Framework · multi-agent-pentest
PentAGI
Autonomous pentest framework with multi-agent roles, Docker isolation, memory, observability, and native GLM/Ollama/custom OpenAI-compatible provider support.
Use responsibly
Test only systems you own or are explicitly authorized to test. Unauthorized testing is illegal.
More frameworks & agents
- BugTraceAImulti-agent-pentestA self-hosted autonomous vuln-discovery framework combining 15 specialist AI agents with real tooling in a six-phase pipeline (discovery→analysis→consolidation→exploitation→validation→reporting), with payload mutation, consensus voting, vision-based finding validation and a swarm dashboard. Python/FastAPI/React/Go, AGPL-3.0.
- HPTSAmulti-agent-pentestHPTSA is a hierarchical multi-agent system from UIUC (EACL 2026) for automated web-app penetration testing, using a planning supervisor agent that coordinates specialized subagents (SQLi, XSS, CSRF, SSTI, etc.) to find and exploit vulnerabilities. Built on the OpenAI Agents SDK with GPT-4 models.
- pentest-agentsmulti-agent-pentestAn autonomous bug-bounty framework that orchestrates AI coding assistants (Claude Code, Codex, Gemini, Cursor, etc.) across ~50 specialized agents by vulnerability class (XSS, SQLi, CSRF, SSRF, OAuth), with a 7-Question Gate validation pipeline, bug-bounty platform integrations, payload libraries, and scope/never-submit controls.
- pentest-aimulti-agent-pentestAn AI-driven penetration-testing tool coordinating 17 specialist agents across recon, web, API, Active Directory and cloud; findings are marked VERIFIED only after deterministic oracles re-run the exploit against the target. Ships CLI (MIT), MCP server, REST API and cloud workspace. Active, ~1.6k stars.
- Agentic Malware Analysisagent-security-skillsKali-based Docker environment with 50+ RE tools, an MCP-connected Binary Ninja or Ghidra backend, and an orchestrator skill that lets Claude Code or Codex CLI turn a binary into a case directory of ranked evidence and hypotheses.
- Anthropic Cybersecurity Skillsagent-security-skillsApache-2.0 library of 818 agentskills.io-format cybersecurity skills in 34 domains, mapped to MITRE ATT&CK, NIST CSF 2.0, ATLAS, D3FEND, NIST AI RMF and F3, for loading into Claude Code, Codex CLI, Cursor and similar agents.