally reused.
- 03Black-box from a URL, where AutoPT needs an IP, a vulnerability label and a scanner.
- 04Runs on a ChatGPT plan and handles refusals natively, rather than relying on jailbreak prompts.
In AutoPT's favour
Where it is stronger.
- 01A published state-machine design that measurably reduces agent stalling.
- 02A peer-reviewed IEEE journal paper.
- 03A focus on known-CVE environments that complements open discovery.
Verdict
Which one should you pick?
AutoPT is a research contribution about agent control, not a deployable tool, and it ships no licence. Pick SwarmAttacker for a parallel, MIT-licensed black-box agent.
Sources
What this page was checked against.
All checked on September 2, 2026.
Turn a URL into a security report.
Open source, MIT licensed, and it runs on the ChatGPT plan you already pay for. Install it and point it at a target you own.
brew install joloooo/swarm/swarm