$npx skillfedfor your agent

bingo-ai

AI-powered red team terminal — Zero-Hallucination · WAF bypass · XSS·Upload·SSRF·OAuth·GraphQL·Smuggling exploit chains · CVE/Exploit KB (trickest+exploitarium) · role-based testing · vuln manager · attack chain · HITL · LLM Orchestrator · multi-model · multi-language

With conditionsPyPI SecurityReleased Aug 2026232.6K downloads / moMITPure Python

Decision gist · record as of 2026-08-14

pure-Python wheel — bingo_ai-7.4.7-py3-none-any.whl
v7.4.7 · released 2026-08-06 · Python >=3.12 · 25 runtime deps: aiohttp, beautifulsoup4, certifi, chardet, charset-normalizer, colorama, cryptography, cssselect

Yes—if you are an authorized penetration tester on macOS or Linux. bingo offers low install friction, active maintenance, permissive MIT licensing, and zero known vulnerabilities. The 25 runtime dependencies are standard and the tool automates complex attack chains. Main gotchas: Python 3.12+ required, macOS/Linux-only, and LLM API keys needed on first launch. Not suitable for Windows users.AI-flagged interpretation of the facts on this page — verify before relying

Before you install

  • macOS or Linux only; Windows is not supported.
  • Requires Python 3.12 or later.
  • Low friction: pure Python wheel with no compiled dependencies.

License · maintenance · safety

MIT (permissive) — MIT license (permissive): you can use, modify, and distribute bingo freely in commercial and private projects with minimal restrictions.

last release 2026-08-06 (8 days)

0 known vulnerabilities (OSV.dev, 2026-08-14) · 232,602 downloads/mo, #9,061 on PyPI

Verify before relying

pip install bingo-ai
bingo
# At prompt: enter target URL and describe tasks in natural language
# Example: "Target: https://example.com\nTasks: 1. Full recon 2. SQLi detection"
  • Whether the 25 runtime dependencies are all actively maintained and free of vulnerabilities beyond OSV reports.
  • Whether the AI models (DeepSeek, Claude, GPT, GLM, Qwen, Ollama, custom) are called via external APIs or run locally, and what API key setup is required.
  • Whether the anti-hallucination claims and auto-strategy switching are empirically validated.
  • Whether findings auto-save to Desktop works reliably across different Linux distributions and macOS versions.
Same gist for agents: .md · .json

What it is and what it does

bingo is a terminal-based red team assistant that combines large language models with automated security testing to discover and exploit vulnerabilities in web applications, mobile apps (Android APK, iOS IPA), Windows executables, and blockchain/DApp targets. You describe a target and testing goals in plain English, and bingo orchestrates the attack chain—from reconnaissance (WAF detection, tech fingerprinting) through exploitation (SQLi, XSS, SSRF, file upload, auth bypass) to post-exploitation (credential dumping, database extraction, webshell deployment). It includes built-in engines for SQL injection across all database types, WAF bypass for Cloudflare/AWS/ModSecurity, and optional integration with nmap and sqlmap if installed. The tool supports 25 runtime dependencies including playwright for browser automation, cryptography for JWT/OAuth testing, and various HTTP clients for proxy rotation and Tor integration.

The package is actively maintained (latest release 8 days ago), requires Python 3.12 or later, and runs only on macOS and Linux—Windows support was permanently discontinued. It carries no known security vulnerabilities as of the query date. The tool is designed for authorized penetration testers and red teamers who want to automate reconnaissance and exploitation workflows through conversational prompts.

Use it for

  • Automated web application penetration testing: describe a target URL and let bingo handle recon, SQLi detection, WAF bypass, and credential extraction.
  • Mobile app security analysis: extract hardcoded secrets, permissions, exported components, and SSL pinning details from Android APK or iOS IPA.
  • Smart contract and DApp auditing: test for reentrancy, flash loan vulnerabilities, oracle manipulation, and wallet authentication bypass.
  • Post-exploitation automation: chain SQLi discovery into webshell deployment, RCE execution, and full database dumps with a single prompt.
  • Headless CI/CD security scanning: run in silent mode with JSON output for automated vulnerability reporting in deployment pipelines.
  • Windows malware analysis: static PE analysis including imports, strings, entropy, hardcoded secrets, and C2 indicator extraction.

Worth the install?

AI-flagged interpretation of the facts on this page. Verify before relying on it.

With conditions

Yes—if you are an authorized penetration tester on macOS or Linux.

bingo offers low install friction, active maintenance, permissive MIT licensing, and zero known vulnerabilities. The 25 runtime dependencies are standard and the tool automates complex attack chains. Main gotchas: Python 3.12+ required, macOS/Linux-only, and LLM API keys needed on first launch. Not suitable for Windows users.

Install

bingo-ai on PyPI

Before you install

Low friction: pure Python wheel with no compiled dependencies. Active maintenance (released 8 days ago). Requires Python 3.12+. Supports macOS and Linux only—Windows is not supported.

macOS or Linux only; Windows is not supported. Requires Python 3.12 or later.

License in practice

MIT license (permissive): you can use, modify, and distribute bingo freely in commercial and private projects with minimal restrictions.

Quickstart

pip install bingo-ai
bingo
# At prompt: enter target URL and describe tasks in natural language
# Example: "Target: https://example.com\nTasks: 1. Full recon 2. SQLi detection"

Verify before relying

  • Whether the 25 runtime dependencies are all actively maintained and free of vulnerabilities beyond OSV reports.
  • Whether the AI models (DeepSeek, Claude, GPT, GLM, Qwen, Ollama, custom) are called via external APIs or run locally, and what API key setup is required.
  • Whether the anti-hallucination claims and auto-strategy switching are empirically validated.
  • Whether findings auto-save to Desktop works reliably across different Linux distributions and macOS versions.

Package facts

LicenseMIT permissive
Python supportSupports the current Python release >=3.12
Install frictionLow. Pure-Python wheel
Runtime dependencies
25 packages
aiohttpbeautifulsoup4certifichardetcharset-normalizercoloramacryptographycssselectdnspythonfake-useragenthtml5libhttpxlxmlplaywrightprompt-toolkitpydanticpyjwtpysockspython-dotenvrequestsrichstemtldextracturllib3uvloop
MaintenanceActively maintained 8 days since the last release
First released
Downloads232,602 / month, #9,061 on PyPI 30-day window, as of 2026-08-14
Known vulnerabilitiesNone known OSV.dev, checked 2026-08-14
Classifiers
Development Status :: 5 - Production/StableEnvironment :: ConsoleIntended Audience :: Information TechnologyLicense :: OSI Approved :: MIT LicenseOperating System :: MacOSOperating System :: POSIX :: LinuxProgramming Language :: Python :: 3Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Programming Language :: Python :: 3.14Topic :: SecurityTopic :: Terminals

Evidence: bingo_ai-7.4.7-py3-none-any.whl

Tags

Capabilities
ai penetration testing toolautomated red team terminalweb application security scannerai-powered vulnerability discoveryllm-driven exploit automationsecurity testing cliwaf bypass and sql injection
Topics
penetration-testingai-automationred-team
PyPI keywords
aiclicveexploithackerknowledge-basellmpentestred-teamsecurityterminalwaf

Let your AI agent find packages like this

Example. Real query, live index.

You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.

wish › “ai penetration testing tool”

  • bingo-aibingo is an AI-powered red team terminal that automates security…
  • deepteamDeepTeam is an open-source red teaming framework that simulates…
  • flask-unsignCommand-line tool to decode, brute-force, and forge Flask session…

Give your agent the search over MCP, or paste the wish link into any chat.

More Security packages

SecretStorage With conditions
PyPI · Python Modules · released Nov 2025

Provides Python bindings to the FreeDesktop.org Secret Service API for securely storing and retrieving passwords and secrets through GNOME Keyring, KWallet, or KeePassXC.

BSD-3-Clausepure Python · 3.10+aging
226.9Mdownloads / mo
msal Worth it
PyPI · Security · released May 2026

MSAL for Python handles OAuth2 and OpenID Connect authentication with Microsoft identity services, managing token acquisition, caching, and refresh for applications integrating with Microsoft Entra ID, Microsoft Accounts, and Azure AD B2C.

MITpure Python · 3.9+
223.0Mdownloads / mo
joserfc Worth it
PyPI · Security · released Jul 2026

joserfc implements JOSE standards (JWS, JWE, JWK, JWT, and related RFCs) for signing, encrypting, and managing JSON-based cryptographic tokens in Python.

BSD-3-Clausepure Python · 3.10+
155.5Mdownloads / mo
Authlib Worth it
PyPI · Security · released May 2026

Authlib provides a complete implementation of OAuth 1.0, OAuth 2.0, and OpenID Connect 1.0 for building both authentication clients and servers, with built-in support for JWS, JWK, JWA, and JWT standards.

BSD-3-Clausepure Python · 3.10+
155.1Mdownloads / mo
argon2-cffi-bindings With conditions
PyPI · Python Modules · released Jul 2025

Provides low-level CFFI bindings to the official Argon2 password hashing algorithm for use by libraries and applications that need direct access to Argon2 without higher-level abstractions.

MITcompiled wheel · 3.9+
74.2Mdownloads / mo
adal Skip
PyPI · Security · released Apr 2021

ADAL for Python authenticates applications with Azure Active Directory to obtain tokens for accessing Azure AD-protected resources.

Install only if maintaining existing code that already depends on it, and plan a migration.

MITpure Pythonabandoned
44.5Mdownloads / mo

See also deepteam · dreadnode · cisco-ai-skill-scanner · open-webui · nxplora · allianceauth-securegroups · frida-tools · aa-memberaudit · openhands · robocorp-browser

Further reading