{"categories":[{"label":"Security","url":"https://skillfed.io/packages/category/security/2"},{"label":"Terminals","url":"https://skillfed.io/packages/category/terminals"}],"enrichment":{"capability":"bingo is an AI-powered red team terminal that automates security testing across web applications, mobile apps, and smart contracts by accepting natural-language targets and tasks, then orchestrating attacks like SQLi, XSS, WAF bypass, and credential extraction.","skillfed_tags":["penetration-testing","ai-automation","red-team"],"use_cases":["Automated web application penetration testing: describe a target URL and let bingo handle recon, SQLi detection, WAF bypass, and credential extraction.","Mobile app security analysis: extract hardcoded secrets, permissions, exported components, and SSL pinning details from Android APK or iOS IPA.","Smart contract and DApp auditing: test for reentrancy, flash loan vulnerabilities, oracle manipulation, and wallet authentication bypass.","Post-exploitation automation: chain SQLi discovery into webshell deployment, RCE execution, and full database dumps with a single prompt.","Headless CI/CD security scanning: run in silent mode with JSON output for automated vulnerability reporting in deployment pipelines.","Windows malware analysis: static PE analysis including imports, strings, entropy, hardcoded secrets, and C2 indicator extraction."],"what_it_does":"bingo is a terminal-based red team assistant that combines large language models with automated security testing to discover and exploit vulnerabilities in web applications, mobile apps (Android APK, iOS IPA), Windows executables, and blockchain/DApp targets. You describe a target and testing goals in plain English, and bingo orchestrates the attack chain\u2014from reconnaissance (WAF detection, tech fingerprinting) through exploitation (SQLi, XSS, SSRF, file upload, auth bypass) to post-exploitation (credential dumping, database extraction, webshell deployment). It includes built-in engines for SQL injection across all database types, WAF bypass for Cloudflare/AWS/ModSecurity, and optional integration with nmap and sqlmap if installed. The tool supports 25 runtime dependencies including playwright for browser automation, cryptography for JWT/OAuth testing, and various HTTP clients for proxy rotation and Tor integration.\n\nThe package is actively maintained (latest release 8 days ago), requires Python 3.12 or later, and runs only on macOS and Linux\u2014Windows support was permanently discontinued. It carries no known security vulnerabilities as of the query date. The tool is designed for authorized penetration testers and red teamers who want to automate reconnaissance and exploitation workflows through conversational prompts.","worth_installing":"Yes\u2014if you are an authorized penetration tester on macOS or Linux. bingo offers low install friction, active maintenance, permissive MIT licensing, and zero known vulnerabilities. The 25 runtime dependencies are standard and the tool automates complex attack chains. Main gotchas: Python 3.12+ required, macOS/Linux-only, and LLM API keys needed on first launch. Not suitable for Windows users."},"id":"bingo-ai","links":{"html":"https://skillfed.io/packages/bingo-ai","md":"https://skillfed.io/packages/bingo-ai.md","pypi":"https://pypi.org/project/bingo-ai/"},"maintenance":{"status":"active"},"meta":{"latest_release":"2026-08-06","license_spdx":null,"license_treatment":"permissive","name":"bingo-ai","python_support":"supports_current","summary":"AI-powered red team terminal \u2014 Zero-Hallucination \u00b7 WAF bypass \u00b7 XSS\u00b7Upload\u00b7SSRF\u00b7OAuth\u00b7GraphQL\u00b7Smuggling exploit chains \u00b7 CVE/Exploit KB (trickest+exploitarium) \u00b7 role-based testing \u00b7 vuln manager \u00b7 attack chain \u00b7 HITL \u00b7 LLM Orchestrator \u00b7 multi-model \u00b7 multi-language"},"popularity":{"monthly_downloads":232602,"position":9061,"tier":"top_15000"},"security":{"n_vulnerabilities":0},"version":"7.4.7"}
