T3MP3ST — What is it?

T3MP3ST is an autonomous red teaming platform that harnesses AI coding agents to perform offensive security testing across various domains.

⭐ 4,470 Stars 🍴 953 Forks TypeScript AGPL-3.0 Author: elder-plinius
Source: Official README and linked documentation View on GitHub →

Why it matters

T3MP3ST is being discussed because its innovative approach of using AI coding agents for offensive security testing, addressing the pain points of complex and expensive traditional red teaming tools. Its key technical choices include reproducibility, keyless operation, and honesty about scope, which differs through the field.

Source: Official README and linked documentation

Core Features

Multi-agent offensive-security framework

T3MP3ST use multiple AI coding agents to perform various security tests, including recon, exploit, and reporting, across different domains such as web apps, CTFs, robotics, and smart contracts.

Source: Official README and linked documentation
Reproducible results

All claims in the README can be verified and recomputed from committed data using the `npm run verify-claims` command, ensuring transparency and trustworthiness.

Source: Official README and linked documentation
Keyless operation

T3MP3ST operates without the need for API keys or cloud services, use the AI coding agent already present on the user's machine, providing cost and privacy benefits.

Source: Official README and linked documentation
Honest scope

The project clearly defines the status of its features, marking them as stable, experimental, or roadmap, fostering transparency and trust in the project's capabilities.

Source: Official README and linked documentation

Architecture

The architecture of T3MP3ST is modular, with distinct components for different domains of security testing. It uses a multi-agent system, where each agent is responsible for a specific task. The data flow is driven by the user's input, which is processed by the agents and the results are reported back. Key technical decisions include the use of TypeScript for development, Docker for containerization, and a focus on reproducibility and keyless operation.

Source: Official repository tree and dependency files

Project Knowledge Graph

Knowledge graph: project (center) + core features (inner hexagons) + key dependencies (outer chips) npm docker typescript Multi-agent offensive-security frameworkMulti-agent offensi… Reproducible results Keyless operation Honest scope T3MP3ST Project Core feature Key dependency

Tech Stack

LanguageTypeScriptFrameworkNot specified in README, but inferred from code structure and dependencies
npmdockertypescript
Docker for containerization, likely running on a local machine or a cloud provider
Source: Official repository tree and dependency files

Quick Start

npm install npm run server # War Room → http://127.0.0.1:3333/ui/ In the War Room, open Settings and connect a local agent. Then describe a target to Op Admiral and launch.
Source: Official README and linked documentation

Use Cases

T3MP3ST is suitable for security professionals, researchers, and educators who need to perform offensive security testing across various domains. It is useful for black-box testing of web applications, solving CTF challenges, analyzing source code, and hunting for vulnerabilities in smart contracts and embedded systems.

Source: Official README and linked documentation

Strengths & Limitations

Strengths

  • Innovative use of AI coding agents for offensive security testing
  • Focus on reproducibility and transparency
  • Keyless operation for privacy and cost savings

Limitations

  • Limited documentation and community support
  • Some features are still in development and may not be fully stable
Source: Official README and linked documentation

Latest Release

The latest formal GitHub release is v1.0.0, published on 2026-09-08 under the name Certified source checkpoint.

Source: github.com/elder-plinius/T3MP3ST/releases/tag/v1.0.0

Verification and evidence

status: docs-only  |  checked_at: 2026-09-23  |  environment: Docs only. Reviewed the official README, package.json, Getting Started, API Reference, FEATURES, WHITEPAPER, and GitHub Releases. Project dependencies were not installed.  |  limitations: No security test was run against any target, and the benchmark was not independently reproduced. Provider login, local-model compatibility, third-party tool status, and task duration still require confirmation in an authorized environment.  |  observed_output: Official materials agree on Node.js 22.19.0 or newer, npm install, npm run server, 127.0.0.1:3333/ui/, npm run verify-claims, and the v1.0.0 release. The README showed verify-claims at 27 of 27 during review.

Source: github.com/elder-plinius/T3MP3ST (1) · github.com/elder-plinius/T3MP3ST/releases/tag/v1.0.0 (2)

Comparison

T3MP3ST and Strix both perform authorized automated security testing. T3MP3ST's official path emphasizes War Room, MCP, an HTTP API, and reuse of locally authenticated coding agents. Strix's open-source quick start begins with Docker, an LLM API key, and strix --target, and covers code repositories, running web applications, and CI. Start with T3MP3ST for local-agent orchestration or MCP. Start with Strix for a single target parameter and CI-oriented application scanning.

Source: github.com/elder-plinius/T3MP3ST (1) · github.com/usestrix/strix (2)

Verdict

T3MP3ST is a open-source project that offers a novel approach to offensive security testing using AI coding agents. Its focus on reproducibility, keyless operation, and transparency makes it a tool for security professionals and researchers. However, its limited documentation and some features still in development may be a barrier for some users.

Frequently Asked Questions

What did the documentation review verify for T3MP3ST on 2026-09-23?

Official materials agree on Node.js 22.19.0 or newer, npm install, npm run server, 127.0.0.1:3333/ui/, npm run verify-claims, and the v1.0.0 release. The README showed verify-claims at 27 of 27 during review. No security test was run against any target, and the benchmark was not independently reproduced.

What evidence boundary applies to this T3MP3ST review?

The review environment was: Docs only. Reviewed the official README, package.json, Getting Started, API Reference, FEATURES, WHITEPAPER, and GitHub Releases. Project dependencies were not installed. T3MP3ST behavior outside that scope still needs a local check.

Sources and review scope
This review is based on the project's public documentation. Versions, installation commands, and feature boundaries can change upstream; check the cited sources and current release before use. Sources checked on: 2026-09-23 10:52.

Reference materials: README, GitHub API, dependency files