</>MCP Agents Market
Agent

pentest-ai

by 0xSteph1.6kPythonUpdated 2026-08-20

Open-source AI pentester that proves every finding. Machine oracles re-run each exploit; verified bugs ship a proof capsule you can replay yourself.

Claude CodeCursorCodex

Pentest-ai is an open-source AI penetration testing agent that verifies security vulnerabilities through machine oracles rather than relying solely on LLM predictions. Each verified finding is proven by re-running exploits multiple times and ships with a portable proof capsule that can be independently replayed. The agent integrates with Claude Code, Cursor, and Codex as an MCP server, or runs standalone via CLI with support for Anthropic, OpenAI, or local Ollama models. It features 63 probes across 14 vulnerability classes, 23 oracle types, and 18 specialist agents that coordinate reconnaissance, authentication testing, web scanning, API analysis, and reporting.

Key Features

Machine oracle verification system that proves findings by re-executing exploits N-out-of-N times without LLM verdict involvement
Portable proof capsules for every verified finding that anyone can replay independently against live targets
52 MCP tools for integration with Claude Code, Cursor, and Codex using existing AI subscriptions
18 specialist agents covering recon, auth, web, API, AD, and cloud testing phases
Zero false positive guarantee on clean applications enforced through CI testing
SARIF output for GitHub Code Scanning and CI/CD integration with --fail-on verified gate
Deterministic mode (--no-llm) that runs probes without LLM coordination
203 security tool wrappers with 18 parsers including nuclei, nikto, ZAP, nmap

Use Cases

  • 01Application security teams integrating authenticated vulnerability scans into PR workflows with verified-findings-only gates
  • 02Security consultants generating pentesting reports with independently-replayable proof capsules for clients
  • 03Bug bounty hunters triaging proven vulnerabilities instead of hundreds of false positives
  • 04DevOps teams running automated security scans in CI/CD pipelines with SARIF output to GitHub Code Scanning
  • 05Penetration testers using Claude Code or Cursor with real security tooling without separate API subscriptions
  • 06Security researchers testing OWASP Top 10 vulnerabilities on web applications with oracle-backed verification

Related Agents

View more

pentest-ai — FAQ

What is pentest-ai and how does it verify vulnerabilities?+

Pentest-ai is an AI penetration testing agent that uses machine oracles to verify security findings by re-executing exploits multiple times. Unlike traditional scanners that flag potential issues, it only marks findings as VERIFIED after a named oracle proves the vulnerability N-out-of-N times with control tests.

How do I install pentest-ai with Claude Code or Cursor?+

Run 'pip install ptai' followed by 'ptai mcp install' to auto-detect and configure your MCP clients. Restart your editor and 52 pentest tools will be available using your existing AI subscription—no separate API key needed.

Do I need an API key to use pentest-ai?+

Not for the MCP server path—it uses your Claude Code, Cursor, or Codex subscription. The standalone CLI requires an Anthropic or OpenAI API key, though you can run fully local with Ollama or deterministic mode with --no-llm.

Which AI clients work with pentest-ai?+

Pentest-ai works as an MCP server with Claude Code, Cursor, and Codex. It also runs standalone via CLI with any Anthropic, OpenAI, or Ollama-compatible LLM provider.

Is pentest-ai free and open source?+

Yes, pentest-ai is MIT licensed and free forever. The core tool is open source on GitHub, though commercial pentesting services and hosted workspaces are available at pentestai.xyz.

Can I use pentest-ai safely against production systems?+

Only with explicit written authorization for every target. Enable the safe guardrails (intensity=safe, respect_rate_limits, strict_scope) and always comply with legal requirements like the Computer Fraud and Abuse Act.

How do I install pentest-ai?+

Open the source repository on GitHub and follow its README. pentest-ai is a agent — MCP Agents Market links you directly to the official repo.

Is pentest-ai free?+

pentest-ai is an open-source project hosted on GitHub. Check the repository for its license and any usage requirements.

Related searches