Pentagi CLI Tools: Complete Guide to Command-Line Utilities for Pentesting Automation

Pentagi provides five specialized command-line utilities—the main pentagi server, an interactive installer wizard, and three diagnostic testers (ctester, ftester, and etester)—all located in backend/cmd/ and distributed as separate binaries.

The vxcontrol/pentagi repository is an open-source autonomous penetration testing platform that includes a complete suite of Pentagi CLI tools for deployment, configuration, and debugging. These utilities complement the web interface and REST/GraphQL APIs, enabling fully automated workflows from initial terminal setup to granular component debugging.

Overview of Pentagi CLI Tools

Pentagi ships purpose-built command-line utilities that handle distinct operational phases. All binaries are compiled from source located in backend/cmd/ and share common infrastructure for configuration handling via pkg/config, structured logging, and Docker interaction.

CLI Tool Purpose Source Location
pentagi Main server binary that starts the HTTP/WebSocket API, UI proxy, task queue, and AI-agent orchestrator backend/cmd/pentagi/main.go
installer Interactive terminal wizard for system checks, LLM provider configuration, search-engine setup, and security hardening backend/cmd/installer/main.go
ctester Container tester that validates LLM provider connectivity and Docker sandbox execution safety backend/cmd/ctester/main.go
ftester Function tester for invoking individual backend components like tool wrappers and memory lookups backend/cmd/ftester/main.go
etester Embedding tester that verifies vector generation and pgvector store indexing backend/cmd/etester/main.go

Core CLI Components

Main Server Binary (pentagi)

The pentagi CLI serves as the primary entry point for running the autonomous penetration testing platform. Located at backend/cmd/pentagi/main.go, this binary initializes the HTTP and WebSocket APIs, serves the web UI proxy, manages the task queue, and coordinates the AI-agent orchestrator.

Interactive Installer (installer)

The installer utility provides an interactive terminal user interface (TUI) that guides administrators through pre-deployment validation. Found in backend/cmd/installer/main.go, it performs system checks, configures LLM providers (OpenAI, Anthropic, Ollama), sets up search engines, validates Docker socket permissions, and applies security hardening before generating the production .env file.

The installer leverages shared processing logic in backend/cmd/installer/processor/docker.go for Docker CLI and API interactions, and UI components in backend/cmd/installer/wizard/ for the terminal interface.

Diagnostic Testers (ctester, ftester, etester)

Pentagi includes three specialized testing CLIs for validating specific subsystem health before and during deployment:

  • ctester (Container Tester): Validates that chosen LLM providers are reachable, that models respond correctly, and that Docker-based sandboxes can execute tools safely. This tool is essential for early-stage provider selection and connectivity verification.

  • ftester (Function Tester): Allows developers to invoke individual backend functions—such as tool wrappers, memory lookups, and vector store queries—with custom arguments. This enables granular debugging of single components without starting the full server.

  • etester (Embedding Tester): Verifies that the embedding service (OpenAI, Anthropic, Ollama, etc.) returns vectors of expected dimensions and that the pgvector store can properly index and search them.

Build Process and Distribution

All Pentagi CLI tools are compiled using a multi-stage Dockerfile that produces optimized binaries for the Alpine Linux runtime. The build process uses Go 1.22 and applies -trimpath flags to reduce binary size and improve reproducibility.


# Build stage

FROM golang:1.22 as be-build
WORKDIR /src
COPY . .
RUN go build -trimpath -o /ctester ./cmd/ctester
RUN go build -trimpath -o /ftester ./cmd/ftester
RUN go build -trimpath -o /etester ./cmd/etester
RUN go build -trimpath -o /installer ./cmd/installer
RUN go build -trimpath -o /pentagi ./cmd/pentagi

# Runtime stage

FROM alpine:3.19 as runtime
COPY --from=be-build /ctester /opt/pentagi/bin/ctester
COPY --from=be-build /ftester /opt/pentagi/bin/ftester
COPY --from=be-build /etester /opt/pentagi/bin/etester
COPY --from=be-build /installer /opt/pentagi/bin/installer
COPY --from=be-build /pentagi /opt/pentagi/bin/pentagi

The final runtime image places all binaries in /opt/pentagi/bin/, making them available for both local execution and containerized workflows. This architecture ensures that the Pentagi CLI tools are self-contained and deployable across different environments without external dependencies.

Practical Usage Examples

The Pentagi CLI tools support a complete development and deployment workflow from terminal initialization to component debugging.

Initial Setup with the Installer

Run the interactive installer to generate configuration and validate system prerequisites:


# Local execution

./installer

# Or via Docker

docker run --rm -v $(pwd):/opt/pentagi vxcontrol/pentagi /opt/pentagi/bin/installer

The wizard creates a production-ready .env file and verifies Docker socket permissions according to the logic in backend/cmd/installer/processor/docker.go.

Validating LLM Providers

Before deploying workflows, use ctester to verify provider connectivity and sandbox execution:


# Test OpenAI connectivity

./ctester -type openai -verbose

# Or within the running container

docker exec -it pentagi /opt/pentagi/bin/ctester -type openai -verbose

This validates that the chosen LLM provider is reachable and that Docker-based sandboxes can execute tools safely.

Debugging Backend Functions

The ftester CLI enables granular testing of individual components without starting the full server:


# List available penetration testing tools

./ftester -function ListTools -verbose

This invokes specific backend functions such as tool wrappers, memory lookups, or vector store queries with custom arguments.

Verifying Vector Store Health

Use etester to validate embedding generation and pgvector indexing:


# Test OpenAI embeddings

./etester -provider openai -verbose

All binaries provide detailed documentation via the --help flag, displaying available flags and arguments for each specific testing scenario.

Key Source Files and Architecture

File Description
backend/cmd/pentagi/main.go Entrypoint for the main server binary handling REST/GraphQL APIs and task orchestration
backend/cmd/installer/main.go Interactive TUI installer with system checks and provider configuration
backend/cmd/ctester/main.go LLM provider and container execution validation
backend/cmd/ftester/main.go Individual backend function invocation for debugging
backend/cmd/etester/main.go Embedding service and pgvector health checks
backend/cmd/installer/processor/docker.go Docker CLI and API interaction logic for the installer
backend/cmd/installer/wizard/ Terminal UI components for the interactive installer
Dockerfile Multi-stage build configuration compiling all CLIs into Alpine runtime
pkg/config Shared configuration handling library used across all binaries

These tools leverage shared libraries in pkg/config for consistent configuration handling across all binaries, ensuring that environment variables and settings remain synchronized between the setup wizard and runtime server.

Summary

  • Pentagi CLI tools provide five specialized binaries for deployment, configuration, and debugging of the autonomous penetration testing platform.
  • The installer utility automates system validation and generates production configurations through an interactive terminal interface.
  • Diagnostic testers (ctester, ftester, etester) enable pre-deployment validation of LLM providers, granular function debugging, and vector store health verification.
  • All tools are built from backend/cmd/ using a multi-stage Dockerfile with Go 1.22, sharing common configuration and logging infrastructure via pkg/config.
  • Binaries are distributed in /opt/pentagi/bin/ within the Alpine 3.19 runtime image, supporting both standalone execution and containerized workflows.

Frequently Asked Questions

What are the main Pentagi CLI tools available?

Pentagi provides five command-line utilities: the pentagi server binary for running the main application, the installer for interactive setup and configuration, and three diagnostic tools—ctester for validating LLM providers and Docker sandboxes, ftester for debugging individual backend functions, and etester for verifying embedding services and vector stores. All are located in backend/cmd/ and compiled as separate binaries.

How do I build the Pentagi CLI tools from source?

The CLI tools are compiled using a multi-stage Dockerfile that utilizes Go 1.22 to build each binary with the -trimpath flag for optimization. The build stage runs go build commands targeting the individual command directories (e.g., ./cmd/pentagi, ./cmd/installer), then copies the resulting executables into an Alpine 3.19 runtime image at /opt/pentagi/bin/.

What is the purpose of the Pentagi installer CLI?

The installer binary provides an interactive terminal user interface that automates pre-deployment validation and configuration. It performs system checks, configures LLM providers (OpenAI, Anthropic, Ollama), sets up search engine integrations, validates Docker socket permissions according to backend/cmd/installer/processor/docker.go, and generates a production-ready .env file before launching the stack.

How can I validate LLM provider connectivity before running Pentagi?

Use the ctester (Container Tester) CLI to verify that your chosen LLM provider is reachable and that the Docker-based sandbox can execute tools safely. Execute ./ctester -type openai -verbose locally or run docker exec -it pentagi /opt/pentagi/bin/ctester -type openai -verbose within the container to validate connectivity, model responses, and container execution permissions before deploying workflows.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →