Favicon of h5i

h5i

Local AI red-teaming toolkit combines browser automation, HTTP testing and configurable sandboxes. Apache 2.0; sessions stay local, models use your provider.

Screenshot of h5i website

h5i is a local, open-source toolkit that gives your AI agent browser automation and direct HTTP control for testing web applications you own or are authorized to assess. It's for teams that want an agent to investigate security flaws, with recorded evidence they can review, even without a dedicated security specialist.

The agent can explore pages, capture the traffic behind an action, change a request and replay it, then compare responses. Browser activity and HTTP testing share a session, so findings retain their connection to what happened in the application. Confirmed attack flows can run again in CI to check that fixes hold.

Sandbox controls can cover the browser or the whole agent workflow, including its development tools and server. Network and filesystem restrictions depend on the isolation level and host support; container and microVM options are available. A dashboard shows sessions, requests and blocked actions. These limits can reduce the impact of prompt injection, but they don't guarantee safe behavior on an allowed target.

The native browser uses Rust without Chromium or V8. It suits content-heavy sites and common interactions; sites that need fuller browser compatibility can use Chromium in a sandbox, with traffic capture on Linux and macOS. Authenticated testing supports human login or named credentials without exposing password or cookie values to the model.

h5i uses the Apache 2.0 license and has no hosted service. It stores sessions locally. Web traffic reaches allowed sites, and model traffic goes to your configured provider.

Similar to h5i