Framework · planner-executor
PentestGPT
Task-tree and planner/executor pentest reference architecture; local models supported mainly in its human-guided workflow.
Use responsibly
Test only systems you own or are explicitly authorized to test. Unauthorized testing is illegal.
Tagsplanner-executor
More frameworks & agents
- Pentest-Strategistplanner-executorA research framework that trains custom LLMs (Qwen 14B with reinforcement learning) on curated penetration-testing reasoning datasets to autonomously generate pentest strategies and step-by-step actions. Ships dataset-collection utilities, training code, RL experiments, and CTF-based evaluation, with an accompanying arXiv preprint.
- WhiteRabbitNeo-PentestGPTplanner-executorOpen-source pentest assistant that pairs the WhiteRabbitNeo security LLM with the PentestGPT prompting methodology, using structured todo-list workflows and constrained (outlines) generation to keep the fully-open-source stack usable without proprietary APIs. Author notes parity with GPT-4 is still a work in progress.
- Agentic Malware Analysisagent-security-skillsKali-based Docker environment with 50+ RE tools, an MCP-connected Binary Ninja or Ghidra backend, and an orchestrator skill that lets Claude Code or Codex CLI turn a binary into a case directory of ranked evidence and hypotheses.
- Anthropic Cybersecurity Skillsagent-security-skillsApache-2.0 library of 818 agentskills.io-format cybersecurity skills in 34 domains, mapped to MITRE ATT&CK, NIST CSF 2.0, ATLAS, D3FEND, NIST AI RMF and F3, for loading into Claude Code, Codex CLI, Cursor and similar agents.
- AppSec (florianbuetow)agent-security-skillsMIT Claude Code plugin bundling 62 slash-command skills across OWASP, STRIDE, PASTA, LINDDUN, MITRE ATT&CK and CWE Top 25, plus six red-team persona agents, for reviewing a codebase and generating fixes.
- Arm Metiswhite-box-sastApache-2.0 white-box framework with broad language support, local-model support, deterministic evidence collection, and validation of SAST findings.