NeoTheCapt/RedteamAgent
Coding · tested 2026-09-22 · by the Hlido desk, not the vendor
In short: A structured red-team workflow for authorized pentesting — decent docs and traction, but unlicensed and CI-less.
7 PASS · 3 FAIL of 10 public-surface claims
Quick answer
NeoTheCapt/RedteamAgent scores 73/100 (STEADY) on Hlido’s independent, hands-on test (reviewed 2026-09-22). STEADY (73) — a repo-surface score below the 82 ceiling because two measurable signals are missing: no licence and no CI workflows. Pricing: Open source (free entry point documented).
RedteamAgent turns a coding agent (Claude Code / OpenCode / Codex) into a structured recon → test → exploit → report pentesting workflow, with containerized tooling and resumable state, scoped explicitly to authorized labs and web-app testing. The repository is reasonably healthy: a 21K-char README, a tagged release (v0.1.1), 92 stars, and commits within the year. Two real gaps hold it below the batch's top: it carries no licence (which is a genuine adoption blocker — without one, reuse rights are unclear), and there are no CI workflows. Given it is offensive-security tooling, the authorized-use framing in its own description is the right posture; the register scores the repository, not the tool's operational effectiveness, which was not tested.
Why STEADY
STEADY (73) — a repo-surface score below the 82 ceiling because two measurable signals are missing: no licence and no CI workflows. What is present is solid: reachable, a 21K-char README with documented usage, a tagged release, and 92 stars. Not VITAL because effectiveness of the recon/exploit workflow needs hands-on testing that repo signals cannot provide.
Public-surface checklist
- PASS Repo reachable (required) — GH API 200 for NeoTheCapt/RedteamAgent
- PASS Readme present (required) — README length 21389
- FAIL License present (required) — none
- PASS Install documented (required) — install/usage section found in README
- PASS Active 12mo (required) — last push 63d ago
- PASS Releases present — latest v0.1.1
- PASS Community traction — 92 stars
- FAIL Ci or tests — no .github/workflows
- PASS Recent commit 90d — last push 63d ago
- FAIL Agent consumable — none found
What we saw
1 screenshot captured by the Hlido engine during the reviewed run (run-984d6fd20cb6ea30-github-com). Our own captures — not vendor marketing material.
What it does well
- Clear, structured workflow: recon → test → exploit → report
- Documented usage in a substantial README (21K chars)
- A tagged release (v0.1.1) and containerized, resumable design
- Reasonable early traction (92 stars)
- Explicitly scoped to authorized labs / web-app pentesting
What it fails at
- No licence — reuse and redistribution rights are unclear (adoption blocker)
- No CI workflows
- Operational effectiveness of the pentest workflow was not hands-on tested
Red flags
- No licence file — legal status of reuse is undefined
Best for
- Security teams running authorized pentests who already use Claude Code / Codex / OpenCode
- Labs wanting a resumable, containerized recon-to-report harness
Not recommended for
- Anyone without explicit authorization to test the target (misuse is out of scope by design)
- Organizations that require a clear open-source licence before adoption
Pricing & access
- ModelOpen source
- Free entry pointYes — a free tier or open-source edition is documented
Derived from Hlido-held evidence only (engine checklist + editorial text); quotes are verbatim from the scorecard; not vendor-supplied; re-derived daily. Verify current prices on the vendor's pricing page. Last verified 2026-07-16.
Related agents
Agent relevance
CLI
Agentic-Commerce Readiness 29/100 · SURFACE-ONLY
Independent readiness for agent delegation & transaction. How it’s scored · check live
Wraps an existing coding agent (Claude Code / OpenCode / Codex) into a pentesting workflow; installed from the repo and driven through the host agent. Consumable by developers, not a standalone callable service.
Agent-friendly score: 5/10
Score over time
The longitudinal record — every point is the score as published on that date. Raw series.
