Skip to content
KitploitKITPLOIT
StrumentiExploitsBlog
Log in
Invia
StrumentiExploitsBlog
Invia

Strumenti di Hacking, PenTest e Cybersecurity per il tuo Arsenale di Sicurezza!

Kitploit è una directory di strumenti di hacking, cybersecurity e pentesting. Scopri gli ultimi aggiornamenti dei progetti per trovare vulnerabilità, analizzare sistemi, automatizzare i test e rafforzare la tua sicurezza.

FeedContattoPrivacy© 2026 Kitploit

Directory degli strumenti

Categorie

Vedi tutte le categorie
Loading categories
red-clippy — open-source pentest management built to be operated by an AI agent | Kitploit
Strumenti/GitHubGitHub/cspf-founder/red-clippy
Penetration Testing FrameworksReconnaissanceVulnerability ScannersVulnerability AnalysisExploitationInformation GatheringPenetration TestingRed TeamingAI Security
GitHubcspf-founder/red-clippy

red-clippy

open-source pentest management built to be operated by an AI agent

2811041 mese faRevisionato da Kitploit
Vedi RepositorySito web

Più Popolari

Vedi tutti →

Scopri gli strumenti più utilizzati dalla nostra community.

Esplora tutti gli strumenti

Sfoglia la nostra collezione di strumenti

Vedi tutti gli strumenti →
Condividi
Contenuto non disponibile nella lingua richiesta. Visualizzazione della versione inglese.

Red Clippy

Your agent tests. Red Clippy keeps the record.

Open-source pentest management built to be operated by an AI agent. Connect it to Claude Code over MCP and it runs the engagement alongside you: scope and assets, recon observations, methodology coverage, and findings with CVSS and evidence.

Built for testers who want an agent's speed without giving up the discipline of a real engagement. Work does not get repeated, findings do not evaporate between sessions, and nothing reaches the report that was never proved.

An engagement in Red Clippy: coverage progress, findings by severity, outstanding phases, recent findings, and the scope from the engagement letter

Full documentation: https://cspf-founder.github.io/red-clippy/


Contents

  • Why
  • Quick start
  • How the data is organized
  • First run
  • Using it
  • Connecting an AI agent (MCP)
  • Features
  • Configuration
  • CLI reference
  • Building from source
  • Development
  • Contributing
  • License

Why

Coding agents have become genuinely useful testers. They have a shell, they run the same tooling you do, and they cover ground fast. Point one at a target and it will find things.

Then the context window fills up, and the engagement is gone. The next session rescans hosts it already cleared, re-tests what it already ruled out, and cannot tell you which parts of the scope were ever touched. Somewhere in the transcript is a confirmed SQL injection nobody wrote down.

Red Clippy fixes that by giving the agent two things it does not have on its own.

A place to put the work. Every asset, observation, check, and finding lands in a database as testing happens, not in a scrollback buffer. Coverage becomes a query instead of a memory: which assets exist, which checks are cleared on each, what has already been reported. Tomorrow's session picks up exactly where the last one stopped.

Rules to work by. A Red Team Instructions document reaches the agent in the MCP handshake, before it does anything: verify before reporting, prove every claim, take the minimum access needed to demonstrate impact, leave third-party systems alone. Override it per organization and per engagement, because house rules differ between teams and clients.

You stay in the loop the whole time. Everything the agent writes is an ordinary row in the web UI that you can review, correct, reclassify, or throw away.

[!CAUTION] Authorized testing only. Red Clippy is for penetration testers working under an engagement. Test only systems you own or have explicit written permission to assess. Scope marking and the Red Team Instructions exist to keep an agent inside the rules of engagement, but they are guardrails, not authorization. An agent acts on your authority, and you remain responsible for everything it does.


Quick start

Download a binary from the latest release and run it. It sets up the database and serves the panel on 127.0.0.1:7337.

Linux

tar xzf red-clippy-*-x86_64-unknown-linux-musl.tar.gz
cd red-clippy-*-x86_64-unknown-linux-musl
./red-clippy serve

Windows

Unzip the archive, then from that folder:

.\red-clippy.exe serve

Open http://127.0.0.1:7337 and the setup wizard takes over from there.

The database is created in the directory where you run the binary. Uploaded evidence is stored there too, in red-clippy-storage. Both paths can be changed in the config file, see Configuration.

Prefer to compile it yourself? See Building from source.


How the data is organized

Red Clippy groups work into organizations. An organization holds your pentests, and each pentest holds the assets, findings, and evidence for that engagement. If you test for one company, a single organization is all you need. If you consult for several clients, give each client its own: an organization sees nothing belonging to another, so their engagements never mix.

An organization has two names. The display name ("XYZ Example Corp") is what you see in the panel and can be changed later. The slug (xyz) is a short lowercase identifier used in the evidence folder on disk (red-clippy-storage/org_xyz/pentest_PT-2026-08-27/), so it is fixed once set.

You can belong to several organizations and switch between them from the avatar menu. In each one you are either an owner, who can add and remove people and rename or delete the organization, or a member, who works the engagements.


First run

On first launch the database is empty, so the browser shows a setup wizard instead of a login form. It asks for:

  • a slug and display name for your first organization
  • a username, and optionally an email
  • a password (minimum 8 characters)

The account it creates is the owner of that organization. The wizard only appears while the database has no users; once the first account exists it is permanently disabled, so it cannot be used to create extra accounts later.

After setup, manage organizations and teammates in the app under avatar menu > Organizations.

If nobody can sign in, the CLI is the way back:

red-clippy reset-password --username alice --password 'new-one'

Using it

The intended flow is agent-driven. You set up the engagement, then work through the target with Claude Code while it keeps the record.

You set up:

  1. Create a pentest. Code, scope, dates. The methodology checklist is seeded automatically.
  2. Define scope. Add the domains, hosts, and IP ranges you are authorised to test, and mark anything explicitly out of scope. You can type these in yourself, or paste the client's scope list to the agent and have it enter them for you.
  3. Connect the agent over MCP, pinned to this engagement (see below).

The agent then works, and records as it goes:

  • Runs recon and testing tools from its own shell, the way it normally would.
  • Hands raw scanner output over with ingest_tool_output, or writes assets and observations directly.
  • Promotes real scope units to assets, leaves the rest as observations.
  • Marks methodology checks as it clears them.
  • Files findings with CVSS, PoC, and evidence attached.

You supervise:

  • Watch it land in the browser in real time.
  • Correct anything: every row the agent wrote is an ordinary record you can edit, reclassify, or delete.
  • Check the coverage view for what is still untouched.
  • Review on the cross-engagement dashboard, which shows every finding in the organization alongside the pentest it came from.

The agent is optional. It works through the same API the panel does, so anything it records you can also enter, correct, or delete yourself in the browser. Run an engagement entirely by hand, entirely through the agent, or switch between the two as you go.


Connecting an AI agent (MCP)

This is the main way Red Clippy is meant to be used.

red-clippy mcp covers the whole application: scope and assets, observations, methodology coverage, findings, evidence, the attack graph, and tool-output ingestion. A connected agent works the engagement rather than just answering questions about it.

Scarica lo strumento