</>MCP Agents Market
Agent

pentest-agents

by H-mmer907PythonUpdated 2026-06-12

Bug bounty agent framework for Claude Code, Codex, Gemini, Cursor, Windsurf, Copilot, and OpenClaw — 48 agents, 26 commands, 19 CLI tools, 2 MCP servers, autonomous hunt loops, exploit chain builder.

Claude CodeCodexGeminiCursorWindsurfVS Code CopilotOpenClaw

Pentest Agents is a comprehensive bug bounty framework delivering 48 autonomous AI sub-agents, 26 slash commands, and 2 MCP servers for offensive security testing across Claude Code, Codex, Gemini, Cursor, Windsurf, Copilot, and OpenClaw. The suite includes vulnerability-class specialists (XSS, SQLi, SSRF, IDOR, OAuth, LLM injection), hunting methodology agents, validation workflows, and exploit chain builders that query writeup databases and apply concrete payloads. Each sub-agent inherits from a 2,600-line payload library and tested hunting patterns, while the 7-Question Gate validator and circuit-breaker logic prevent shallow testing and platform bans.

Key Features

48 specialized sub-agents covering H1 weakness categories, SAST pipelines, recon, validation, and exploit chain construction
Two MCP servers: bounty-platforms (16 platform integrations including HackerOne API) and writeup-search (BYO FAISS/SQLite index with graceful fallback)
Cross-IDE installer rendering native formats for 7 AI coding tools from a single Claude Code source tree
7-Question Gate validation protocol with PASS/KILL/DOWNGRADE/CHAIN gating for /report and /submit commands
Autonomous hunt loops with paranoid/normal/yolo checkpoints, endpoint tracking brain, and anti-shallow depth engine
PreToolUse scope hook blocking out-of-scope Bash commands; SubagentStop cost-tracking hook auto-logging session spend
Five deep methodology skills (hunt-rce, hunt-idor, hunt-xss, hunt-oauth, hunt-llm-ai) distilled from 1,000+ reports each
Built-in RAG builder (rag-builder/) turning GitHub/GitLab repos into searchable FAISS indexes for the writeup-search MCP

Use Cases

  • 01Bug bounty hunters running autonomous vulnerability discovery loops against HackerOne, Bugcrowd, or Intigriti programs
  • 02Security researchers building multi-step exploit chains (A→B→C) from capability tables and prior writeups
  • 03Penetration testers performing SAST analysis with entry-point mapping, taint flow tracing, and gap-to-exploit pipelines
  • 04Red teams validating findings with the 7-Question Gate before submitting reports, preventing low-quality duplicates
  • 05Security engineers indexing internal CTF archives or public writeup repos into a queryable knowledge base for agent use
  • 06Offensive security practitioners needing stealth browser automation (Camoufox) and WAF bypass iteration protocols

Related Agents

View more

pentest-agents — FAQ

What is Pentest Agents?+

Pentest Agents is a bug bounty automation framework providing 48 AI sub-agents, 26 slash commands, 19 CLI tools, and 2 MCP servers for offensive security testing. It works natively with Claude Code, Codex, Gemini, Cursor, Windsurf, VS Code Copilot, and OpenClaw.

How do I install Pentest Agents for Claude Code?+

Clone the repo, run 'python3 -m tools.installer install --targets claude_code --scope project' in your bounty workspace, then configure the two MCP servers in .mcp.json or ~/.claude.json. Alternatively, use 'tools/scaffold.py' to provision a ready-to-use workspace with all agents and MCP servers pre-configured.

Which AI coding tools does Pentest Agents support?+

It supports Claude Code, OpenAI Codex, Google Gemini, Cursor, Windsurf, VS Code Copilot, and OpenClaw. The installer translates the native Claude Code agent definitions into each tool's format (TOML for Codex, skills for Cursor/Windsurf, .agent.md for Copilot).

Do I need API keys for the MCP servers?+

The bounty-platforms MCP requires platform credentials (e.g. HACKERONE_USERNAME and HACKERONE_TOKEN for HackerOne API access). The writeup-search MCP works out-of-the-box with local payloads; semantic/keyword search activates when you provide your own metadata.db and optional index.faiss.

Is Pentest Agents free to use?+

Yes, the framework is open-source. Usage incurs costs only from the underlying AI model API (Claude, GPT, Gemini tokens) and optional paid bug bounty platform accounts.

What prerequisites are required?+

Python 3.10+, uv package manager, and security tools (nmap, httpx, subfinder, nuclei, ffuf, katana, sqlmap). Optional: faiss-cpu and sentence-transformers for semantic writeup search, cargo for graphql-path-enum, grim/scrot/ffmpeg for evidence capture.

How do I install pentest-agents?+

Open the source repository on GitHub and follow its README. pentest-agents is a agent — MCP Agents Market links you directly to the official repo.

Is pentest-agents free?+

pentest-agents is an open-source project hosted on GitHub. Check the repository for its license and any usage requirements.

Related searches