</>MCP Agents Market
Agent

PentestGPT

by GreyDGL15kPythonUpdated 2026-07-14

Automated Penetration Testing Agentic Framework Powered by Large Language Models

Claude CodeCodex

PentestGPT is an autonomous AI agent that conducts penetration testing and Capture The Flag (CTF) challenges using large language model reasoning. Published at USENIX Security 2024, this framework works through multi-stage pipelines—reconnaissance, exploitation, and walkthrough for CTFs; asset discovery, vulnerability identification, and reporting for pentests—feeding each stage's findings into the next. The agent drives Claude Code or Codex to run security tools and reason without human intervention, supporting web, crypto, reversing, forensics, PWN, and privilege escalation categories. A legacy interactive mode supports additional LLM providers including OpenAI, Anthropic, Google Gemini, DeepSeek, xAI, Qwen, Moonshot, and local Ollama models.

Key Features

Autonomous multi-stage pipeline that progresses from recon to exploit to walkthrough in CTF mode, or asset discovery to vulnerability identification to reporting in pentest mode
Integrates with Claude Code and Codex backends for autonomous tool execution
Session persistence enables saving and resuming penetration testing sessions
Real-time walkthrough tracking displays agent steps and activity as challenges are solved
Legacy interactive mode with multi-LLM support via PTT (Pentesting Task Tree) architecture across OpenAI, Anthropic, Gemini, DeepSeek, xAI, Qwen, Moonshot, and Ollama
Multi-category security testing support including web, crypto, reversing, forensics, PWN, and privilege escalation
Docker runtime bundles CLI tools with persistent authentication for Claude Code and Codex
Anonymous telemetry via Langfuse for usage insights, opt-out supported

Use Cases

  • 01Automated penetration testing of web applications and network targets without manual intervention
  • 02Solving CTF challenges across multiple categories with AI-driven reasoning and tool execution
  • 03Security assessment workflows that require asset discovery, vulnerability scanning, and reporting
  • 04Educational security testing scenarios for learning penetration testing techniques
  • 05Research into LLM-powered autonomous security testing capabilities
  • 06Interactive penetration testing sessions with human-in-the-loop guidance using multiple LLM providers

Related Agents

View more

PentestGPT — FAQ

What is PentestGPT?+

PentestGPT is an autonomous AI agent framework for penetration testing and CTF challenges, published at USENIX Security 2024. It uses large language models to reason through security assessments in multi-stage pipelines, automatically executing tools via Claude Code or Codex backends.

How do I install PentestGPT?+

Clone the repository, ensure you have Python 3.12+, uv package manager, and either Claude Code CLI or Codex CLI installed and authenticated. Run 'make install' to install dependencies, then use the 'pentestgpt' command with a target. Docker installation is also available with 'make docker-build' and 'make docker-login'.

What are the prerequisites and API keys needed?+

You need Python 3.12+, the uv package manager, and either Claude Code CLI (authenticated) or Codex CLI (authenticated) for autonomous mode. For the legacy interactive mode, set API keys for any provider you want: OPENAI_API_KEY, ANTHROPIC_API_KEY, GEMINI_API_KEY, DEEPSEEK_API_KEY, GROK_API_KEY, QWEN_API_KEY, or KIMI_API_KEY.

Which AI clients and backends does PentestGPT work with?+

The autonomous agent mode works with Claude Code and Codex as backends. The legacy interactive mode supports OpenAI, Anthropic, Google Gemini, DeepSeek, xAI Grok, Alibaba Qwen, Moonshot Kimi, and local Ollama models.

Is PentestGPT free to use?+

Yes, PentestGPT is open source under the MIT License. However, you'll need valid API keys or authentication for the LLM backends (Claude Code, Codex, OpenAI, etc.), which may have their own costs.

Can I disable telemetry data collection?+

Yes, you can disable anonymous telemetry by using the '--no-telemetry' command-line flag or by setting the environment variable 'LANGFUSE_ENABLED=false'. No sensitive data like command outputs, credentials, or flag values are ever collected.

How do I install PentestGPT?+

Open the source repository on GitHub and follow its README. PentestGPT is a agent — MCP Agents Market links you directly to the official repo.

Is PentestGPT free?+

PentestGPT is an open-source project hosted on GitHub. Check the repository for its license and any usage requirements.

Related searches