paranoid: attack your own running app

/hack-me breaks into your own running app, proves each bug with a real request, patches it, and re-verifies the exact exploit.

Stars
★ 48
Last updated
12d ago
License
MIT
Primary language
Python

At a glance

Works with
Universal · cross-platformCodex · Claude Code
You'll need
Python 3 (to run your local app)Shell / CLINetwork accessLocal filesystem
Typical use
A developer vibe-coding in Claude Code, Codex, or Cursor whose app is already running locally and who wants it actually attacked before shipping.
Main limitation
It is v0.1 and actively developed, so its coverage is bounded by the current 24 vulnerability classes and twelve framework guides.

What does this agent do, and when should you use it?

paranoid is a Markdown-based agent skill whose main entry point is the /hack-me command. Pointed at an app you have running locally and authorized, it runs a find → prove → patch → re-verify loop: it maps the app and picks the risk classes, probes each with a crafted request that only succeeds if the bug is real, patches the root cause with a minimal behavior-preserving fix, then replays the exact exploit to confirm it is dead. A sixth sweep step hunts the same bug pattern on paths no probe touched. It ships route-and-auth guidance for twelve stacks (Next.js, FastAPI, Express, Django, Rails, Flask, Spring Boot, Laravel, Phoenix, Go, NestJS, ASP.NET Core) plus companion references and a 7-point pre-commit gate. The repository also carries a reproducible benchmark harness covering 24 vulnerability classes. It has no dependencies, makes no network calls and sends no telemetry; you install it as a Claude Code plugin or via npx skills add. It is v0.1 and in active development.

When you run /hack-me, it first maps your running app and selects the risk classes the app is exposed to. For each class it sends one crafted request that only succeeds if the vulnerability is real, and it proves every finding with the actual request and response rather than theorizing. It then patches the root cause with a minimal, behavior-preserving fix and re-verifies by replaying the exact exploit — a finding is not closed until that request fails. Finally it sweeps for the same bug on paths no probe touched: a sibling branch, the same resource under a different method, a /v1 copy, or a cron job reaching the same sink. The skill loads supporting references — vibe-top-10, auth-access, secrets-config, injection, apis-webhooks, and frameworks — along with a 7-point pre-commit checklist. The repository also includes the benchmark/ harness, which defines 24 vulnerability classes, each with a neutral spec, a functional check, and a real exploit check.

  1. A developer vibe-coding in Claude Code, Codex, or Cursor whose app is already running locally and who wants it actually attacked before shipping.
  2. An engineer handed an API they did not write — for example a third-party target like OWASP VAmPI — with only a URL, wondering which bugs are actually exploitable.
  3. A team that wants a pre-merge black-box check against the running app, where every conclusion comes with a reproducible request as evidence.
  4. A security engineer validating that a fix really closed an exploit path, and who wants to replay the original request instead of reading a diff.
  5. Training or demo settings: showing how IDOR, SQLi, and mass assignment are proven and fixed on local targets such as DVWA, VulnShop, or the bundled ledgerlite app.
  6. Teams on one of the twelve supported stacks who want the agent to locate routes and auth code quickly instead of searching by hand.

How do you install or deploy this agent?

Claude Code users install through the plugin marketplace, which brings both the skill and the pentest loop:

/plugin marketplace add kulchankas/paranoid
/plugin install paranoid@paranoid

For Codex, Cursor, or any agent that reads skills:

npx skills add kulchankas/paranoid/skills/paranoid

You also need to copy commands/hack-me.md into your agent's commands directory (for example .claude/commands/) so the plain /hack-me command exists. The tool itself has no dependencies, makes no network calls, and sends no telemetry — it is Markdown your agent reads.

How do you use this agent?

Start your own app locally, then point the loop at it. In Claude Code, plugin skills are namespaced, so the command is /paranoid:hack-me:

python3 my_app.py     # your app, running locally
/paranoid:hack-me     # → http://localhost:<port>

The bundled demo app can be reproduced like this:

python3 examples/ledgerlite/app.py

Afterwards, read the report — for example examples/ledgerlite/HACKME_REPORT.md, examples/vampi/HACKME_REPORT.md, or examples/vulnshop/HACKME_REPORT.md — which contains the exact requests and diffs. Scope is limited to authorized targets, localhost only, with non-destructive proofs.

What are this agent's strengths and limitations?

Pros
  • Every finding needs a real HTTP request as proof, and a fix is not closed until the original exploit request fails.
  • The sixth sweep step targets the bug class, not just the request — added after a DVWA run left an identical SQL injection in the same file's other database-backend branch.
  • It publishes a reproducible 24-class benchmark and an honest negative result: on 22 blinded classes, the exploit rate was 0% both with and without the skill, so advice alone added nothing on isolated functions.
  • It has third-party receipts: against OWASP VAmPI it found, fixed, and re-verified six real bugs, of which VAmPI's own secure-mode flag closed only four.
  • Route-and-auth guidance covers twelve stacks (Next.js, FastAPI, Express, Django, Rails, Flask, Spring Boot, Laravel, Phoenix, Go, NestJS, ASP.NET Core), reducing cross-stack hunting.
Limitations
  • It is v0.1 and actively developed, so its coverage is bounded by the current 24 vulnerability classes and twelve framework guides.
  • It only works on a locally running app, on localhost, with authorization, and will decline to target third-party or production systems.
  • Output quality depends on the host agent and its model; there is no standalone CLI or server component that runs without an agent.
  • Issues the sweep fixes but cannot reach with a request are reported as "same pattern, fixed, not separately proven" and never count as verified.
  • The repository itself notes that a target publishing no bug list anywhere is still an open case — the VulnShop proof still had classes named in the upstream README.

How does this agent compare with similar options?

Key facts side by side with the most closely related agents.

Agent Source review Form / cost Stars Updated Language Full support on
paranoid: attack your own running app This agent 41 · Major gaps — ★ 48 12d ago Python Codex · Claude Code
JoySafeter 59 · Major gaps Self-hosted serviceFree + model costs ★ 313 5mo ago Python —
OpenClaw Master Skills 12 · Major gaps CLIFree + model costs ★ 2.2k 2mo ago Python —
CyberStrike — Open-Source AI Penetration Testing & Red Team Platform 43 · Major gaps CLIFree + model costs ★ 3.1k today TypeScript —

How does FollowAgents rate this agent?

FollowAgents source review · FARS-2.1
Major gaps
41/ 100 5-point scale 2.1 / 5
Trust 10/29
Reliability 5/14
Adaptability 9/18
Convention 10/18
Effectiveness 4/13
Verifiability 3/8
Why each dimension lost points
Trust10 / 29 · 1.7/5

README and SECURITY.md state localhost-only, authorized, non-destructive testing and claim the skill will decline out-of-scope requests; the CI workflow shows least privilege (contents: read), SHA-pinned actions, and persist-credentials: false, which are visible positives. However, the actual skill instructions (skills/paranoid), commands/hack-me.md, and references are absent from the evidence, so the promises of refusal, non-destructiveness, and minimal patches cannot be verified at the instruction level. The tool patches user code directly with no described backup, diff confirmation, or rollback path, and there is no statement on how sensitive artifacts captured during proof (passwords, tokens) are handled. Each item scores 1: asserted but not verifiable.

Reliability5 / 14 · 1.8/5

The README describes a coherent find→prove→patch→re-verify→sweep loop and honestly discloses a real failure (the DVWA run where sweep missed a sibling injection), which supports self-consistency. But the skill body is missing, so the described flow cannot be checked against implementation. On dependencies, the project claims 'no dependencies, no network calls', yet benchmark/harness/run.py imports and executes solution code it is pointed at, as SECURITY.md itself admits — an execution risk not surfaced in the main README narrative. Failure messages and error-handling paths are not evidenced. All three score 1.

Adaptability9 / 18 · 2.5/5

Audience and scenarios are well described: developers on Claude Code / Codex / Cursor, 12 framework guides, 24 vulnerability classes, and explicit applicability notes for three independent targets (VAmPI, DVWA, VulnShop) — this earns 2. Capability boundaries are also stated clearly (own code only, localhost only, no third-party targeting, no live malware) — 2. Trigger precision rests only on README examples (/paranoid:hack-me, /hack-me); commands/hack-me.md is not provided, so trigger conditions, arguments, and preconditions cannot be judged. Environment fit (port discovery, how the app is started, non-HTTP cases) also lacks verifiable detail. Both score 1.

Convention10 / 18 · 2.8/5

Information architecture is strong: a complete README with Quickstart, Receipts, Scope & ethics, Roadmap, Contributing, License, and links into references, checklists, benchmark, and examples — 2. Install notes are concrete (plugin marketplace and npx skills paths) — 2. Examples and FAQ-level material are extensive, with tabulated findings and reproduction commands — 2. Known limitations are stated honestly (v0.1, two task classes not yet model-scored, VulnShop's upstream README naming the classes, the sweep miss) — 2. LICENSE is a full MIT text — 2. Naming stability cannot be assessed because the skill files are absent; versioning is a single 'v0.1' with no CHANGELOG; maintenance responsibility points only to issues/PRs and a Security Advisory with no maintainer commitment or response target. Those three score 1.

Effectiveness4 / 13 · 1.5/5

For output usability, the README shows report samples and before/after status tables, but the actual HACKME_REPORT.md files and the skill's output template are not in evidence, so it is unclear whether output is directly consumable in an engineering workflow — 1. Marginal value has unusually honest evidence: the author published a negative benchmark result (security advice gave zero benefit on isolated functions for a capable model) and pivoted to runtime attack accordingly, which raises credibility; but that same result indicates limited marginal value in some settings, and there is no independent third-party reproduction — 1. On cost/benefit, the claimed zero-dependency Markdown form is cheap, but patches modify user code and require a running app with potentially destructive requests, and the trade-off is not quantified — 1.

Verifiability3 / 8 · 1.9/5

Key claims (6 VAmPI bugs, 4 ledgerlite bugs, 5 VulnShop bugs, 22/24 benchmark classes) point to in-repo files, so traceability is intended, but the cited examples/*/HACKME_REPORT.md, benchmark results, and skill files are all absent from this evidence, so nothing can be cross-checked — claim_traceability and cross_source_corroboration each score 1. Fact/inference separation is handled well: the author explicitly distinguishes 'proven', 'same pattern fixed but not separately proven', and 'task classes not yet model-scored', which is a genuine positive, but again lacks verifiable raw records, so it also scores 1.

Risks and how to mitigate them
  • Evidence covers only README, LICENSE, SECURITY.md, and one CI workflow; the skill body (skills/paranoid), commands/hack-me.md, references, example reports, and benchmark results are absent, so no behavioral claim can be verified statically.
  • The tool patches user application code directly, yet no backup, diff-confirmation, or rollback mechanism is described; use only on a clean VCS state and review every patch by hand.
  • README claims 'no dependencies, no network calls', but benchmark/harness/run.py imports and executes solution code it is pointed at (acknowledged in SECURITY.md); do not run that harness against untrusted code.
  • The proof step captures and displays real credentials (password dumps, session tokens), and the material does not say how such sensitive data is stored or purged; control log and report retention yourself.
  • Publisher identity is unverified by the FollowAgents registry; review the skill instructions yourself before installing, especially whether the promised refusal of out-of-scope requests is actually implemented.
Evidence confidence: Low Reviewed Oct 08, 2026 Reviewed revision b5bbdcead155
See the full review method →
View on GitHub ↗ Install ↓

Compare agents like this one

The same FARS review applied across the shortlist this agent qualifies for.

Related agents