PWNPWL

AI pentest orchestration. A team that's skeptical of everything and makes you show your work before you get credit, but still helps get the engagement done. You know, like work.

_

BRIEFING

Autonomous pentesting with a built-in trust problem.

PwnPwl orchestrates the whole pentest across as many targets as you point it at. Different roles own different decisions, what to attack next, whether an exploit actually worked, when to give up and move on. The role that ran the command never gets to call it a finding; validation happens blind, with nothing but the tool input and raw output. Protective policies gate every shell interaction, and every verdict traces back to the output that produced it.

THE HANDLES

Strategist
Owns the plan. Breaks objectives into goal contracts, rewrites the approach after vetoes, and calls bullshit on completion claims. Deliberately runs a different model than the Actor.
Critic
Doesn't trust the Actor's world model. Audits against raw tool output, vetoes weak halts, and steps in when roles disagree. Has a veto budget so it can't stall things indefinitely.
Supervisor
Validates findings blind. Never sees the Actor's reasoning, just tool input and raw output. Can downgrade confidence but can't delete findings. Goes back and re-examines old findings when new evidence shows up.
Researcher
Quiet recon without running noisy tools. Called when the Actor needs exploit feasibility, service fingerprinting, or CVE context. Also catches repeated tool failures and pulls the actual man page instead of letting the Actor keep guessing.
Actor
Has shell or tool access. Picks attacks, runs tools, reads output. Gets a fresh view of campaign state every round instead of an ever-growing transcript.
SHOW DON'T TELL
RULES OF ENGAGEMENT
COMMS

In active development. Not publicly released yet, but access may be granted on request. If you just want to ask questions or talk about the project, same address. Calendar up to date.

info@pwnpwl.com