Seven containers make the light install a security platform
RedAmon is much bigger than an AI wrapper around Nmap. Even its lighter setup starts 7 containers: a web app, PostgreSQL, Neo4j, the agent, a Kali sandbox, a recon orchestrator, and a broker that filters Docker socket access. Recon results flow into a graph, the agent can call security tools through MCP, and CypherFix can triage findings, clone source, propose edits, and open a GitHub pull request. OpenVAS adds 4 more runtime containers plus feed initialization jobs.
That range is useful when your current assessment already jumps between scan output, notes, exploit consoles, and source repositories. The checkout we measured made the scale visible: 3,164 files, about 632,972 lines of source, and 424.7 MB before dependencies. RedAmon also ships test targets, security-tool containers, agent orchestration, a Next.js interface, and several databases. Adopting it means operating a small security platform, not adding one command to a CI job.
Dangerous tools require approval by default
The documented safety model has more substance than a warning banner. A deterministic target guard blocks government, military, education, and international-organization domains at project creation, scan launch, and agent reasoning. A separate model-based guard covers other sensitive targets and fails closed at startup. Phase rules limit which tools can run, exploitation and post-exploitation upgrades wait for approval, and 17 dangerous tools use explicit confirmation by default. There is also an emergency stop for running agent work.
Those controls do not supply authorization. A scope mistake can still hit the wrong host, and an approved offensive action can still damage a permitted target. The rules-of-engagement check binds scans to targets and time windows, although the security notes say the time window is advisory during agent reasoning. Use isolated test systems first, write the permitted ranges down, and keep the human approval step. The repository's legal notice is direct: only test systems you own or have explicit written permission to assess.
What happened when we ran it
Our sandbox installed the Python project under agentic/ in 9 seconds, adding 35 packages and using 37 MB on disk. Its build completed in 1 second. Pytest then exited with code 1 after 15 seconds: 252 passed, 104 failed, 13 skipped, 96 hit collection or setup errors, and 144 subtests passed. Pip-audit reported 0 known vulnerabilities in the installed Python environment.
The tail of the test log showed repeated ModuleNotFoundError messages for pydantic in the fireteam retry tests. Cases for rate limits, overloaded services, permission errors, and HTTP status handling all failed at that import. The log does not say why the module was unavailable, so we will not assign a cause. The practical result is enough: commit 724c832 did not produce a trustworthy green suite in our fresh unprivileged Debian container.
This was not a deployment benchmark. Our 15-second test run did not start PostgreSQL, Neo4j, the Kali sandbox, OpenVAS, or target-facing scan containers. It did not download vulnerability feeds, call an LLM, launch an exploit, or assess the project's published benchmark claims. The measured checkout had a Dockerfile, Compose file, and tests directory, but 0 CI workflow files. A local test command this large needs a documented, reproducible environment even when development uses other checks.
The local stack exposes 3 powerful LAN ports
RedAmon documents 2 deployment postures. The default local stack publishes the web app on port 3000, the agent on 8090, and a reverse-shell catcher on 4444 to the LAN. Internal databases, MCP services, and the orchestrator bind to loopback. The project explicitly says the raw stack is unsuitable for a public IP because it lacks the internet-facing controls. That warning matters when the agent endpoint can drive tools and the reverse-shell service is intentionally reachable.
The hardened single-host deployment changes the boundary. It binds internal services to loopback, exposes one HTTPS origin through nginx, configures firewall and SSH rules, generates service secrets, and refuses weak or missing values. The Docker broker prevents spawned scanners from asking the daemon for arbitrary images, privileged mode, device access, or broad host mounts. A generic docker compose up on a cloud VM is the wrong path.
The minimum footprint starts at 80 GB
Without OpenVAS, the README calls for 2 CPU cores, 4 GB of RAM, and 80 GB free. The OpenVAS configuration raises that to 4 cores, 8 GB of RAM, and 110 GB, with 16 GB recommended. The server guide goes further for ongoing engagements because Neo4j data, scan output, PostgreSQL, and logs keep growing. A local knowledge base adds another download, while dynamic scans create more containers on demand.
Configuration happens in the web interface after an admin account is created. You need at least one supported LLM path, such as OpenAI, Anthropic, OpenRouter, Bedrock, or a compatible local endpoint. Tavily, Shodan, NVD, Vulners, URLScan, and other intelligence sources are optional and use separate keys. GitHub access is needed if CypherFix will clone a private repository and open a pull request. Secret count and provider cost rise with the features you enable.
September 2026 work is active despite the failed suite
GitHub recorded a push on September 27, 2026. The repository had 2,725 stars and 16 combined issues and pull requests when fetched, with a pull request updated the next day. The latest GitHub release was v6.14.1 from September 11, while the README badge named a newer version, so the branch has moved beyond that release page. Recent release notes fixed an updater that could leave a checkout unable to pull after scans changed tracked runtime files.
Active maintenance does not resolve our 104 failures, and a clean pip-audit does not validate an autonomous attack chain. RedAmon earns attention for putting scope gates, confirmation, container controls, and a hardened deployment beside its offensive features. Test those controls, not just the scanner output. If your team cannot explain each allowed target, each exposed port, and each approved action before the agent starts, use Nuclei or Atomic Red Team first.

