pentest-copilot
Pentest Copilot is an AI-powered browser based ethical hacking assistant tool designed to streamline pentesting workflows.
Pentest Copilot is an open-source AI-powered autonomous penetration testing agent that connects to attack environments like Kali Linux to conduct security assessments. The agent runs reconnaissance tools, analyzes output, makes tactical decisions, and iterates through up to 25 steps without manual intervention. It integrates with Burp Suite for web application testing, includes browser automation capabilities, and supports concurrent task execution through subagents. Security professionals can describe a target and let the AI sub-agent autonomously execute pentesting workflows for CTF challenges, boot-to-root boxes, and authorized engagements.
Key Features
Use Cases
- 01Automated reconnaissance and vulnerability scanning for authorized penetration testing engagements
- 02Solving Capture The Flag (CTF) challenges and boot-to-root practice boxes with AI assistance
- 03Web application security testing using integrated Burp Suite proxy and browser automation
- 04Concurrent multi-vector security assessments through parallel subagent task execution
- 05Authentication bypass and logic flaw testing in JavaScript-heavy web applications
- 06Network enumeration and exploitation workflows against remote targets via VPN connections
Related Agents
View morehermes-agent
The agent that grows with you
agency-agents
A complete AI agency at your fingertips - From frontend wizards to Reddit community ninjas, from whimsy injectors to reality checkers. Each agent is a specialized expert with personality, processes, and proven deliverables.
openinterpreter
A coding agent for open models like Kimi K3
cline
Autonomous coding agent as an SDK, IDE extension, or CLI assistant.
pentest-copilot — FAQ
What is Pentest Copilot and what does it do?+
Pentest Copilot is an autonomous AI agent designed for ethical hacking and penetration testing. It connects to attack environments like Kali Linux, autonomously runs security tools, analyzes results, and iterates through testing workflows based on natural language target descriptions.
How do I install Pentest Copilot?+
Clone the repository and run ./run.sh start to launch the Dockerized stack. After containers start, open http://localhost:3000 to register and configure a model provider under Settings. On Windows, run inside WSL2 with Docker Desktop integration enabled.
Which AI clients or platforms does Pentest Copilot work with?+
Pentest Copilot is a standalone browser-based application with its own web interface. It can expose an MCP endpoint for integration with Claude Code or Codex clients and supports multiple LLM providers including OpenAI, Anthropic, Google, Mistral, and OpenAI-compatible endpoints.
Do I need API keys or subscriptions to use Pentest Copilot?+
You need API keys for at least one LLM provider (OpenAI, Anthropic, Google, or Mistral) or can use authenticated Codex CLI or Claude Code subscriptions. Pentest Copilot itself is open-source and free under MIT license. Docker and 8GB+ RAM are required to run the stack.
Is Pentest Copilot free and open source?+
Yes, Pentest Copilot is released under the MIT License and is completely free and open source. LLM inference costs apply separately based on your chosen provider (API-based or authenticated CLI subscriptions).
What are the system requirements for running Pentest Copilot?+
Minimum 8GB RAM (10GB with built-in Kali container), 20GB disk space, Docker v20+ with Compose v2+. Node.js v22+ and pnpm v9+ are required only for development mode. The system must support POSIX shells; native Windows PowerShell is not supported.
How do I install pentest-copilot?+
Open the source repository on GitHub and follow its README. pentest-copilot is a agent — MCP Agents Market links you directly to the official repo.
Is pentest-copilot free?+
pentest-copilot is an open-source project hosted on GitHub. Check the repository for its license and any usage requirements.