← all repositories
FrancescoStabile/numasec

A terminal-native AI agent for AppSec and pentest workflows

numasec keeps your security workflow—tools, findings, evidence, and reports—inside a durable terminal workspace so nothing disappears when the chat ends.

508 stars TypeScript AgentsCoding AssistantsDomain Apps
numasec
Collecting fresh signals — velocity needs a few days of history.
collecting data…
star history

What it does

numasec is a terminal-based AI security agent that wraps around the tools already on your machine. It runs security runbooks, switches between specialized agents for AppSec, pentest, OSINT, and CTF work, and tracks findings with severity, evidence, and replay state. The goal is to keep the entire operation—target scope, tool output, observations, and report context—in one resumable workspace rather than letting it fragment across shell history, screenshots, and notes.

The interesting bit

Instead of treating AI as a chatty advisor on the side, numasec makes the terminal itself the security workspace. Findings live inside the operation with attached state, so weak signals, rejected claims, and reportable issues all stay visible to the agent without losing the thread.

Key highlights

  • Uses your existing local toolchain; it does not bundle its own scanner suite.
  • Durable operations that can be named, resumed, renamed, and exported as shareable bundles.
  • Posture switching via TAB between AppSec, Pentest, OSINT, CTF/lab, and research agents.
  • Runbooks drive the agent through structured tasks rather than random tool calls.
  • Built-in findings workflow with evidence, replay tracking, and report generation from live operation state.

Caveats

  • AppSec and Pentest workflows are the most mature surfaces; OSINT and other agents exist but are not yet equally developed.
  • It relies on locally installed security tools, so a bare environment will need its own toolchain first.

Verdict

Worth a look if you want an AI teammate that stays inside your terminal and keeps pentest context organized. Skip it if you are looking for a drop-in scanner replacement or a fully autonomous hacker-in-a-box.

Frequently asked

What is FrancescoStabile/numasec?
numasec keeps your security workflow—tools, findings, evidence, and reports—inside a durable terminal workspace so nothing disappears when the chat ends.
Is numasec open source?
Yes — FrancescoStabile/numasec is open source, released under the AGPL-3.0 license.
What language is numasec written in?
FrancescoStabile/numasec is primarily written in TypeScript.
How popular is numasec?
FrancescoStabile/numasec has 508 stars on GitHub.
Where can I find numasec?
FrancescoStabile/numasec is on GitHub at https://github.com/FrancescoStabile/numasec.

heatdrop uses Google Analytics to see which pages get read — nothing else. Your call. How we handle data.