← 开源
hackerai-tech

hackerai

Find and fix vulnerabilities by chatting with AI

ApplicationsSpecialistsTypeScript
在 GitHub 打开
增长势头
+124 小时新增 Star+0.1%
739
Star
192
Fork
—
本周
7
贡献者
创建于 2025-08-09 · 更新于 2026-10-05 · 今日第 4991 名
主要开发者
README

HackerAI Logo

HackerAI

Your AI-Powered Penetration Testing Assistant

License Website

Getting started

Coding agents should start with AGENTS.md.

Prerequisites

You'll need the following accounts:

Required:

Optional:

Clone the repo

git clone https://github.com/hackerai-tech/hackerai.git

Navigate to the project directory

cd hackerai

Install dependencies

pnpm install

Run the setup script

pnpm run setup

To use abliteration.ai for eligible security requests, create an API key in the abliteration.ai console and set ABLITERATION_API_KEY in .env.local, Vercel, and Trigger.dev. Without this optional key, HackerAI continues using its standard models.

Start the development server

This runs both Next.js and Convex dev servers:

pnpm run dev

Or run them separately in two terminals:

pnpm run dev:next
pnpm run dev:convex

Run the Trigger.dev worker

Agent mode runs the agent loop on a Trigger.dev task. To use the agent locally:

  1. Create a project at https://cloud.trigger.dev and copy your dev secret key (tr_dev_…) into .env.local as TRIGGER_SECRET_KEY.

  2. In the Trigger.dev dashboard → your project → Environment Variables, add the env vars the task needs to run (these live on the worker, not on Vercel): NEXT_PUBLIC_CONVEX_URL, CONVEX_SERVICE_ROLE_KEY, OPENROUTER_API_KEY, OPENAI_API_KEY, AWS_S3_ACCESS_KEY_ID, AWS_S3_SECRET_ACCESS_KEY, AWS_S3_REGION, AWS_S3_BUCKET_NAME, and E2B_API_KEY. Cloud Agent execution currently uses E2B. MIOSA execution and migration are paused in code, including explicit provider overrides. Retain MIOSA_API_KEY when cleanup or recovery of existing MIOSA files is needed. Before resuming the rollout, follow the MIOSA runbook. New Miosa workspaces default to the native hackerai-tools template; optionally set MIOSA_TEMPLATE_ID to override it. An existing miosa-sandbox-docker override still selects the Docker template, so remove or update that value in each intended runtime to use the native default. Existing workspaces retain their original runtime and files. Migrated workspaces require verified recovery before they can use E2B; their retained E2B source may be stale. Add any optional keys you use (ABLITERATION_API_KEY, PERPLEXITY_API_KEY, JINA_API_KEY, etc.).

  3. Start the worker in a third terminal:

    pnpm dev:trigger
    

    This starts the default Trigger.dev worker used by local Agent requests. To start an explicitly routed Trigger.dev branch instead, set a stable branch name with TRIGGER_DEV_BRANCH=my-local-agent pnpm dev:trigger. Only use that override when the request path is configured to target the same Trigger.dev branch.