An AI pentester that asks permission before it breaks things
ARTEX is a Go+Next.js autonomous penetration-testing system that won Baidu's "agent+" attack-defense challenge — and it keeps a human in the loop.
ARTEX is a multi-agent attack system whose own terms bar it from ever touching a live target — a preserved specimen of how far agentic offense engineering has gotten.

What it does
ARTEX runs LLM-driven agents that explore an asset graph, launch tasks, call tools, and record findings — a full autonomous pentest pipeline with a dashboard for token spend, live activity streams, and per-task sessions. It ships as a single Go binary with an embedded Next.js frontend, backed by PostgreSQL, and includes a traffic-recording proxy so you can watch exactly what the agents did.
The interesting bit
The human-in-the-loop design: an interception/approval system gates dangerous agent actions, with approval cards in chat and expandable approval records. There’s also a dedicated retester agent that re-verifies reported vulnerabilities and auto-marks them “fixed” only when the retest session confirms it.
Key highlights
- Asset coverage graph (force-directed layout) showing which nodes the agents have actually tested
- One-click asset sync from ScopeSentry — domains, subdomains, IPs, ports, endpoints — instead of re-collecting
- Self-updating binary with SHA256 verification, smoke tests, automatic rollback after 3 failed boots, and “restart-as-migration” idempotent schema
- Configurable per-task work-agent concurrency (default 3), pluggable LLM providers, and remote MCP over Streamable HTTP or legacy SSE
- Manual vulnerability retesting with per-run verdicts (“still reproducible” / “fixed” / “inconclusive”) and preserved evidence
Caveats
- This repo is explicitly a final-version source backup — the Docker deployment source is dead, and the README tells you to have an AI rebuild it locally. Treat it as a snapshot, not an actively maintained project.
- Updates interrupt running tasks (update = restart), and Docker-based updates don’t refresh the bundled toolchain (nmap, playwright, etc.).
Verdict
Worth a look if you build security automation or want a reference architecture for supervised offensive agents — the approval flow and retest loop are genuinely thoughtful. Skip it if you need a maintained, production-supported product; this is a champion project preserved in amber.
Frequently asked
- What is mhtsec/ARTEX?
- ARTEX is a Go+Next.js autonomous penetration-testing system that won Baidu's "agent+" attack-defense challenge — and it keeps a human in the loop.
- Is ARTEX open source?
- Yes — mhtsec/ARTEX is open source, released under the AGPL-3.0 license.
- What language is ARTEX written in?
- mhtsec/ARTEX is primarily written in Go.
- How popular is ARTEX?
- mhtsec/ARTEX has 2.2k stars on GitHub.
- Where can I find ARTEX?
- mhtsec/ARTEX is on GitHub at https://github.com/mhtsec/ARTEX.