Pentest AI
Open-source AI pentester that proves every finding. Machine oracles re-run each exploit; verified bugs ship a proof capsule you can replay yourself. observed · 2026-08-28
Health v2 · maintenance only
80/100
- Activity 98
- Release rhythm 98
- Longevity 10
Flags: young
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.
- gap_med: 1.0
- age_days: 151
- days_rel: 17
- days_push: 13
- n_releases_24m: 23
Adoption not part of the score
1629 stars · 314 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded
pentest-ai is an MIT-licensed local CLI and MCP server that turns Claude Code (or any LLM) into an offensive security assistant, pairing 50 specialized subagents with a verification engine that re-runs exploits to prove findings. It runs entirely on your machine with local SQLite storage, no telemetry, and can also be installed as a Claude Code plugin.
Use cases
- run authorized penetration tests with AI assistance
- verify and reproduce security findings automatically
- plan and manage pentest engagements from the terminal
- integrate pentesting tools into Claude Code via MCP
- research exploits and build detection rules
- generate penetration test reports
- practice for OSCP or bug bounty hunting
When to choose
- you want AI-assisted pentesting that runs locally with no cloud dependency or telemetry
- you need machine-verified findings rather than unverified scanner flags
- you already use Claude Code, Cursor, or another MCP-compatible client
- you want specialized subagents covering recon, web, AD, cloud, mobile, and post-exploitation
When to avoid
- you need a fully autonomous scanner with no LLM subscription or API key
- you lack explicit authorization to test your targets - this is for authorized engagements only
- you need a commercial compliance-grade scanning platform with vendor support
- you want a GUI-only workflow without terminal or MCP interaction
Facets
cli-tool · maturity active
penetration-testing security agent-framework mcp cli vulnerability-scanning osint reverse-engineering security penetration-testing developer-tools cli python self-hosted claude-code subagents red-team bug-bounty ctf mitre-attack exploit-verification mcp-server offensive-security report-generation command-line ai-agents linux macos docker
3 sources
- readme: https://github.com/0xSteph/pentest-ai · fetched 2026-08-28 · c35fcd30d21d
- homepage: https://pentestai.xyz · fetched 2026-08-29 · 14915fa9030b
- site_page: https://pentestai.xyz/docs/getting-started · fetched 2026-08-29 · 4ecc21915914
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| 0xSteph/pentest-ai | main | 80 |
| 0xSteph/pentest-ai-agents | plugin | 72 |
For agents
markdown · JSON · MCP: product_card(name="0xSteph/pentest-ai")
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem