pentest-ai-agents
Turn Claude Code into your offensive security research assistant. Specialized AI subagents for authorized penetration testing plan engagements, analyze recon, research exploits, build detections, audit STIGs, and write reports.
Pentest AI Agents is a collection of 50 specialized AI sub-agents that transform Claude Code into an offensive security research assistant. Each agent file provides deep domain expertise in specific penetration testing areas including reconnaissance, Active Directory attacks, cloud security, exploit chaining, detection engineering, and reporting. The sub-agents route automatically based on task description and include both advisory (Tier 1) and execution-capable (Tier 2) modes, with the latter able to compose and run security tools directly under defined scope constraints. Installation requires either a single curl command or Claude Code's plugin marketplace, placing agent definition files where Claude can route to them.
Key Features
Use Cases
- 01Planning multi-phase penetration tests with MITRE ATT&CK-mapped engagement plans and time estimates
- 02Analyzing BloodHound, Nmap, or vulnerability scanner output to prioritize targets and recommend next commands
- 03Executing authorized Active Directory attacks (Kerberoasting, delegation abuse, certificate exploitation) with tool command generation
- 04Generating detection engineering content (Sigma rules, Splunk SPL, Elastic KQL) paired with offensive techniques
- 05Conducting authorized phishing simulations with GoPhish/Evilginx infrastructure setup and campaign tracking
- 06Chaining low-severity findings into complete attack paths with step-by-step approval gates and remediation guidance
Related Agents
View morehermes-agent
The agent that grows with you
agency-agents
A complete AI agency at your fingertips - From frontend wizards to Reddit community ninjas, from whimsy injectors to reality checkers. Each agent is a specialized expert with personality, processes, and proven deliverables.
openinterpreter
A coding agent for open models like Kimi K3
cline
Autonomous coding agent as an SDK, IDE extension, or CLI assistant.
pentest-ai-agents — FAQ
What is pentest-ai-agents?+
A collection of 50 Claude Code sub-agent definition files that provide specialized penetration testing knowledge and methodology. Each agent focuses on a specific security domain (recon, web, AD, cloud, mobile, etc.) and can provide advisory guidance or execute security tools directly.
How do I install pentest-ai-agents?+
Run 'curl -fsSL https://raw.githubusercontent.com/0xSteph/pentest-ai-agents/main/install.sh | bash' to copy agents to ~/.claude/agents/, or use the Claude Code plugin marketplace with '/plugin marketplace add 0xSteph/pentest-ai-agents' then '/plugin install pentest-ai-agents@pentest-ai-agents'. Both methods are idempotent and safe to re-run for updates.
Which AI clients work with pentest-ai-agents?+
Designed for Claude Code with Claude Pro or Max subscription. The plain markdown system prompts can also be adapted to other Anthropic-compatible endpoints by setting ANTHROPIC_BASE_URL, or copied into local runners like Ollama or LM Studio.
Do I need API keys or external tools?+
You need an active Claude Pro or Max subscription for Claude Code. The agents work in advisory mode with no additional tools, but Tier 2 execution mode requires underlying security tools (nmap, BloodHound, sqlmap, etc.), installable via 'install.sh --tools'.
Is pentest-ai-agents free to use?+
Yes, the agent collection is MIT licensed and free. However, you need a paid Claude Pro or Max subscription to run Claude Code, and all usage must be for authorized security testing with proper written authorization and defined scope.
What's the difference between Tier 1 and Tier 2 agents?+
Tier 1 agents provide advisory guidance—you paste tool output and receive analysis and recommendations. Tier 2 agents can also compose and execute security tool commands directly after validating targets against your declared authorized scope, with each command requiring approval before execution.
How do I install pentest-ai-agents?+
Open the source repository on GitHub and follow its README. pentest-ai-agents is a agent — MCP Agents Market links you directly to the official repo.
Is pentest-ai-agents free?+
pentest-ai-agents is an open-source project hosted on GitHub. Check the repository for its license and any usage requirements.