# PentesterFlow/agent

Agentic offensive-security in your terminal

Repository: https://github.com/PentesterFlow/agent
Canonical: https://ross.abutalabs.com/products/pentesterflow-agent
Homepage: https://pentesterflow.com
Language: TypeScript
License: Apache-2.0
License Family: permissive
Topics: ai, ai-agents, bugbounty, penetration-testing, security-audit, security-automation
Last push: 2026-06-14T08:51:57+00:00

## Health v2 (maintenance only)
Score: 71/100 (v2, computed 2026-09-02T17:46:02.011165+00:00)
- activity 87, release rhythm 88, longevity 6
- inputs: {"age_days": 94, "days_push": 80, "days_rel": 80, "gap_med": 0.0, "n_releases_24m": 21}
- flags: young
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1308, forks 240 (observed 2026-08-28T04:04:19.121162+00:00)

## What it is
PentesterFlow is a terminal-based agentic AI CLI assistant for penetration testers and bug bounty hunters. It orchestrates LLM-driven recon, enumeration, validation, and reporting workflows while keeping the human analyst in control of sensitive actions.

## Use cases
- automate recon and enumeration on a pentest target
- test an API for broken access control and IDOR vulnerabilities
- collect evidence and generate findings reports during a security audit
- run an AI agent that assists with bug bounty hunting
- keep an audit log of commands run during authorized offensive-security work

## When to choose
- you are a pentester or bug hunter wanting an LLM assistant with human-in-the-loop approval
- you need reproducible, curl-first command execution with saved evidence for reporting
- you want an agent that remembers lessons across sessions via local knowledge bases

## When to avoid
- you lack explicit authorization to test the target systems
- you need fully autonomous scanning without human approval gates
- you need a GUI-based vulnerability scanner rather than a terminal workflow

## Facets
- artifact type: cli-tool
- maturity: active
- function: agent-framework, llm-inference, security, penetration-testing, cli, developer-tools
- domain: security, penetration-testing, artificial-intelligence, developer-tools
- platform: cli, cross-platform, windows
- tags: offensive-security, bug-bounty, human-in-the-loop, agentic-ai, security-automation, recon, vulnerability-assessment, ai-agents, command-line, nodejs, macos, linux

## Member repositories
- PentesterFlow/agent (main) score 71

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:04:19.121162+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T04:50:03.866432+00:00, confidence not recorded.
  - readme: https://github.com/PentesterFlow/agent (fetched 2026-08-28T04:04:19.121162+00:00, sha 8916918380a2)
- Data as of 2026-08-30T08:39:29.467469+00:00.
