August 30, 2026 · By YasKad
Z4nzu/hackingtool

hackingtool: an all-in-one console for authorized security testing

Z4nzu/hackingtool · 79,741★ · 9,039 forks

A launcher tool with 215 curated tools across 21 categories, a data-driven catalog, and an optional AI layer that turns natural-language requests into real, documented commands.


What hackingtool is

hackingtool is a security-testing tool launcher: it doesn’t implement attack or defense tools itself, it discovers, installs, and runs them from a single console. The current README describes it as an “all-in-one, AI-guided kit for authorized security testing,” with 215 curated tools across 21 categories (recon, OSINT, web, wireless, phishing, forensics, post-exploitation, among others) and a fixed 63-tag taxonomy that makes every tool discoverable.

The current product is an interactive Python console with three input modes: slash commands (/run, /search, /find), at-references (@nmap, @tag:osint), and natural-language text (“crack a wifi handshake”), which the tool recommender interprets.

The console's three input pathways: slash commands, at-references, and natural language

An optional, bring-your-own-key AI layer (an OpenAI-compatible endpoint or a local Ollama model) acts on top of that catalog: it recommends tools, drafts the exact command for a target, plans multi-step goals, and summarizes findings. With no model configured, every feature degrades to deterministic local behavior: nothing executes autonomously and nothing is fabricated.

Optional bring-your-own-key AI layer: recommends tools and plans without executing anything autonomously

The repository stands apart from tool listings by being a data-driven catalog: every tool is a YAML entry in src/hackingtool/catalog/ with tags from a closed taxonomy and usage cards with real commands, verified against each project’s own documentation.

A data-driven catalog: YAML entries with 63 tags from a closed taxonomy, no invented tools

Origin

The repository was created on April 11, 2020 by Hardik Zinzu (GitHub user Z4nzu), whose account indicates residence in India and a bio centered on “Python | Frappe | ERPNext | Odoo | DevOps,” with a personal blog at hardikzinzu.com. The master branch’s first commit is literally “Initial commit,” on that same April 11, 2020.

Early commits show the project’s modest origin: a single script (hackingtool.py), updated from mobile (“From mobile,” “first time,” “small change”) during the first two weeks, with a sudo git clone-based install and a classic numbered menu. Early tags came later: v1.0 points to a July 19, 2020 commit and v1.1.0 to July 21, 2020.

The early-issue history documents the project’s growing pains: syntax errors from Python 2/3 incompatibility (issue #174, 31 comments; #185, 11 comments), failures running under sudo (#242, 10 comments), and installation problems (#7, 10 comments). There’s also an early security milestone: PR #116, “RCE fix: Changed all cmd executions from os.system to subprocess.Popen calls,” with 12 comments, which eliminated command execution through the system shell.

The modern leap dates to 2026. The March 15, 2026 commit, “Restructure for v2.0.0 with new tools, features, and UI updates” (PR #590), restructured the project; and on July 26, 2026 the full redesign landed: “feat: AI operator console — 215 curated tools, AI layer, /find discovery (v2.0.0 rework),” followed by “chore(release): 3.0.0.” The repository’s GitHub description remains the original (“ALL IN ONE Hacking Tool For Hackers”), but the current README already presents itself as a tool for “authorized security testing” aimed at the full spectrum: red teams, blue teams, OSINT, bug bounty, CTF, and forensics/IR.

Philosophy and principles

The base rules documented in CONTRIBUTING.md are declared “non-negotiable” and are enforced in review and in CI where possible:

  • Authorized targets only. No feature assumes access to systems the operator doesn’t own or isn’t permitted to test.
  • No fabrication. AI outputs are validated against closed sets; catalog commands must be real, documented invocations, never invented.
  • subprocess in list form only. Never shell=True with interpolated input.
  • Pinned, verified downloads. Every download carries a pinned version and a SHA-256 sum; no curl | bash, “ever.”
  • No forced sudo. Tools install into ~/.hackingtool/, not system paths.
  • Linux/macOS first. Windows-exclusive tools are deprioritized.

The README adds design principles for the AI layer: it’s optional and bring-your-own-key; the AI can only return tags from the fixed taxonomy (the catalog resolves tag → tool, so a tool can’t be invented); /find is suggestions only (it never clones, installs, or executes) and makes zero model calls; out-of-scope objectives (jamming, DoS, mass harassment, malware) are denied before any network call, with an authorized alternative offered when one exists; and scan-tool output is treated as untrusted data with respect to the AI (see the operator letter in src/hackingtool/skill/OPERATOR.md).

Safety principles: authorized targets only, no fabrication, subprocess-list-only execution, pinned SHA-256 downloads

How it works

The basic flow documented in docs/HOW-TO-USE.md:

  1. Startup. The console shows the banner, system status, and prompt. Tab completes commands, tool names, and tags; ↑/↓ navigates history.
  2. Discovery. /tags lists the 63 tags with their counts; @tag:osint opens that tag’s tools; /search <keyword> searches names, descriptions, and tags; @nmap opens a tool directly (case-insensitive, with typo tolerance).
  3. Tool card. Every tool shows a description, a link to the project, and, if curated, a usage card with real commands. Menu: 1 install, 2 run, c ask for the exact command for a target, 98 project page, 99 back. If the tool already exists on PATH (apt, brew, Kali), hackingtool reuses the binary instead of re-cloning it.
  4. /find answers “what do I use for X?”: it searches the 215 curated tools first, then the GitHub search API, ranking results with the reason for each placement. It’s suggestions-only: saving a result with a writes it to ~/.hackingtool/found.yaml with no install or execution command, so a discovered entry can never run anything.

The /find command: safe, suggestions-only search with no install or automatic execution

  1. /goal turns an objective into a short plan of real commands (a single model call, for planning only) and runs it step by step with user confirmation ([y] run, [s] skip, [e] edit, [q] abort). Every step runs in list form, never via shell, with a 30-minute-per-step limit, and everything lands in a timestamped workspace under ~/.hackingtool/goals/ (plan.json, run.log with UTC timestamps and each step’s raw output). Tool output is never returned to the model.

The /goal command: step-by-step planning with user confirmation and a 30-minute-per-step limit

  1. Background panels (tmux). With tmux installed, /run <tool> … & opens a labeled window in a detached session; /panes lists them, /attach watches (Ctrl-b d to return), and /kill stops. Without tmux, the tool opens inline.

Background panels with tmux: long-running scans in labeled windows inside a detached session

  1. Headless mode. The same catalog drives a non-interactive orchestrator: hackingtool --engagement acme --targets example.com --pipeline recon normalizes tool output into a findings.json; --report generates a deterministic Markdown report; --ai-summary and --ai-report are optional AI passes that only summarize findings that already exist (the deterministic report is never overwritten by the AI draft).

Headless mode: a non-interactive pipeline producing findings.json and a deterministic Markdown report

The catalog is the technical core: YAML entries in src/hackingtool/catalog/ (or Python classes for custom install/run logic), tags required to exist in src/hackingtool/tags.py (TAXONOMY), and an “overlay” mechanism that lets you add guidance to existing tools. 59 entries are archived (decommissioned or dead upstream) and stay hidden unless show_archived true is set in /config.

Official and semi-official status

  • PyPI: not published. At the time of measurement (August 25, 2026), the PyPI API returned 404 for hackingtool. The README itself hides the PyPI/.deb install instructions with a comment reading “Hidden until these distribution channels are live.”
  • GitHub releases: none. The releases API returned an empty list at measurement time, despite SECURITY.md documenting signed releases with SLSA provenance, a CycloneDX SBOM attested via Sigstore, and PEP 740 attestations for PyPI. That section describes the intended process (or one from a version after the measurement); as of August 25, 2026, no release existed in the repository.
  • Docker Hub: the image hardikzinzu/hackingtool (the author’s namespace) exists, updated on July 26, 2026; the API returned 0 pulls at measurement time, a figure that shouldn’t be read as an adoption indicator.
  • Context7: an August 23, 2026 commit adds context7.json with the URL context7.com/z4nzu/hackingtool and a public key, integrating the project’s docs into Context7 for coding agents.
  • Trendshift: the README includes Trendshift badges (repository 869), a trending-repository tracker.
  • De facto: with 79,100 stars, it’s by far the most-starred “all-in-one hacking” repository on GitHub (the next in that lane has ~746 stars), making it the default reference when someone looks for a single security-tool console. There’s no vendor endorsement or official standards status, however, in the sources consulted.

The ecosystem

The author’s repositories (Z4nzu / Hardik Zinzu)

The author maintains other security projects from the same era, per his repository list consulted in this run:

  • Z4nzu/fakeap: an Evil Twin attack with a fake access point; 160 stars.
  • Z4nzu/fastssh: fast SSH scanning and brute-forcing; 104 stars.
  • Z4nzu/wlcreator: a wordlist generator in C; 95 stars.
  • Z4nzu/PhoneInfoga: an advanced OSINT framework for phone numbers; 84 stars.

The rest of his activity sits in the Frappe/ERPNext ecosystem (forks of frappe, erpnext, raven, krama, agent, education and commerce projects), consistent with his ERP/DevOps developer bio.

Community extensions and plugins

  • AKCodez/hackingtool-plugin (author Ariacodez / AKCODEZ): a Claude Code plugin that wraps the Z4nzu/hackingtool catalog — 183 pentesting and OSINT tools — with automatic backend selection (native bash on Linux/macOS, WSL on Windows, or purpose-built Docker images like instrumentisto/nmap, projectdiscovery/nuclei, caffix/amass, and 20 more). Installed with /plugin marketplace add AKCODEZ/hackingtool-plugin; 1,016 stars and 231 forks, created April 23, 2026. It’s the ecosystem’s most visible extension: it brings the catalog to an AI agent instead of a standalone console.
  • MAXZL1/hackingtool-plugin: another 183-tool integration for Claude Code; 14 stars.
  • assiff/hackingtool: a “by Z4nzu” replica/fork; 98 stars.
  • The main repository accumulates 8,975 forks total, though the vast majority are personal-use clones, not active derivatives.

The ecosystem around hackingtool: the author's repositories, community plugins, Docker images, and agent documentation

Curated lists

  • rawfilejson/awesome-osint-arsenal (2,291 stars): includes Hackingtool in its all-in-one tools table.
  • Wechat-ggGitHub/Awesome-GitHub-Repo (17,192 stars): lists it with a Chinese-language description, a sign of its reach in the Chinese GitHub community.

Agent-oriented documentation

The operator letter (src/hackingtool/skill/OPERATOR.md, also viewable with /skill) defines the “constitution” that governs the AI layer: an authorized-testing persona, authorized targets only, untrusted <scan_data> content, and explicit anti-fabrication rules. Together with the context7.json file, it documents the project’s 2026 strategy: letting third-party AI agents (Claude Code, Context7-enabled agents) operate the catalog under the same safety rules as the console.

Quick-start guide

Installation and first launch

Prerequisites: Python 3.10+ on Linux or macOS (Kali, Parrot, Debian/Ubuntu, Arch…). Windows isn’t supported: the app detects it and exits.

# 1 — get the code
git clone https://github.com/Z4nzu/hackingtool.git
cd hackingtool

# 2 — install onto PATH (isolated environment via pipx)
pipx install .

# 3 — run from any directory
hackingtool

Without pipx: brew install pipx && pipx ensurepath (macOS) or sudo apt install pipx && pipx ensurepath (Debian/Ubuntu/Kali), then open a new shell. Documented alternatives: uv tool install ., venv + pip install ., or the published container docker run -it --rm hardikzinzu/hackingtool:latest.

On first launch, the app creates ~/.hackingtool/ with config.json (default settings), .env (a commented secrets template, chmod 600), tools/ (where installed tools get cloned/built), and history. In a non-interactive terminal (or without prompt_toolkit), it falls back to the classic numbered menu; you can always force it with hackingtool --classic.

Common workflows

  • To explore the catalog: /tags prints the 63 tags with their counts; @tag:osint lists OSINT tools, picked by number; @nmap opens the tool directly; /search wordlist searches by keyword.
  • To find a tool not in the catalog: /find hidden directories on a website returns two blocks — “In your toolbox (vetted)” and “Found on GitHub — NOT vetted by us” — and typing a plus the number saves the result as a bookmark in ~/.hackingtool/found.yaml (no commands, just references).
  • To plan and run an objective: /goal find live subdomains of example.com generates the plan (one model call), asks you to confirm authorization with y, and runs it step by step with [y] run / [s] skip / [e] edit / [q] abort. The plan, log, and each step’s output land in ~/.hackingtool/goals/<UTC-timestamp>/.
  • For long background scans (with tmux): /run nmap -sV -oA scan 10.0.0.5 & starts a labeled panel; /panes lists, /attach watches, and /kill all stops everything.
  • For a scripted engagement (CI or batches): hackingtool --engagement acme --targets example.com --pipeline recon produces findings.json; --engagement acme --report regenerates the deterministic Markdown report.

Essential configuration

File / settingWhat it touches first
~/.hackingtool/config.jsonEvery console setting; edited with /config (arrows to move, t to test the connection) or /config <key> <value> (e.g. /config theme cyan, /config show_archived true).
~/.hackingtool/.envThe AI key (HACKINGTOOL_AI_KEY) and GitHub token (HACKINGTOOL_GITHUB_TOKEN), mode 600; never printed to screen.
ai_base_url + ai_model (+ key)Enables the AI layer with any OpenAI-compatible endpoint; if ai_base_url is left empty, local Ollama is used (e.g. ollama pull llama3).
A scopeless GitHub tokenRaises /find’s limit from 10 to 30 searches per minute; it must be generated with no scopes and no repository selected.
background_runneroff disables tmux background panels.

Environment variables (HACKINGTOOL_AI_BASE_URL, HACKINGTOOL_AI_MODEL, HACKINGTOOL_AI_KEY, HACKINGTOOL_AI_PROVIDER) always take priority over config.json.

Common pitfalls and fixes

  • Windows doesn’t work. The app detects it and exits. The documented fix is Linux or macOS (Kali/Parrot are the typical environments).
  • Without tmux, /run … & doesn’t open panels. The console says so and opens the tool inline; you can disable the attempt with /config background_runner off.
  • /find without a token is limited to 10 searches/minute of the GitHub API. With a personal GitHub token that has no scopes or permissions, it rises to 30; the guide documents step by step where to generate it (/config github).
  • Without a configured model, /goal doesn’t plan: it degrades to tool recommendations for the same objective. Connectivity is checked with /config test, which reports the real failure.
  • Project history (v1.x): early versions failed under Python 2 (syntax errors, issue #174 with 31 comments; #185 with 11) and required specific environments (issues #13 and #242, sudo install failures). The 2026 restructure fixed the install model (pipx/uv, no forced sudo, no curl | bash), but anyone installing old versions from a 2020–2024 clone will run into those documented issues.
  • Offensive categories are present. The catalog includes offensive categories (DDoS, RAT, XSS, phishing). The 2026 layer denies out-of-scope requests (jamming, DoS, mass harassment, malware) in /find and requires confirming authorization in /goal, but the full catalog remains available; scope responsibility falls on the operator, as SECURITY.md acknowledges.

Integrations and migration

  • With AI agents: the operator letter (/skill, OPERATOR.md) is the script the AI layer follows; the context7.json file integrates the docs into Context7 for coding agents; and AKCodez/hackingtool-plugin brings the catalog to Claude Code with Docker/WSL backends.
  • With CI: headless mode (--engagement, --pipeline recon, findings.json, --report) is designed for pipelines; the normalized JSON can be grepped, diffed, or fed into other tools.
  • With security distros: if a tool is already on PATH (apt, brew, Kali metapackages), hackingtool reuses the binary instead of re-cloning it; that’s why it coexists with a Kali install instead of replacing it.
  • Migrating from legacy launchers (v1.x): the flow is cloning the current repository and installing with pipx install .; the old sudo git clone && sudo ./hackingtool.py is obsolete, and tools now live in ~/.hackingtool/tools/ instead of system paths.
  • Migrating to something else: the underlying tools (nmap, sqlmap, nuclei, etc.) are independent projects; leaving hackingtool just means dropping the launcher — the knowledge of each tool is the same you’d get documenting it separately.

Repo numbers

Measured: August 25, 2026, GitHub API.

MetricValue
Stars79,100
Forks8,975
Subscribers1,474
Commits on master340
API open_issues_count132
Total issues (search API)525
Total pull requests (search API)166
Primary languagePython (487,109 bytes; Dockerfile 1,520; Shell 949; Makefile 384)
LicenseMIT
CreatedApril 11, 2020
Last pushAugust 23, 2026
Latest tagv3.0.0 (July 26, 2026); also v1.1.0 (2020) and v1.0 (2020)

The top contributors returned by the API, by contribution count: Z4nzu (122), cclauss (85), Greatest125 (69), mokrunka (6), W1LDN16H7 (4). The 340-commit count was obtained from the final page of the commits API’s pagination link. GitHub’s API uses open_issues_count, which can include open pull requests, so it shouldn’t be read as an issues-only count; the search API distinguishes 525 total issues and 166 total PRs (open and closed). Likewise, the general response’s watchers_count mirrors star count; that’s why subscribers_count is reported as the real subscriber figure. The v2.0.0 tag doesn’t exist as a tag: only as a name in the redesign’s commits (March and July 2026).

How to contribute

The process documented in CONTRIBUTING.md is concrete:

  1. Dev setup: git clone + make setup (once: points git to .githooks, whose pre-push runs the verification gate) and uv run hackingtool to run from source.
  2. The gate: make check (ruff with mandatory lint errors + pytest + catalog and schema validation) is the exact script CI and the pre-push hook run (scripts/check.sh). A PR review is considered a “rubber stamp” of a green gate, so it’s expected to be green, with a check added for non-trivial logic.
  3. Adding a tool (preferred path): a single YAML entry in src/hackingtool/catalog/ — new, or as an “overlay” on an existing one (matched by exact title). Tags must exist in TAXONOMY in src/hackingtool/tags.py; usage is [description, command] pairs with canonical, documented commands; surveillance/C2/keylogger/RAT tools get tags only, no operational commands.
  4. Legacy path: a Python class in the matching tools/*.py file, with list-form installers and pinned downloads + SHA-256.
  5. PRs: branch from master (never commit to master directly), title [New Tool] Name — Category, [Fix] …, or [Improve] …, describe what changed and what was tested, one logical change per PR, and use the PR template.
  6. Bugs and security: functional bugs via the Bug report template; vulnerabilities privately, through GitHub’s advisory flow (SECURITY.md: acknowledgment within 5 business days, a fix or plan within 30 days for confirmed reports).

How the community received it

Public reception is notable for its asymmetry: massive adoption (79,100 stars, the largest in the category) contrasts with a scarcity of verifiable public debate.

  • Hacker News: no thread dedicated to this repository was found. Searches by the repo’s name, by Z4nzu, by the repository URL, and by the project’s tagline returned 0 relevant results (matches for “hacking tool” are unrelated news: Bit Pirate, Pegasus, Metasploit, etc.). No HN points or comments are inferred, then.
  • Reddit: only minimal-activity mentions found via the search API: on r/hacking, thread 18jmsbu “Hackingtool don’t work for me can someone recommend something else?” (1 point, 0 comments); on r/iguru, 190l7qz “HackingTool 1.2.0: ALL IN ONE Hacking Tools” (1 point, 0 comments); and crossposts of 15r59mg “I suggest you to read this articles if you want to start Hacking through CTFs” on r/Kalilinux, r/tryhackme, r/InfoSecWriteups, and r/securityCTF (1 point each). None is a substantive discussion.
  • GitHub (the real debate is here): early issues document novice-user frustration: #13 “error” (39 comments), #174 SyntaxError (31), #185 (11), #242 “error while running sudo hackingtool” (10), #200 “Kali Linux not running the program” (8). The launcher’s security was an early topic: PR #116 fixed execution via os.system (12 comments), and PR #176 “Update ddos.py” (10 comments) shows the scrutiny the included DDoS tools received. The balance from these sources: adoption is enormous and sustained, but the project lives off practical use more than public debate; documented criticisms center on old versions’ install friction and on the presence of offensive tools in the catalog.
  • YouTube: small-scale videos: “how to stay anonymous using Z4nzu’s hacking tool” (Waxweazel81 channel, ~499 views), “Z4nzu/hackingtool - Gource visualisation” (Gourcer channel, ~233 views), and two videos from the “GitHub Daily Trend AI Podcast” channel about the repository (~226 and ~2,289 views, the latter in Spanish).

Hackingtool versus other approaches

ProjectVerifiable overlapVerifiable difference
CodingRanjith/hackingtoolkit (746 stars)An all-in-one Python collection for pentesting and cybersecurity.Its own independent catalog; no comparable documented AI layer in the source consulted.
AKCodez/hackingtool-plugin (1,016 stars)Same base catalog: it’s a Z4nzu/hackingtool wrapper for Claude Code.It doesn’t compete: it extends. It brings Docker/WSL backends and purpose-built images; it runs on top of the AI agent instead of a console.
laxa/HackingTools (338 stars)Compiles hacking tools exhaustively.It’s a list, with no installation or console.
ByteHackr/HackingTools-2 (374 stars)A collection of excellent lists for pentesters.A meta-list (lists of lists), with no execution.
Kali LinuxSame target audience: the README explicitly addresses Kali/Parrot users.Kali embeds tools into the distro; hackingtool runs on any Linux/macOS, reuses binaries already present, and adds discovery layers (tags, /find, /goal) the distro doesn’t provide.

The most useful comparison is by layer: classic all-in-one launchers (including this same project’s own v1.x) solved “install and run”; the 2026 version adds “discover, plan, and document,” with the AI agent as an optional assistant.

Use cases

  • Pentesters and red teamers opening engagements against a target: /goal with authorization confirmation and a per-step audit log (run.log under ~/.hackingtool/goals/), tmux panels for long scans, and headless mode (--engagement, findings.json, --report) for pipelines or reproducible deliverables.
  • Blue team / DFIR analysts: the README states defensive framings (“detect a SYN flood,” “hunt for…”) are never denied in /find, the catalog includes 12 forensic and defensive post-exploitation tools, and surveillance/C2/RAT tools carry tags only, no operational commands, by documented design decision.
  • OSINT investigators: 26 information-gathering tools and the osint tag as an entry point (@tag:osint), plus the Context7 integration for researching agents.
  • Bug bounty hunters: /goal find live subdomains of example.com chains subfinder/httpx/nuclei with step-by-step confirmation; /find bookmarks in found.yaml let you build a personal arsenal without code.
  • Students and CTF/THM players: the “60-second grammar” (commands, at-signs, natural language), per-tool curated usage cards, and no-AI operation (deterministic fallback) lower the barrier compared to installing 215 tools separately.
  • Teams running AI agents over security: the operator letter (OPERATOR.md), the context7.json file, and the community plugin AKCodez/hackingtool-plugin (1,016 stars) document the pattern of letting an agent pick and run catalog tools with anti-fabrication rules and limited trust in scan output.
  • Security infrastructure maintainers assessing surfaces: the same catalog works as an auditable inventory: 215 tools, a closed 63-tag taxonomy, pinned and verified downloads, and the make check gate for contributions.

Resources


This article combines the README, docs/HOW-TO-USE.md, CONTRIBUTING.md, SECURITY.md, the operator letter, the GitHub API (measured August 25, 2026), Hacker News and Reddit searches, the Docker Hub registry, and YouTube results gathered during this investigation. Figures change over time.

Comments