mrkeyoor.com_
Sat 03 Oct 23:33 UTC
AI Toolsevaluationupdated 03 Oct 2026

ARTEX review

ARTEX is a Chinese-language, self-hosted system that lets multiple AI agents plan and carry out penetration-testing work inside an asset and evidence dashboard. Its README and sole file in `docs/` are in Chinese, and the repository has no separate English README or English documentation file. It tracks targets, tool calls, traffic, findings, approvals, and the chain of evidence behind each task.

Verdict

Our ARTEX run built in 66 seconds, but its 99-second test step ended with 28 passing and 3 failing tests out of 31. Treat it as source material and a local security-research lab, which is also the limit stated in its own README. Do not choose it for real client work or internet-connected testing, even with authorization, because the published usage rules explicitly forbid that job.

We ran it

Lab card: what happened when we ran ARTEXScreenshot of ARTEX (artex-demo.vercel.app)
Install✓ · 35s184 packages
Build✓ · 66s
Tests✗ · 99s28 passed · 3 failed of 31 (go test)
Repo598 files~151,519 lines of source · 12.5 MB · 1 CI workflows · Dockerfile

Answers from our run

Does ARTEX build from source?

Dependencies installed in 35 seconds (184 packages), and the build succeeded in 66 seconds. We cloned commit d003372 into a clean Debian container with 3 CPUs and no project-specific setup.

Do ARTEX's tests pass?

Not all of them: 28 of 31 passed and 3 failed when we ran the project's own test command (go test). Some failures need services or credentials a bare container does not have.

Who should not use ARTEX?

Anyone conducting a real penetration test, including an authorized test of an owned system: the README expressly limits ARTEX to learning, source research, and isolated local validation, and forbids tests against any online or networked system.

What are the alternatives to ARTEX?

PentAGI, PentestGPT, Cairn. Our ARTEX run built in 66 seconds, but its 99-second test step ended with 28 passing and 3 failing tests out of 31.

Setup3/5Build passed, but PostgreSQL, an LLM, and a failed suite add work
Docs3/5Detailed Chinese setup and architecture; no English docs found
Community4/51,465 stars, an October 3 push, and active September releases
Maturity2/5v0.3.14 is active, but tests and scope controls need work

Who it’s for

Security researchers studying agent planning and evidence graphs in an isolated local lab.
Chinese-speaking developers who want a Go backend, embedded Next.js interface, and PostgreSQL storage in one deployment.
Researchers comparing planner and worker coordination on legal, non-networked test targets.
Teams prepared to review every command, scope decision, and generated finding rather than trust autonomous output.

Who it’s NOT for

Anyone conducting a real penetration test, including an authorized test of an owned system: the README expressly limits ARTEX to learning, source research, and isolated local validation, and forbids tests against any online or networked system.
Operators who need a hard technical scope boundary: open issue 153 documents derived domains being added automatically and tested beyond the supplied IP list.
Release pipelines that require a green fresh-container suite: our run ended with 28 passing and 3 failing tests out of 31.
English-only teams: the README, release notes, issue discussion, and file under docs/ are Chinese, with no separate English documentation found.
Proprietary hosted forks that cannot publish their modifications to users: the project uses AGPL-3.0 and the README calls out its network source-sharing obligation.

Setup reality

Our sandbox installed commit d003372 in 35 seconds, adding 184 packages. The build passed in 66 seconds. Tests exited with code 1 after 99 seconds: the harness reported 28 passed and 3 failed out of 31, while the log tail named seven failing TestNotify... cases in the server package.

ARTEX needs PostgreSQL plus an Anthropic or OpenAI key, compatible endpoint, or UI-configured model. The documented installer can choose Docker Compose or a local Go build. First login at port 8787 sends you to /setup to create the administrator password.

The Docker image includes security tools, while the service also exposes a traffic-recording proxy on port 8788. Remote MCP can use Streamable HTTP or SSE. Keep the system in an isolated lab, follow the README's usage limits, and close the proxy and application ports to untrusted networks.

ARTEX is limited to isolated local research

ARTEX calls itself an autonomous penetration-testing system, but its usage terms set a smaller boundary. The README permits source study and technical validation in an isolated local environment. It forbids scanning, probing, exploitation, or attacks against any online or networked system, even when the operator owns it or has authorization. That rules out client work and internal assessments.

Inside that boundary, a planner creates intentions, workers execute one intention at a time, and a human can approve intercepted commands. The interface records tasks, assets, findings, traffic, token use, and activity. The default is 3 workers per task. PostgreSQL stores the results, and the Go backend embeds a static Next.js interface.

Two graphs keep assets separate from the reasoning trail

ARTEX stores targets in a shared asset graph and each task's reasoning in an exploration graph. Asset nodes cover domains, IP addresses, services, applications, and endpoints. Exploration nodes represent goals, intentions, facts, findings, and hints. Anchors join the two, showing which task tested an asset and which evidence led to a finding.

The planner wakes when the graph changes and keeps a task-level to-do list across fresh sessions. Workers can search one another's traces before repeating an action. ARTEX also has a recording proxy, command approvals, reports, skills, memory, and remote MCP connections over Streamable HTTP or older SSE. It is closer to a security operations application than a single prompt loop.

What happened when we ran it

Our sandbox cloned commit d003372 with 598 files, about 151,519 lines of source, and a 12.5 MB checkout. Installing its Go dependencies succeeded in 35 seconds and brought in 184 packages. The build also succeeded, taking 66 seconds. We ran this in an unprivileged golang:1.24-bookworm container with 3 CPUs, 8 GB of RAM, and no secrets.

The test command failed with exit code 1 after 99 seconds. The harness summary recorded 28 passed and 3 failed out of 31. The final log lines named seven failing server tests: status-change suppression, the test-message endpoint, delivery history and retry, metadata and settings round-trip, public-base-URL deep links, missing-base-URL behavior, and digest segmentation. The server package failed, while sidequestion and traffic finished successfully. The log tail does not establish why those notification tests failed.

The repository has 1 CI workflow, a Dockerfile, and a Compose file, but no directory named tests. Go tests commonly sit beside source files, so that layout does not measure quality. The useful result is that commit d003372 failed its complete test step in our fresh container. Reproduce the named notification cases before relying on alerts.

Setup needs PostgreSQL, an LLM, and an isolated network

The shortest documented route is install.sh, which can select a full Docker deployment or a local build. Manual Compose setup needs a PostgreSQL password and may take an Anthropic key. OpenAI credentials and compatible base URLs are also supported, and model details can be entered in the interface. The application listens on port 8787, sends the first browser visit to /setup for an administrator password, and can run its traffic proxy on port 8788.

Source builds compile the web interface first, copy its static output into the Go embed directory, and then build with the embedui tag. Prebuilt archives use start.sh or start.bat as a supervisor for the in-app updater. Version v0.3.14 was published on September 24, 2026. The README warns that a binary-only update does not refresh the security tools in a Docker image and that updating interrupts active tasks.

AGPL-3.0 requires a modified network service to provide its corresponding source to users, according to the README. A hosted fork needs a source-distribution process and license review. PostgreSQL data, local files, and skills persist across upgrades. Back up both the database and data directory because schema changes do not roll back with the binary.

Open issue 153 shows why scope needs an external guard

A September 20 report describes ARTEX moving outside a supplied list of 60 IP addresses. According to issue 153, agents derived root domains from certificates and pages, automatically added those domains to task scope, enumerated subdomains, and continued testing the resulting assets. The issue calls that expansion outside explicit authorization. This is one report, yet it concerns the control that matters most in any autonomous security tool: where activity is allowed to go.

Keep the lab behind firewall rules that cannot reach anything else, use disposable credentials, and review command approvals. Open issue 164 asks for clearer retry and allow-or-block behavior when command interception errors. Neither report proves every run crosses scope, but both support placing the effective boundary outside the agent process.

October activity shows speed, while English support remains absent

GitHub showed 1,465 stars, 39 open issues, and 2 open pull requests on October 3, 2026. The repository was pushed that day, nine days after v0.3.14. Issue traffic continued through October 2, and September releases were frequent. This is active development, even though the current version number, failing test step, and open operational requests point to an early product.

The documentation is detailed if you read Chinese. It covers five installation paths, proxy behavior, updates, database configuration, architecture, and license limits. The root listing has one README.md, and docs/ contains one Chinese-named document about vulnerability traffic evidence. There is no English README or English documentation file in those locations. English-only teams would be translating safety rules and deployment instructions, which is a poor place to accept ambiguity.

Alternatives

ProjectWhat it isPick it when
PentAGI gh↗An MIT-licensed autonomous security-testing system with container isolation, a web UI, APIs, and monitoring integrations.pick this instead when English operations documentation and a broader production-style service stack matter more than ARTEX's dual-graph interface.
PentestGPTAn MIT-licensed agent framework for staged CTF and penetration-testing workflows using Claude Code or Codex.pick this instead when you want a research-oriented command-line workflow rather than a persistent multi-user dashboard.
CairnAn AGPL state-space search engine whose first validated domain is autonomous penetration testing.pick this instead when you want a reusable fact-and-intent search engine instead of ARTEX's full asset, traffic, and findings product.

What people are saying

  1. [github-trending] Autumn-27/ARTEX

Sources

  1. ARTEX README
  2. ARTEX repository facts
  3. ARTEX v0.3.14 release
  4. Out-of-scope testing report 153
  5. Command interception retry request 164

More ai tools reviews

chandra · production-agentic-rag-course · GPT-as-Policy · NeuralScreen · mural · recurrent-looped-tranformer · the whole board →