Skip to content
Agents tracked: 258 Downloads (7d): 219M up 6.1% GitHub stars: 5.5M VS Code installs: 148M Releases (7d): 327 Agent status: 1 with issues Updated Oct 7, 2026

PentAGI changelog: what's new each month

Every stable PentAGI release summarised by month: the highlights, new features, improvements, fixes and anything you need to act on. 3 months covered; the current month updates daily.

October 2026 · so far

1 release: 2.2.0

October brought expanded model support across new providers and vendors, improved reasoning configuration for each API style, and enhanced security defaults. The release adds three new provider integrations and strengthens both authentication and container isolation.

Action needed
  • DOCKERINSIDE defaults to false; nested Docker access now requires DOCKERINSIDEHOST configuration pointing to a separate daemon.

Highlights

  • Three new providers—MiniMax, Mistral, and xAI—bring the total to 13 supported provider types.
  • Adaptive reasoning now sends thinking budgets and effort levels in each vendor's native format rather than a generic approach.
  • Provider failover automatically retries failed model calls on a second configured provider.
  • Workload Identity Federation lets you use Kubernetes or GitHub Actions tokens to get short-lived Claude credentials without long-lived API keys.
  • Docker container isolation now defaults to secure settings, requiring explicit opt-in to nested Docker access.

New

  • MiniMax, Mistral, and xAI provider integrations.
  • LLMFALLBACKPROVIDER for automatic provider failover on model call failures.
  • Workload Identity Federation support for exchanging OIDC tokens (Kubernetes, GitHub Actions, etc.) to temporary Anthropic credentials.
  • Example configurations and test reports for OpenRouter, DeepInfra, Ollama Cloud, self-hosted vLLM, and other endpoints.
  • Process limits and capability-dropping security policy for worker containers.

Improved

  • Reasoning parameters now adapt to each vendor's expected format instead of using a one-size-fits-all approach.
  • Model catalogue updated with current versions: GPT-6, Claude Opus 5.x and Fable 5.x, Gemini 3.x, Qwen 3.8, GLM 5.3, DeepSeek V4, and Grok 4.7, with prices synced to vendor pages.
  • Agent chains are now more compact in representation.
  • Custom provider endpoint support extended to include Azure OpenAI.
  • Provider failover records the switch in execution traces for visibility.

Fixed

  • DOCKERINSIDE security: host socket is no longer mounted automatically, and nested Docker now requires explicit DOCKERINSIDEHOST daemon configuration.
  • Worker container capabilities hardened: MKNOD withheld to prevent escape paths, SYSPTRACE added for debugger support.

May 2026

1 release: 2.1.0

May brought major file and knowledge management capabilities to PentAI, with a new persistent user resource library, flow-level file workspaces, and a complete knowledge store interface with semantic search and text anonymization.

Action needed
  • File upload limits enforced: 300 MB per file, 1000 files per request, 2 GB total; 255-byte name limit.

Highlights

  • User Resources library with MD5 deduplication and virtual filesystem for persistent, organized file storage.
  • Flow files that sync into worker containers and can be promoted back into the user library.
  • Knowledge store with semantic search, document ownership, and real-time subscriptions via GraphQL and REST.
  • File Manager UI with multi-select, drag-and-drop, bulk actions, and keyboard navigation across resources and flows.
  • Text anonymization service to scrub sensitive data directly in the knowledge editor.

New

  • User Resources — a per-user file library with MD5-deduplicated storage and virtual path filesystem.
  • Flow files that sync into worker containers at /work/uploads and /work/resources.
  • File Manager UI component with multi-select, keyboard navigation, drag-and-drop, sortable columns, and bulk actions.
  • Knowledge store with full GraphQL and REST CRUD, semantic search, and real-time subscriptions.
  • New /knowledges interface with list and detail pages, markdown editor, and inline rename/delete.
  • anonymizeText service (GraphQL/REST) to scrub sensitive data from text.
  • Semantic-search input in the knowledge editor with hotkey access.
  • Admin and user scoping for knowledge store documents with per-user ownership.

Improved

  • Vector search engine rewritten to use direct, parameterized SQL queries instead of string interpolation.
  • Files can be pulled back out of running containers and promoted into the user library.
  • Knowledge documents are re-embedded automatically on update.
  • File Manager supports partial updates and collapsible interface elements.
  • Resource and knowledge management both use the same reusable File Manager tree component.

Fixed

  • Document IDs were being dropped in vector search results.
  • Unsafe SQL string interpolation in the vector search engine.
  • Upload paths are now protected against directory traversal and symlink escapes.

April 2026

1 release: 2.0.0

April brought major upgrades to observability and agent control. PentAGI 2.0.0 introduced detailed cost tracking across all agent types and providers, plus new safeguards to prevent unproductive agent behavior.

Highlights

  • Token usage and cost breakdown now visible per flow and per agent type, with separate cache metrics for each provider.
  • Planning step feature lets agents create a 3–7 step execution plan before starting work, reducing task drift.
  • Execution monitoring automatically detects when agents repeatedly call the same tool or explore excessively.
  • New tool call limits prevent runaway behavior: 100 calls for primary and specialist agents, 20 for focused agents.

New

  • Per-agent-type cost and token usage tracking (primary, pentester, coder, installer, searcher, adviser).
  • Cache hit rates and separated cache read/write costs for Anthropic and Gemini.
  • Tool call frequency and execution time metrics per flow and subtask.
  • Multi-provider cost detail view for simultaneous configurations.
  • Planning step before specialist agents start work (AGENTPLANNINGSTEPENABLED).
  • Automatic unproductive behavior detection (EXECUTIONMONITORENABLED).
  • Consecutive identical tool call detection with configurable limit (EXECUTIONMONITORSAMETOOLLIMIT).
  • Configurable tool call limits by agent type (MAXGENERALAGENTTOOLCALLS, MAXLIMITEDAGENTTOOLCALLS).

Summaries are written automatically from the official release notes (full changelog ↗); check the original notes before relying on a detail. PentAGI: pricing, features and alternatives · All changelogs