pentest-ai — security grade SAFE, quality 68/100

Security audit verdict: SAFE · quality 68/100

No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →

by 0xSteph · MCP Server · ★ 1.7k

Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h

🔒 Is pentest-ai safe to install? View the security audit →

About pentest-ai

pentest-ai Turn Claude Code into your offensive security research assistant. 17 specialized AI subagents for every phase of authorized penetration testing, from scoping to reporting. MITRE ATT&CK mapped. Dual offensive/defensive perspective in every response. []() []() []() []() [](https://github.com/0xSteph/pent

ai-penetration-testingai-pentestingai-securityappsecbug-bountyclaudectfcybersecuritydevsecopsethical-hacking

Quick Facts

Stars1,667
Forks313
LanguagePython
CategoryMCP Server
LicenseMIT
Quality Score68.2041472926808/100
Open Issues1
Last Updated2026-09-13
Created2026-04-04
Platformsclaude-code, mcp, python
Est. Tokens~19k

Compatible Skills

These tools work well together with pentest-ai for enhanced workflows:

  • tengu — semantic(0.62)+complementary+rare_topics+similar_pop+shared_platform (72%)
  • red-run — semantic(0.60)+complementary+rare_topics+similar_pop+shared_platform (71%)
  • CyberStrike — semantic(0.60)+complementary+rare_topics+similar_pop (66%)
  • Anthropic-Cybersecurity-Skills — semantic(0.48)+complementary+rare_topics+shared_platform (62%)

pentest-ai alternative? Top 6 similar tools

Looking for a pentest-ai alternative? If you're comparing pentest-ai with other mcp server tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.

  • CyberStrike by CyberStrikeus · ⭐ 1.9k

    Open-source AI-augmented offensive security harness. 13+ autonomous agents, 150+ LLM providers, 5,300+ models,

  • numasec by FrancescoStabile · ⭐ 466

    The AI Agent for Cyber Security.

  • Dark-Moon by ASCIT31 · ⭐ 957

    Open source autonomous AI penetration testing platform. 50+ specialist agents for AI security testing across w

  • Claude-BugHunter by elementalsouls · ⭐ 4.6k

    A Claude Code skill bundle for bug hunting and external red-team work - 82 skills, 15 slash commands, 681 disc

  • mcp-security-hub by FuzzingLabs · ⭐ 758

    A growing collection of MCP servers bringing offensive security tools to AI assistants. Nmap, Ghidra, Nuclei,

  • h5i by h5i-dev · ⭐ 652

    An agent-native red-teaming workspace with a fast browser, direct HTTP traffic control, sandboxed execution, a

More MCP Server Tools

Explore other popular mcp server tools:

View all MCP Server tools →

Popular Python Agent Tools

Frequently Asked Questions

What is pentest-ai?

pentest-ai is Open-source AI pentester that proves every finding. Machine oracles re-run each exploit; verified bugs ship a proof capsule you can replay yourself.. It is categorized as a MCP Server with 1.7k GitHub stars.

What programming language is pentest-ai written in?

pentest-ai is primarily written in Python. It covers topics such as ai-penetration-testing, ai-pentesting, ai-security.

How do I install or use pentest-ai?

You can find installation instructions and usage details in the pentest-ai GitHub repository at github.com/0xSteph/pentest-ai. The project has 1.7k stars and 313 forks, indicating an active community.

What license does pentest-ai use?

pentest-ai is released under the MIT license, making it free to use and modify according to the license terms.

What are the best alternatives to pentest-ai?

The top alternatives to pentest-ai on Agent Skills Hub include CyberStrike, numasec, Dark-Moon. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.

How this security grade is produced

Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.

The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.

Sources & who's responsible:

View on GitHub → Browse MCP Server tools