What Are the Dependencies of the Pentagi Project? A Complete Stack Analysis

Pentagi relies on a dual-stack dependency model: Go modules (including Gin, GORM, Docker SDK, OpenTelemetry, and multiple LLM adapters) for the backend, and npm packages (React, Apollo Client, Radix UI, and XTerm.js) for the React/TypeScript frontend.

The vxcontrol/pentagi repository implements a full-stack AI-powered penetration testing platform, and understanding the dependencies of the Pentagi project is essential for developers contributing to or deploying the system. The codebase splits external libraries between a Go-based backend handling LLM integrations and containerized sandboxing, and a React/TypeScript frontend managing the terminal interface and GraphQL communications.

Backend Dependencies: Go Modules

The Go backend defines its requirements in backend/go.mod, pulling modules that handle everything from HTTP routing to Docker container orchestration.

Web Framework and HTTP Utilities

The server layer relies on Gin and its ecosystem for request handling. The github.com/gin-gonic/gin module provides the core HTTP router and middleware framework, while github.com/gin-contrib/cors handles cross-origin resource sharing, github.com/gin-contrib/sessions manages user session state, and github.com/gin-contrib/static serves built frontend assets. These are imported and configured in backend/cmd/pentagi/main.go to initialize the web server.

GraphQL Server Infrastructure

For API communications, Pentagi uses github.com/99designs/gqlgen as the GraphQL code generator and runtime server, paired with github.com/vektah/gqlparser/v2 for schema parsing and validation. This combination enables type-safe GraphQL operations between the frontend and backend.

Database and Vector Storage

Data persistence relies on PostgreSQL through several specialized drivers. The github.com/jackc/pgx/v5 package provides the primary PostgreSQL driver, while github.com/jinzhu/gorm offers the ORM layer for model management. Vector embeddings are handled by github.com/pgvector/pgvector-go, and github.com/lib/pq serves as a fallback PostgreSQL driver for legacy compatibility.

LLM Provider Integrations

The backend abstracts multiple AI providers through a unified adapter layer defined in backend/pkg/providers/provider.go. Key dependencies include github.com/aws/aws-sdk-go-v2 (specifically the bedrockruntime service), github.com/ollama/ollama for local model hosting, and custom VxControl libraries github.com/vxcontrol/cloud and github.com/vxcontrol/langchaingo that standardize interactions with OpenAI, Anthropic, Gemini, and other LLM services.

Observability and Monitoring

Distributed tracing and metrics are implemented via the OpenTelemetry Go SDK. The go.opentelemetry.io/otel/* module family (including trace, metric, and log exporters) instruments the backend for performance monitoring and debugging across the containerized execution environment.

Containerization and Sandboxing

Since Pentagi executes penetration testing tools in isolated environments, the backend imports github.com/docker/docker and github.com/docker/go-connections. These modules enable the Go application to create, start, and manage Docker containers programmatically, as implemented in the tools execution layer.

Developer and Utility Libraries

Supporting functionality comes from specialized utility modules. The github.com/charmbracelet/* family (Bubbles, Bubbletea, Glamour, Lipgloss, Ultraviolet, and x/ansi) provides terminal UI components for any CLI interfaces. Logging uses github.com/sirupsen/logrus, while github.com/creack/pty handles pseudo-terminal allocation for interactive sessions. Additional utilities include github.com/google/uuid for identifier generation, github.com/go-playground/validator/v10 for struct validation, github.com/joho/godotenv and github.com/caarlos0/env/v10 for environment parsing, and github.com/pressly/goose/v3 for database migrations.

Frontend Dependencies: npm Packages

The React frontend declares its requirements in frontend/package.json, organized between runtime dependencies shipped to the browser and development tools used for building and testing.

Core React Framework and Routing

The UI foundation consists of react and react-dom for component rendering, with react-router-dom managing client-side navigation between the dashboard, terminal views, and reporting interfaces.

GraphQL Client and State Management

Data fetching uses Apollo Client (@apollo/client) for GraphQL operations over HTTP, combined with graphql-ws for WebSocket-based subscriptions that stream real-time terminal output from the backend. The graphql package provides the core query language utilities. This configuration is centralized in frontend/src/lib/apollo.ts.

Form Handling and Validation

User input management relies on react-hook-form for performant form state, @hookform/resolvers for validation integration, and zod for TypeScript-first schema validation. This trio ensures type-safe form submissions throughout the application.

UI Components and Terminal Emulator

The component library builds on Radix UI primitives (@radix-ui/react-*) for accessible dropdowns, dialogs, and tabs, styled with tailwindcss and accompanied by lucide-react icons. Special-purpose components include sonner for notifications, react-diff-viewer-continued for comparing outputs, react-markdown with remark-gfm and rehype-raw for rendering AI-generated reports, and @react-pdf/renderer for PDF export functionality.

The in-browser terminal implementation in frontend/src/components/term/Terminal.tsx depends on @xterm/xterm and its addon packages (@xterm/addon-fit, @xterm/addon-web-links) to emulate a full terminal environment for interacting with backend sandboxed tools.

Utility and Styling Libraries

Supporting utilities include axios for HTTP requests, clsx for conditional CSS classes, date-fns for date formatting, lru-cache for client-side caching, and marked for markdown processing. The styling pipeline relies on tailwindcss, postcss, and autoprefixer.

Development Tooling

The build system uses vite for fast development and production bundling, with vitest for unit testing. Code quality is enforced by eslint and prettier, while @graphql-codegen/* generates TypeScript types from the GraphQL schema. typescript provides the core type system.

Key Dependency Files in the Repository

Understanding where these libraries are declared helps navigate the codebase:

How Dependencies Are Used in the Code

Initializing the Gin HTTP Server

The backend entry point in backend/cmd/pentagi/main.go demonstrates how Gin and CORS middleware are instantiated:

package main

import (
	"github.com/gin-gonic/gin"
	"github.com/gin-contrib/cors"
	"github.com/vxcontrol/pentagi/pkg/server"
)

func main() {
	r := gin.Default()
	r.Use(cors.Default())

	// Register routes from the internal server package
	server.RegisterRoutes(r)

	// Listen on the configured port
	_ = r.Run(":8080")
}

This snippet uses github.com/gin-gonic/gin and github.com/gin-contrib/cors declared in backend/go.mod.

Configuring the Apollo GraphQL Client

The frontend establishes real-time communication with the backend using Apollo Client and WebSocket links, as defined in frontend/src/lib/apollo.ts:

import { ApolloClient, InMemoryCache, split, HttpLink } from '@apollo/client';
import { GraphQLWsLink } from '@apollo/client/link/subscriptions';
import { createClient } from 'graphql-ws';

// HTTP link for queries & mutations
const httpLink = new HttpLink({ uri: '/api/graphql' });

// WebSocket link for subscriptions
const wsLink = new GraphQLWsLink(
  createClient({ url: `${window.location.protocol === 'https:' ? 'wss' : 'ws'}://localhost:8443/graphql` })
);

// Split traffic based on operation type
const link = split(
  ({ query }) => {
    const definition = getMainDefinition(query);
    return definition.kind === 'OperationDefinition' && definition.operation === 'subscription';
  },
  wsLink,
  httpLink
);

export const client = new ApolloClient({
  link,
  cache: new InMemoryCache(),
});

This configuration consumes @apollo/client and graphql-ws from frontend/package.json.

Executing Docker Containers

The backend sandboxing functionality uses the Docker SDK to run security tools in isolated containers:

package tools

import (
	"context"
	"github.com/docker/docker/client"
	"github.com/docker/docker/api/types/container"
)

func RunNmap(ctx context.Context, target string) (string, error) {
	cli, _ := client.NewClientWithOpts(client.FromEnv)
	resp, err := cli.ContainerCreate(ctx,
		&container.Config{
			Image: "instrumentisto/nmap",
			Cmd:   []string{"-sV", target},
		},
		nil, nil, nil, "")
	if err != nil {
		return "", err
	}
	cli.ContainerStart(ctx, resp.ID, types.ContainerStartOptions{})
	// …collect logs, remove container, etc.
}

This implementation relies on github.com/docker/docker from backend/go.mod.

Rendering Markdown Reports

The frontend renders AI-generated penetration testing reports using React Markdown:

import React from 'react';
import ReactMarkdown from 'react-markdown';
import remarkGfm from 'remark-gfm';
import rehypeRaw from 'rehype-raw';

export const Report = ({ markdown }: { markdown: string }) => (
  <ReactMarkdown remarkPlugins={[remarkGfm]} rehypePlugins={[rehypeRaw]}>
    {markdown}
  </ReactMarkdown>
);

This component uses react-markdown, remark-gfm, and rehype-raw declared in frontend/package.json.

Summary

  • Pentagi uses a dual-stack architecture: Go modules power the backend AI and sandboxing engine, while npm packages drive the React frontend terminal interface.
  • Key backend libraries include: Gin for HTTP routing, GORM and pgx for PostgreSQL, Docker SDK for containerization, OpenTelemetry for observability, and multiple LLM adapters (AWS Bedrock, Ollama, LangChainGo).
  • Key frontend libraries include: React with Apollo Client for GraphQL, Radix UI for components, XTerm.js for the terminal emulator, and React Markdown for report rendering.
  • Dependency declarations live in: backend/go.mod and frontend/package.json, with lockfiles ensuring reproducible builds across environments.

Frequently Asked Questions

Does Pentagi require Docker to be installed separately?

Yes. While the backend includes github.com/docker/docker to communicate with the Docker daemon programmatically, the Docker Engine must be installed and running on the host system. The Go client library depends on the Docker socket or environment variables to manage containers for sandboxed tool execution.

Can I use a different database instead of PostgreSQL?

The current implementation in backend/go.mod specifically imports PostgreSQL drivers (github.com/jackc/pgx/v5, github.com/lib/pq, github.com/pgvector/pgvector-go) and GORM configurations optimized for PostgreSQL. Switching to another database would require replacing these dependencies and updating the connection logic in backend/cmd/pentagi/main.go.

Which LLM providers are supported out of the box?

According to the source code in backend/pkg/providers/provider.go, the project supports OpenAI, Anthropic Claude, Google Gemini, AWS Bedrock, and local Ollama instances. These integrations rely on github.com/aws/aws-sdk-go-v2, github.com/ollama/ollama, and github.com/vxcontrol/langchaingo to standardize API interactions across different model providers.

Are the frontend dependencies suitable for production deployment?

Yes. The frontend/package.json separates dependencies (shipped to browsers, including React, Apollo Client, and XTerm.js) from devDependencies (build tools like Vite, TypeScript, and ESLint). The build process, configured in Vite, tree-shakes unused code and bundles only the required runtime libraries for the production bundle.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →