The Red Agent maps the attack surface and proves weaknesses with
non-destructive evidence. The Blue Agent detects the activity,
applies countermeasures and verifies them.
A few questions about the target and the system does the rest.
Prefer to ask first? Switch to Copilot.
0 of 0 todos completed
Pentest copilot
Let's talk about the engagement first. Tell me what you want to test
and what matters, and I'll propose a plan. Nothing runs until you
approve it.
Manage models…
New audit
What kind of target are you testing?
Lab presets:
Optional. If you have credentials, the agents test authenticated
surfaces too. Stored locally in splitagent.yaml.
All optional. The more context you give, the better the
plan the planner proposes for this specific environment.
No document attached.
Need to clarify something? Open the planner chat — it only plans, it never tests.
Models
Toggle models to control what appears in the model picker.
Your active model is marked with a dot.
Providers
Connected
Popular
General
Inference
Configuration file
Connect provider
Keys are stored locally in splitagent config.yaml.
Custom model
Add a model id that the provider catalogue does not list.
Engagement
Target scope and run parameters, saved to .
Set up the isolated environment
SplitAgent installs and runs its security tools inside a disposable Docker
container, so your computer is never modified. Recommended for a
professional, reproducible workflow.
Dockerchecking…
Enginechecking…
Imagechecking…
Workspace—
The image is built once. After that the toolbox starts silently in the
background and you never have to touch Docker again.