</>MCP Agents Market
Agent

pentest-copilot

by bugbasesecurity1.3kTypeScriptUpdated 2026-08-14

Pentest Copilot is an AI-powered browser based ethical hacking assistant tool designed to streamline pentesting workflows.

Claude CodeCodex

Pentest Copilot is an open-source AI-powered autonomous penetration testing agent that connects to attack environments like Kali Linux to conduct security assessments. The agent runs reconnaissance tools, analyzes output, makes tactical decisions, and iterates through up to 25 steps without manual intervention. It integrates with Burp Suite for web application testing, includes browser automation capabilities, and supports concurrent task execution through subagents. Security professionals can describe a target and let the AI sub-agent autonomously execute pentesting workflows for CTF challenges, boot-to-root boxes, and authorized engagements.

Key Features

Autonomous agentic execution with up to 25 self-directed iterations per engagement turn
16 specialized agent tools including bash execution, Python scripting, tool installation, Google search, and subagent spawning
Full Burp Suite integration with proxy history access, Repeater and Intruder control, and Collaborator support
Browser automation agent using Magnitude for testing JavaScript-heavy applications and authentication flows
Curated registry of 100+ security capabilities across network, reverse engineering, pwn, crypto, forensics, and steganography categories
VPN profile management supporting multiple simultaneous OpenVPN connections with certificate bundles
Parallel subagent execution for concurrent tasks like directory brute-forcing and subdomain enumeration
Safety consent layer requiring explicit approval for dangerous commands even in auto-run mode

Use Cases

  • 01Automated reconnaissance and vulnerability scanning for authorized penetration testing engagements
  • 02Solving Capture The Flag (CTF) challenges and boot-to-root practice boxes with AI assistance
  • 03Web application security testing using integrated Burp Suite proxy and browser automation
  • 04Concurrent multi-vector security assessments through parallel subagent task execution
  • 05Authentication bypass and logic flaw testing in JavaScript-heavy web applications
  • 06Network enumeration and exploitation workflows against remote targets via VPN connections

Related Agents

View more

pentest-copilot — FAQ

What is Pentest Copilot and what does it do?+

Pentest Copilot is an autonomous AI agent designed for ethical hacking and penetration testing. It connects to attack environments like Kali Linux, autonomously runs security tools, analyzes results, and iterates through testing workflows based on natural language target descriptions.

How do I install Pentest Copilot?+

Clone the repository and run ./run.sh start to launch the Dockerized stack. After containers start, open http://localhost:3000 to register and configure a model provider under Settings. On Windows, run inside WSL2 with Docker Desktop integration enabled.

Which AI clients or platforms does Pentest Copilot work with?+

Pentest Copilot is a standalone browser-based application with its own web interface. It can expose an MCP endpoint for integration with Claude Code or Codex clients and supports multiple LLM providers including OpenAI, Anthropic, Google, Mistral, and OpenAI-compatible endpoints.

Do I need API keys or subscriptions to use Pentest Copilot?+

You need API keys for at least one LLM provider (OpenAI, Anthropic, Google, or Mistral) or can use authenticated Codex CLI or Claude Code subscriptions. Pentest Copilot itself is open-source and free under MIT license. Docker and 8GB+ RAM are required to run the stack.

Is Pentest Copilot free and open source?+

Yes, Pentest Copilot is released under the MIT License and is completely free and open source. LLM inference costs apply separately based on your chosen provider (API-based or authenticated CLI subscriptions).

What are the system requirements for running Pentest Copilot?+

Minimum 8GB RAM (10GB with built-in Kali container), 20GB disk space, Docker v20+ with Compose v2+. Node.js v22+ and pnpm v9+ are required only for development mode. The system must support POSIX shells; native Windows PowerShell is not supported.

How do I install pentest-copilot?+

Open the source repository on GitHub and follow its README. pentest-copilot is a agent — MCP Agents Market links you directly to the official repo.

Is pentest-copilot free?+

pentest-copilot is an open-source project hosted on GitHub. Check the repository for its license and any usage requirements.

Related searches