Farai is a local AI agent built for CTFs, lab automation, security research, and long-running technical workflows. It runs from the terminal, keeps sessions resumable, executes tools locally or inside a Kali Docker runtime, and preserves tool output, artifacts, usage, and evidence so work can be reviewed instead of only trusted from a final answer.
For CSI/CyBench materials and exploratory benchmark artifacts, see farai-csi-bench.
Installation
npm install -g farai
Requirements:
- Bun 1.1+
- Docker
- A model provider/API key, unless using an already configured default provider
Setup
Configure Farai and prepare the local runtime:
farai setup
Usage
Open the interactive:
farai
Config and auth files live under:
~/.local/pajarori/farai/
Farai checks the separate farai-data content channel before opening the TUI. Each commit to that repository is built into an immutable, commit-pinned bundle; when a validated bundle publishes new knowledge or skills, Farai asks before downloading it. The current content can be inspected or managed without starting a session:
farai update status
farai update check
farai update apply
farai update rollback
Set FARAI_CONTENT_MANIFEST_URL for a private channel or local file:// manifest, and FARAI_CONTENT_DIR to isolate the local content store. Set FARAI_DISABLE_CONTENT_UPDATE=1 to disable the channel.
Status
Farai is under active development.
The current defensible claim is that Farai has substantial implementation validation and an evidence-oriented agent architecture. Stronger claims require clean benchmark campaigns, stronger isolation, canonical scoring, and larger empirical evaluations.
Early benchmark artifacts should be treated as exploratory unless the run artifact, oracle, isolation policy, model selection, and challenge materials are frozen and auditable.
License
Apache License 2.0