Show HN: Nightcrawler – A local AI pentesting agent running on a smartphone
Posted by NickySlicks 2 hours ago
Comments
Comment by voodooEntity 34 minutes ago
What an irony. I cant publish a attack surface mapping / pentesting tool i wrote which runs fully deterministic and really controlable due to "dual use" legal problems - but llm driven tools hit public space......
sorry for the rant....
Comment by NickySlicks 31 minutes ago
Comment by kreidema 1 hour ago
Comment by oquidave 43 minutes ago
Comment by NickySlicks 33 minutes ago
Comment by saagarjha 37 minutes ago
Comment by NickySlicks 1 hour ago
The project started with a question: how much of a real pentesting workflow could I run locally on relatively old mobile hardware, without relying on a cloud model or API?
Nightcrawler runs a 1.2B-parameter model locally on the Adreno GPU of a OnePlus 8. The model chooses targets and tools, while a separate scope-enforcement proxy validates every command before execution. The system maintains per-host memory in SQLite, rotates between targets, matches detected versions against a local CVE database, executes multi-step playbooks, and generates a structured report.
A few implementation details that may be interesting:
Local inference runs at roughly 115 prompt tokens/sec and 13 generated tokens/sec. The small model only produces a usable command around 50% of the time, so much of the engineering is recovery logic, duplicate detection, persistent memory, and deterministic playbooks. Every command passes through a separate scope and safety layer rather than trusting the model to remain in scope. The project includes a dry-run mode, so the agent loop can be tested without executing real network commands or owning the phone hardware. I've had it running on my home network for the past 3 months uninterrupted
Comment by mr_mitm 49 minutes ago
Comment by NickySlicks 29 minutes ago