promptzero

module
v0.191.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: May 16, 2026 License: AGPL-3.0

README

Latest release AGPL-3.0 CI

Describe it. Generate it. Deploy it. Run it.

PromptZero is a natural-language operator for the Flipper Zero. Talk to it like you'd talk to a person — it generates payloads, deploys them, and runs them, all from a single sentence.

[!CAUTION] Authorised use only. PromptZero generates and runs RF, NFC, RFID, and HID payloads — illegal outside contexts you own or have written authorisation to test. Read SECURITY.md for the safety model and threat boundary. The project is under active development; APIs and tools change between minor versions.

Built end-to-end with Claude. Review generated payloads before deployment.

promptzero> make me a Starbucks WiFi captive portal
  Generated and deployed evil_portal to /ext/apps_data/evil_portal/index.html
  Evil portal started on Marauder devboard

promptzero> scan for nearby WiFi networks and deauth the strongest one
  Found 12 access points. Strongest: "NETGEAR-5G" (-31 dBm, channel 6)
  Selected AP 0. Deauth attack running...

promptzero> create a BadUSB payload that opens a reverse shell on Windows
  Generated and deployed badusb to /ext/badusb/generated_payload.txt
  Ready to execute - plug into target and run

promptzero> identify this device: /tmp/remote.jpg
  That's a Samsung BN59 series TV remote using the Samsung32 IR protocol.
  I can generate a complete remote file. Want me to create it?

Quick start

Prerequisites — Flipper Zero with modded firmware (Momentum / Unleashed / RogueMaster), an Anthropic API key, and a USB cable.

# 1. Install (Linux/macOS, amd64/arm64) — pinned to release artifacts (immutable per tag)
curl -fsSL https://github.com/xunholy/promptzero/releases/latest/download/install.sh | sh

# 2. Configure
export ANTHROPIC_API_KEY="sk-ant-..."

# 3. Run
promptzero
promptzero> what's connected?
  Flipper Zero — firmware 0.99.1, hardware v7.4
  Battery 84 % | SD card 4.1 GB free / 7.4 GB total

That's the whole onboarding. From here, type natural-language instructions or /help to see slash commands.

Defensive posture (one-flag safety rail): add --read-only to refuse any tool that writes, transmits, or executes. Pure reads / scans / queries still dispatch; anything risk-Medium or above is refused at the boundary. See Read-only safety rail for the full rule.

promptzero --read-only          # blue-team / forensics / training

Other paths: Windows users grab the .zip from the releases page. WSL2 needs USB passthrough — see Transports → WSL2. For wireless BLE, config files, personas, environment variables, and self-upgrade: Configuration reference.


What it does

PromptZero connects to your Flipper Zero (and optional ESP32 Marauder WiFi devboard) over USB serial or BLE, then lets you control everything through natural language.

Subsystem Capabilities
Flipper Zero Sub-GHz TX/RX, IR TX/RX, NFC detect/emulate, RFID read/write/emulate, iButton, GPIO, BadUSB, storage, app launcher
ESP32 Marauder WiFi scan, deauth, beacon spam, probe flood, PMKID capture, evil portal, BLE spam, BT scanning, skimmer detection, wardriving, MAC spoofing
AI Generation Evil portal HTML, BadUSB DuckyScript, Sub-GHz .sub, IR .ir, NFC .nfc from natural language — plus parametric builders for typed parameters
Intelligence Image analysis via Claude vision (file path → device ID + attack vector), SD card discovery
Audit SQLite audit log with MITRE ATT&CK technique tags, session export, statistics

Run promptzero and type /tools for the live registry. Tool count grows release-over-release.

The agent layer ships prompt caching, cost-tier model routing (recon on Haiku / exploit on Opus), prompt-injection quarantine, reflexion-on-error with structured ToolError, a <device-state> oracle injected each turn, and OpenTelemetry GenAI spans. See docs/ for architecture details.


Modes

CLI — promptzero

Default. Interactive REPL.

promptzero> scan the SD card and show me what signals I have saved
promptzero> transmit the garage door signal
promptzero> read the NFC tag on my desk

Slash commands (run /help for the full list with descriptions):

  • Conversation: /help, /reset, /quit
  • Session: /sessions, /save <name>, /resume <id>, /forget <id>
  • Info: /status, /tools [filter|page <n>], /history [N], /audit {stats|find|tail|top|session|query|export}, /stats [section], /cost, /budget [set <USD>|off], /debug
  • Operator: /persona [name], /mode [name], /watch [pause|resume], /webhooks [test <name>], /validate <path>, /attack {set|clear} <techniques>, /campaign {validate|run} <file>, /rewind [snapshot], /report [session] [json] [save], /rules [list|pause|resume|test]
  • Device: /reconnect

Keystrokes during a turn:

  • Ctrl+C — cancel the current turn entirely.
  • Ctrl+G — abort the current streaming tool (e.g. subghz_receive, wifi_scan_ap) but let the agent continue with the partial result. Use this when you've seen what you needed and don't want to wait out the full duration.
  • Ctrl+R — reverse-incremental history search.
  • Ctrl+L — clear screen.

Web UI — promptzero --web

Dark-themed browser interface at http://localhost:8080. Includes the chat surface, a live Flipper viewport, file browser, audit log, report builder, and (when a Marauder is connected) a TFT display panel.

[!IMPORTANT] Auth. Set web.token in your config or PROMPTZERO_WEB_TOKEN in env. The browser picks up #token=… from the URL fragment on first load and caches it in sessionStorage. Empty token + non-loopback bind → server prints a red warning. PromptZero speaks plain HTTP — terminate TLS at a reverse proxy (Caddy / Traefik / nginx) or a Tailscale / Cloudflare tunnel.

Voice — promptzero --voice

Push-to-talk in CLI mode. Press Enter with no text to record (requires sox); audio is transcribed via OpenAI Whisper, then processed as a normal command.

Ubuntu/Debian:  apt install sox
macOS (brew):   brew install sox
Arch:           pacman -S sox

MCP — promptzero --mcp

Runs as a Model Context Protocol server over stdio. Add to Claude Desktop / Claude Code:

{
  "mcpServers": {
    "promptzero": {
      "command": "/path/to/promptzero",
      "args": ["--mcp"]
    }
  }
}

[!IMPORTANT] MCP risk gate. Risk-High and Risk-Critical tools are refused by default — set PROMPTZERO_MCP_ALLOW_HIGH=1 and / or PROMPTZERO_MCP_ALLOW_CRITICAL=1 to allow them. All MCP calls (allowed or denied) are recorded in the audit log. See Safety model below.


Safety model

PromptZero is dual-use offensive tooling. The safety story is the project's social licence to exist.

  • Risk classification per tool. Every spec carries a tier — Low / Medium / High / Critical. Read-only ops are Low; destructive RF transmit, RFID write, BadUSB run, factory-reset are Critical.
  • Consent gate. High and Critical tools require operator confirmation. The CLI shows a boxed preview (frequency / modulation / hex) with a 2-second delay; positive consent (y, all, confirm) is rejected before the delay opens. Negative decisions (n, r for revise, Esc) bypass the delay.
  • MCP refuses by default. No MCP client can run High+ tools without explicit env-var opt-in (see above).
  • Audit-log fail-closed. If no audit log is initialised, the agent refuses High+ actions rather than running them silently.
  • Prompt-injection quarantine. Tool outputs (scanned SSIDs, captured packets, image content, SD filenames) are wrapped before being fed back into the model so they can't override the system prompt.
  • No auto-deploy of generated payloads. BadUSB scripts deploy without execution by default.

Read SECURITY.md for the full threat model, scope / out-of-scope, and how to report a vulnerability.


Compatibility

Firmware Status
Momentum (formerly Xtreme) Primary target
Unleashed Supported
RogueMaster Supported
Official (OFW) 1.x Supported with reduced feature set — region-locked Sub-GHz, no rolling code

[!NOTE] Official firmware locks Sub-GHz TX to region-specific ISM bands and blocks rolling-code protocols. Modded firmware unlocks the full CC1101 range (300–348 / 387–464 / 779–928 MHz) and enables TX for all 52 supported protocols.

ESP32 Marauder devboard requires firmware v1.11.1+ over USB CDC ACM (/dev/ttyACM1 for the official Flipper WiFi devboard, baud 115200).

For BLE wireless (no cable, all tools work, ~10× slower than USB) and per-platform pairing: see Transports reference.


Documentation


Build & contribute

See CONTRIBUTING.md. Short version:

git clone https://github.com/xunholy/promptzero.git
cd promptzero
task dev:setup
task build
task test

License

AGPL-3.0-or-later. Hosting a modified PromptZero as a network service requires publishing source changes under the same license.


Built with Claude by xunholy.

Directories

Path Synopsis
cmd
cliprobe command
cliprobe: minimal pty driver that sends ONE prompt and dumps every byte the CLI emits for 60s.
cliprobe: minimal pty driver that sends ONE prompt and dumps every byte the CLI emits for 60s.
clitest command
clitest spawns `promptzero` in REPL mode under a pty (because the REPL refuses to enter raw mode without a TTY) and drives a few non-LLM slash commands to verify the CLI plumbing works end-to-end: banner prints, /help renders, /quit exits cleanly.
clitest spawns `promptzero` in REPL mode under a pty (because the REPL refuses to enter raw mode without a TTY) and drives a few non-LLM slash commands to verify the CLI plumbing works end-to-end: banner prints, /help renders, /quit exits cleanly.
cliyolo command
cliyolo drives the promptzero REPL through a pty with a curated set of natural-language prompts to exercise every non-destructive Flipper subsystem.
cliyolo drives the promptzero REPL through a pty with a curated set of natural-language prompts to exercise every non-destructive Flipper subsystem.
coverage-diff command
cmd/coverage-diff scrapes the awesome-flipperzero upstream lists for tool/verb names and cross-references them against PromptZero's registered tool registry (internal/tools).
cmd/coverage-diff scrapes the awesome-flipperzero upstream lists for tool/verb names and cross-references them against PromptZero's registered tool registry (internal/tools).
flipper-usecases command
Command flipper-usecases runs realistic operator tasks against a live Flipper Zero and reports pass/fail + concise summaries.
Command flipper-usecases runs realistic operator tasks against a live Flipper Zero and reports pass/fail + concise summaries.
flipper-validate command
flipper-validate is an integration harness that exercises Flipper wrapper methods against a live device over serial.
flipper-validate is an integration harness that exercises Flipper wrapper methods against a live device over serial.
hwtest command
hwtest is a developer-only smoke harness that drives a real Flipper Zero (and optional Marauder) over MCP.
hwtest is a developer-only smoke harness that drives a real Flipper Zero (and optional Marauder) over MCP.
marauder-validate command
marauder-validate is an integration harness that exercises the safe read/RX/inspection subset of Marauder wrapper methods against a live ESP32 Marauder devboard over USB serial.
marauder-validate is an integration harness that exercises the safe read/RX/inspection subset of Marauder wrapper methods against a live ESP32 Marauder devboard over USB serial.
mifaretest command
mifaretest exercises the realistic Mifare workflow against a tag held to the real Flipper: detect → inspect existing fixtures → dump protocol → save a UID-only file → diff vs an existing file → edit → emulate → cleanup.
mifaretest exercises the realistic Mifare workflow against a tag held to the real Flipper: detect → inspect existing fixtures → dump protocol → save a UID-only file → diff vs an existing file → edit → emulate → cleanup.
promptzero command
pzrunner command
pzrunner is a non-interactive harness that drives the promptzero Agent end-to-end over a real Flipper.
pzrunner is a non-interactive harness that drives the promptzero Agent end-to-end over a real Flipper.
webtest command
webtest spawns `promptzero --web` against a real Flipper, then drives every HTTP API endpoint and the websocket handshake to confirm the public web surface is wired correctly.
webtest spawns `promptzero --web` against a real Flipper, then drives every HTTP API endpoint and the websocket handshake to confirm the public web surface is wired correctly.
internal
attack
Package attack maps PromptZero tools and workflows to MITRE ATT&CK techniques.
Package attack maps PromptZero tools and workflows to MITRE ATT&CK techniques.
breaker
Package breaker implements a per-tool consecutive-error circuit breaker (roadmap P3-28, second half).
Package breaker implements a per-tool consecutive-error circuit breaker (roadmap P3-28, second half).
bruce
Package bruce interfaces with the Bruce pentesting firmware for ESP32-based boards over a USB-serial connection.
Package bruce interfaces with the Bruce pentesting firmware for ESP32-based boards over a USB-serial connection.
buspirate
Package buspirate is the PromptZero backend for the Bus Pirate 5 universal bus probe (RP2040-based).
Package buspirate is the PromptZero backend for the Bus Pirate 5 universal bus probe (RP2040-based).
campaign
Package campaign implements the PromptZero Campaigns feature (roadmap P2-19) — declarative, YAML-authored multi-step engagement specs that compose the existing agent tool surface.
Package campaign implements the PromptZero Campaigns feature (roadmap P2-19) — declarative, YAML-authored multi-step engagement specs that compose the existing agent tool surface.
clisafe
Package clisafe contains helpers shared by every transport that pushes operator-supplied strings through a line-oriented CLI.
Package clisafe contains helpers shared by every transport that pushes operator-supplied strings through a line-oriented CLI.
confidence
Package confidence provides pre-dispatch heuristic scoring for tool-use inputs.
Package confidence provides pre-dispatch heuristic scoring for tool-use inputs.
consensus
Package consensus implements ensemble voting over multi-model risk verdicts (roadmap P3-33).
Package consensus implements ensemble voting over multi-model risk verdicts (roadmap P3-33).
containerbridge
Package containerbridge runs external CLI tools inside Docker containers and surfaces their output as Go values.
Package containerbridge runs external CLI tools inside Docker containers and surfaces their output as Go values.
cost
Package cost tracks Anthropic token usage and running dollar cost per PromptZero session, and implements the simple "consecutive errors → offline" heuristic that flips the observability offline banner.
Package cost tracks Anthropic token usage and running dollar cost per PromptZero session, and implements the simple "consecutive errors → offline" heuristic that flips the observability offline banner.
crypto1
Package crypto1 is the pure-Go implementation of the Crypto1 stream cipher used by MIFARE Classic and some HID iCLASS legacy systems.
Package crypto1 is the pure-Go implementation of the Crypto1 stream cipher used by MIFARE Classic and some HID iCLASS legacy systems.
defense
Package defense provides passive RF / BLE detection helpers used to surface adversarial activity nearby — the blue-team complement to PromptZero's offensive capability set.
Package defense provides passive RF / BLE detection helpers used to surface adversarial activity nearby — the blue-team complement to PromptZero's offensive capability set.
diff
Package diff renders a `git diff --no-prefix`-style unified-diff string from two text inputs.
Package diff renders a `git diff --no-prefix`-style unified-diff string from two text inputs.
eval
Package eval provides the PromptZero golden evaluation harness (roadmap P2-25).
Package eval provides the PromptZero golden evaluation harness (roadmap P2-25).
faultier
Package faultier drives a hextreeio Faultier USB voltage-glitcher via its serial bridge interface.
Package faultier drives a hextreeio Faultier USB voltage-glitcher via its serial bridge interface.
fileformat
Package fileformat gives the PromptZero agent structural access to the Flipper file formats it already ships with — .sub, .nfc, .ir, .rfid.
Package fileformat gives the PromptZero agent structural access to the Flipper file formats it already ships with — .sub, .nfc, .ir, .rfid.
flipper/mock
Package mock provides a pty-backed fake Flipper CLI so serial.go and the command wrappers can be exercised without real hardware.
Package mock provides a pty-backed fake Flipper CLI so serial.go and the command wrappers can be exercised without real hardware.
flipper/rpc
Package rpc implements a typed Flipper Zero RPC client over a transport.Transport.
Package rpc implements a typed Flipper Zero RPC client over a transport.Transport.
flipper/transport
Package transport defines the byte-channel substrate the Flipper CLI layer operates over.
Package transport defines the byte-channel substrate the Flipper CLI layer operates over.
iclass
Package iclass implements the iCLASS block cipher and the loclass key-recovery attack against HID iCLASS Elite / High Security readers.
Package iclass implements the iCLASS block cipher and the loclass key-recovery attack against HID iCLASS Elite / High Security readers.
keeloq
Package keeloq implements the KeeLoq block cipher and supporting primitives for sub-GHz rolling-code analysis.
Package keeloq implements the KeeLoq block cipher and supporting primitives for sub-GHz rolling-code analysis.
marauder/parsers
Package parsers turns Marauder CLI output lines into typed events the web layer can ship as JSON.
Package parsers turns Marauder CLI output lines into typed events the web layer can ship as JSON.
mcp
Package mcp exposes PromptZero's tool surface over the Model Context Protocol (stdio transport).
Package mcp exposes PromptZero's tool surface over the Model Context Protocol (stdio transport).
mcpfed
Package mcpfed federates external Model Context Protocol (MCP) servers as native PromptZero tools.
Package mcpfed federates external Model Context Protocol (MCP) servers as native PromptZero tools.
mode
Package mode defines named operation profiles that constrain which tools the agent will dispatch.
Package mode defines named operation profiles that constrain which tools the agent will dispatch.
obs
Package obs ("observability") is the cross-cutting layer that wires structured logging, Prometheus metrics, and the /debug snapshot view into the rest of PromptZero.
Package obs ("observability") is the cross-cutting layer that wires structured logging, Prometheus metrics, and the /debug snapshot view into the rest of PromptZero.
pcap
Package pcap implements a pure-Go libpcap classic-format writer and reader.
Package pcap implements a pure-Go libpcap classic-format writer and reader.
persona
Package persona implements operator-mode profiles for PromptZero.
Package persona implements operator-mode profiles for PromptZero.
rag
Package rag provides lexical retrieval over the bundled PromptZero documentation corpus.
Package rag provides lexical retrieval over the bundled PromptZero documentation corpus.
report
Package report renders engagement reports from PromptZero session audit data.
Package report renders engagement reports from PromptZero session audit data.
rules
Package rules is PromptZero's reactive rules engine.
Package rules is PromptZero's reactive rules engine.
semcache
Package semcache implements a small, durable, on-disk semantic cache for LLM-generated payloads (roadmap P2-27).
Package semcache implements a small, durable, on-disk semantic cache for LLM-generated payloads (roadmap P2-27).
snapshot
Package snapshot captures pre-write copies of Flipper SD files so /rewind can restore them on demand.
Package snapshot captures pre-write copies of Flipper SD files so /rewind can restore them on demand.
streaming
Package streaming provides the partial-frame sink used by tools that opt into streaming dispatch (roadmap P3-28 first half).
Package streaming provides the partial-frame sink used by tools that opt into streaming dispatch (roadmap P3-28 first half).
subghz
Package subghz provides pure-Go classifiers for common Sub-GHz radio protocols captured by the Flipper Zero.
Package subghz provides pure-Go classifiers for common Sub-GHz radio protocols captured by the Flipper Zero.
subghz/protocols
Package protocols implements pure-Go decoders for the top-20 Sub-GHz remote control protocols captured by the Flipper Zero.
Package protocols implements pure-Go decoders for the top-20 Sub-GHz remote control protocols captured by the Flipper Zero.
targetmem
Package targetmem stores per-target facts across PromptZero sessions.
Package targetmem stores per-target facts across PromptZero sessions.
testmocks
Package testmocks centralises the shared mock harness used across PromptZero's test surfaces — flipper-agent tests, end-to-end REPL tests, workflow tests.
Package testmocks centralises the shared mock harness used across PromptZero's test surfaces — flipper-agent tests, end-to-end REPL tests, workflow tests.
toolctx
Package toolctx serves static per-tool cheat sheets the agent appends to tool descriptions at catalog registration time.
Package toolctx serves static per-tool cheat sheets the agent appends to tool descriptions at catalog registration time.
tools
Package tools — argument-extraction helpers.
Package tools — argument-extraction helpers.
trainset
Package trainset exports the audit log as a fine-tuning dataset.
Package trainset exports the audit log as a fine-tuning dataset.
validator
Package validator scans BadUSB/DuckyScript payloads for patterns that the operator would want to see before the Flipper types them on a real target.
Package validator scans BadUSB/DuckyScript payloads for patterns that the operator would want to see before the Flipper types them on a real target.
version
Package version carries build-time metadata embedded via -ldflags.
Package version carries build-time metadata embedded via -ldflags.
watch
Package watch implements the --watch filesystem-trigger mode.
Package watch implements the --watch filesystem-trigger mode.
web
Marauder synth-panel WebSocket layer.
Marauder synth-panel WebSocket layer.
webhook
Package webhook dispatches PromptZero lifecycle events as outbound HTTP POSTs.
Package webhook dispatches PromptZero lifecycle events as outbound HTTP POSTs.
wordlists
Package wordlists embeds PromptZero's built-in wordlists and exposes them as MCP resources via promptzero://wordlists/<name> URIs.
Package wordlists embeds PromptZero's built-in wordlists and exposes them as MCP resources via promptzero://wordlists/<name> URIs.
workflows
Package workflows implements composite pentest flows that orchestrate several Flipper primitives + LLM reasoning behind a single LLM-callable tool.
Package workflows implements composite pentest flows that orchestrate several Flipper primitives + LLM reasoning behind a single LLM-callable tool.
test
adversarial
Package adversarial holds the cross-package adversarial test suite (roadmap P3-30).
Package adversarial holds the cross-package adversarial test suite (roadmap P3-30).

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL