# Pentagi CLI Tools: Complete Guide to Command-Line Utilities for Pentesting Automation

> Automate pentesting with Pentagi CLI tools. Explore the main pentagi server, installer, and diagnostic testers for efficient security operations. Get the complete guide.

- Repository: [VXControl/pentagi](https://github.com/vxcontrol/pentagi)
- Tags: how-to-guide
- Published: 2026-03-21

---

**Pentagi provides five specialized command-line utilities—the main `pentagi` server, an interactive `installer` wizard, and three diagnostic testers (`ctester`, `ftester`, and `etester`)—all located in `backend/cmd/` and distributed as separate binaries.**

The `vxcontrol/pentagi` repository is an open-source autonomous penetration testing platform that includes a complete suite of **Pentagi CLI tools** for deployment, configuration, and debugging. These utilities complement the web interface and REST/GraphQL APIs, enabling fully automated workflows from initial terminal setup to granular component debugging.

## Overview of Pentagi CLI Tools

Pentagi ships purpose-built command-line utilities that handle distinct operational phases. All binaries are compiled from source located in `backend/cmd/` and share common infrastructure for configuration handling via `pkg/config`, structured logging, and Docker interaction.

| CLI Tool | Purpose | Source Location |
|----------|---------|-----------------|
| `pentagi` | Main server binary that starts the HTTP/WebSocket API, UI proxy, task queue, and AI-agent orchestrator | [`backend/cmd/pentagi/main.go`](https://github.com/vxcontrol/pentagi/blob/main/backend/cmd/pentagi/main.go) |
| `installer` | Interactive terminal wizard for system checks, LLM provider configuration, search-engine setup, and security hardening | [`backend/cmd/installer/main.go`](https://github.com/vxcontrol/pentagi/blob/main/backend/cmd/installer/main.go) |
| `ctester` | Container tester that validates LLM provider connectivity and Docker sandbox execution safety | [`backend/cmd/ctester/main.go`](https://github.com/vxcontrol/pentagi/blob/main/backend/cmd/ctester/main.go) |
| `ftester` | Function tester for invoking individual backend components like tool wrappers and memory lookups | [`backend/cmd/ftester/main.go`](https://github.com/vxcontrol/pentagi/blob/main/backend/cmd/ftester/main.go) |
| `etester` | Embedding tester that verifies vector generation and pgvector store indexing | [`backend/cmd/etester/main.go`](https://github.com/vxcontrol/pentagi/blob/main/backend/cmd/etester/main.go) |

## Core CLI Components

### Main Server Binary (`pentagi`)

The **`pentagi`** CLI serves as the primary entry point for running the autonomous penetration testing platform. Located at [`backend/cmd/pentagi/main.go`](https://github.com/vxcontrol/pentagi/blob/main/backend/cmd/pentagi/main.go), this binary initializes the HTTP and WebSocket APIs, serves the web UI proxy, manages the task queue, and coordinates the AI-agent orchestrator.

### Interactive Installer (`installer`)

The **`installer`** utility provides an interactive terminal user interface (TUI) that guides administrators through pre-deployment validation. Found in [`backend/cmd/installer/main.go`](https://github.com/vxcontrol/pentagi/blob/main/backend/cmd/installer/main.go), it performs system checks, configures LLM providers (OpenAI, Anthropic, Ollama), sets up search engines, validates Docker socket permissions, and applies security hardening before generating the production `.env` file.

The installer leverages shared processing logic in [`backend/cmd/installer/processor/docker.go`](https://github.com/vxcontrol/pentagi/blob/main/backend/cmd/installer/processor/docker.go) for Docker CLI and API interactions, and UI components in `backend/cmd/installer/wizard/` for the terminal interface.

### Diagnostic Testers (`ctester`, `ftester`, `etester`)

Pentagi includes three specialized testing CLIs for validating specific subsystem health before and during deployment:

- **`ctester`** (Container Tester): Validates that chosen LLM providers are reachable, that models respond correctly, and that Docker-based sandboxes can execute tools safely. This tool is essential for early-stage provider selection and connectivity verification.

- **`ftester`** (Function Tester): Allows developers to invoke individual backend functions—such as tool wrappers, memory lookups, and vector store queries—with custom arguments. This enables granular debugging of single components without starting the full server.

- **`etester`** (Embedding Tester): Verifies that the embedding service (OpenAI, Anthropic, Ollama, etc.) returns vectors of expected dimensions and that the pgvector store can properly index and search them.

## Build Process and Distribution

All Pentagi CLI tools are compiled using a multi-stage Dockerfile that produces optimized binaries for the Alpine Linux runtime. The build process uses Go 1.22 and applies `-trimpath` flags to reduce binary size and improve reproducibility.

```dockerfile

# Build stage

FROM golang:1.22 as be-build
WORKDIR /src
COPY . .
RUN go build -trimpath -o /ctester ./cmd/ctester
RUN go build -trimpath -o /ftester ./cmd/ftester
RUN go build -trimpath -o /etester ./cmd/etester
RUN go build -trimpath -o /installer ./cmd/installer
RUN go build -trimpath -o /pentagi ./cmd/pentagi

# Runtime stage

FROM alpine:3.19 as runtime
COPY --from=be-build /ctester /opt/pentagi/bin/ctester
COPY --from=be-build /ftester /opt/pentagi/bin/ftester
COPY --from=be-build /etester /opt/pentagi/bin/etester
COPY --from=be-build /installer /opt/pentagi/bin/installer
COPY --from=be-build /pentagi /opt/pentagi/bin/pentagi

```

The final runtime image places all binaries in `/opt/pentagi/bin/`, making them available for both local execution and containerized workflows. This architecture ensures that the Pentagi CLI tools are self-contained and deployable across different environments without external dependencies.

## Practical Usage Examples

The Pentagi CLI tools support a complete development and deployment workflow from terminal initialization to component debugging.

### Initial Setup with the Installer

Run the interactive installer to generate configuration and validate system prerequisites:

```bash

# Local execution

./installer

# Or via Docker

docker run --rm -v $(pwd):/opt/pentagi vxcontrol/pentagi /opt/pentagi/bin/installer

```

The wizard creates a production-ready `.env` file and verifies Docker socket permissions according to the logic in [`backend/cmd/installer/processor/docker.go`](https://github.com/vxcontrol/pentagi/blob/main/backend/cmd/installer/processor/docker.go).

### Validating LLM Providers

Before deploying workflows, use `ctester` to verify provider connectivity and sandbox execution:

```bash

# Test OpenAI connectivity

./ctester -type openai -verbose

# Or within the running container

docker exec -it pentagi /opt/pentagi/bin/ctester -type openai -verbose

```

This validates that the chosen LLM provider is reachable and that Docker-based sandboxes can execute tools safely.

### Debugging Backend Functions

The `ftester` CLI enables granular testing of individual components without starting the full server:

```bash

# List available penetration testing tools

./ftester -function ListTools -verbose

```

This invokes specific backend functions such as tool wrappers, memory lookups, or vector store queries with custom arguments.

### Verifying Vector Store Health

Use `etester` to validate embedding generation and pgvector indexing:

```bash

# Test OpenAI embeddings

./etester -provider openai -verbose

```

All binaries provide detailed documentation via the `--help` flag, displaying available flags and arguments for each specific testing scenario.

## Key Source Files and Architecture

| File | Description |
|------|-------------|
| [`backend/cmd/pentagi/main.go`](https://github.com/vxcontrol/pentagi/blob/main/backend/cmd/pentagi/main.go) | Entrypoint for the main server binary handling REST/GraphQL APIs and task orchestration |
| [`backend/cmd/installer/main.go`](https://github.com/vxcontrol/pentagi/blob/main/backend/cmd/installer/main.go) | Interactive TUI installer with system checks and provider configuration |
| [`backend/cmd/ctester/main.go`](https://github.com/vxcontrol/pentagi/blob/main/backend/cmd/ctester/main.go) | LLM provider and container execution validation |
| [`backend/cmd/ftester/main.go`](https://github.com/vxcontrol/pentagi/blob/main/backend/cmd/ftester/main.go) | Individual backend function invocation for debugging |
| [`backend/cmd/etester/main.go`](https://github.com/vxcontrol/pentagi/blob/main/backend/cmd/etester/main.go) | Embedding service and pgvector health checks |
| [`backend/cmd/installer/processor/docker.go`](https://github.com/vxcontrol/pentagi/blob/main/backend/cmd/installer/processor/docker.go) | Docker CLI and API interaction logic for the installer |
| `backend/cmd/installer/wizard/` | Terminal UI components for the interactive installer |
| `Dockerfile` | Multi-stage build configuration compiling all CLIs into Alpine runtime |
| `pkg/config` | Shared configuration handling library used across all binaries |

These tools leverage shared libraries in `pkg/config` for consistent configuration handling across all binaries, ensuring that environment variables and settings remain synchronized between the setup wizard and runtime server.

## Summary

- **Pentagi CLI tools** provide five specialized binaries for deployment, configuration, and debugging of the autonomous penetration testing platform.
- The **`installer`** utility automates system validation and generates production configurations through an interactive terminal interface.
- **Diagnostic testers** (`ctester`, `ftester`, `etester`) enable pre-deployment validation of LLM providers, granular function debugging, and vector store health verification.
- All tools are built from `backend/cmd/` using a multi-stage Dockerfile with Go 1.22, sharing common configuration and logging infrastructure via `pkg/config`.
- Binaries are distributed in `/opt/pentagi/bin/` within the Alpine 3.19 runtime image, supporting both standalone execution and containerized workflows.

## Frequently Asked Questions

### What are the main Pentagi CLI tools available?

Pentagi provides five command-line utilities: the **`pentagi`** server binary for running the main application, the **`installer`** for interactive setup and configuration, and three diagnostic tools—**`ctester`** for validating LLM providers and Docker sandboxes, **`ftester`** for debugging individual backend functions, and **`etester`** for verifying embedding services and vector stores. All are located in `backend/cmd/` and compiled as separate binaries.

### How do I build the Pentagi CLI tools from source?

The CLI tools are compiled using a multi-stage Dockerfile that utilizes Go 1.22 to build each binary with the `-trimpath` flag for optimization. The build stage runs `go build` commands targeting the individual command directories (e.g., `./cmd/pentagi`, `./cmd/installer`), then copies the resulting executables into an Alpine 3.19 runtime image at `/opt/pentagi/bin/`.

### What is the purpose of the Pentagi installer CLI?

The **`installer`** binary provides an interactive terminal user interface that automates pre-deployment validation and configuration. It performs system checks, configures LLM providers (OpenAI, Anthropic, Ollama), sets up search engine integrations, validates Docker socket permissions according to [`backend/cmd/installer/processor/docker.go`](https://github.com/vxcontrol/pentagi/blob/main/backend/cmd/installer/processor/docker.go), and generates a production-ready `.env` file before launching the stack.

### How can I validate LLM provider connectivity before running Pentagi?

Use the **`ctester`** (Container Tester) CLI to verify that your chosen LLM provider is reachable and that the Docker-based sandbox can execute tools safely. Execute `./ctester -type openai -verbose` locally or run `docker exec -it pentagi /opt/pentagi/bin/ctester -type openai -verbose` within the container to validate connectivity, model responses, and container execution permissions before deploying workflows.