pentest-agents — security grade SAFE, quality 73/100

Security audit verdict: SAFE · quality 73/100

No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →

by H-mmer · MCP Server · ★ 794

Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h

🔒 Is pentest-agents safe to install? View the security audit →

About pentest-agents

Pentest Agent Suite for Claude Code Autonomous bug-bounty framework for Claude Code and 6 other AI coding tools — 48 agents, 26 commands, 19 CLI tools, 2 MCP servers. 300 files · 49k+ lines · 48 agents · 26 commands · 19 CLI tools · 6 skills · 2 MCP servers (16 bug-bounty platforms + BYO writeup search) · 2,047 payload lines A complete bug bounty framework. Battle-tested hunting methodology with concrete payloads, 7-Question Gate validation, autonomous hunt loops, A→B exploit chain building, persistent brain with endpoint tracking, optional semantic writeup search (bring your own index), automatic cost tracking via CC hooks, live platform integration, and a cross-IDE installer that emits the native format for Claude Code, Codex, Gemini, Cursor, Windsurf, and VS Cod

agentsbug-bountybugcrowdclaude-codehackeronemcppentestingsecurity-tools

Quick Facts

Stars794
Forks158
LanguagePython
CategoryMCP Server
Quality Score72.8653156751116/100
Open Issues4
Last Updated2026-06-12
Created2026-04-01
Platformsclaude-code, cli, codex, gemini, mcp, python
Est. Tokens~229k

Compatible Skills

These tools work well together with pentest-agents for enhanced workflows:

  • claude-bug-bounty — semantic(0.45)+complementary+rare_topics+same_lang+shared_platform (69%)
  • h1-brain — semantic(0.68)+rare_topics+same_lang+shared_platform (62%)
  • pentest-ai — semantic(0.45)+rare_topics+same_lang+similar_pop+shared_platform (60%)
  • RedteamAgent — semantic(0.28)+complementary+rare_topics+same_lang+similar_pop+shared_platform (59%)

pentest-agents alternative? Top 6 similar tools

Looking for a pentest-agents alternative? If you're comparing pentest-agents with other mcp server tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.

  • pentest-ai-agents by 0xSteph · ⭐ 2.1k

    Turn Claude Code into your offensive security research assistant. Specialized AI subagents for authorized pene

  • src-hunter-skill by MyuriKanao · ⭐ 596

    实战 SRC / 众测 / Bug bounty 漏洞挖掘 Claude Code skill — 19 个攻击类 playbook、305 个结构化 payload、263 个 WAF/EDR 绕过、2887 份 Ha

  • h1-brain by PatrikFehrenbach · ⭐ 333

    MCP server that connects AI assistants to HackerOne for bug bounty hunting

  • public-skills-builder by awarexone · ⭐ 238

    Generate Claude Code bug bounty skills from public HackerOne reports and GitHub writeups — 18 vuln classes, no

  • Continuous-Claude-v3 by parcadei · ⭐ 3.9k

    Context management for Claude Code. Hooks maintain state via ledgers and handoffs. MCP execution without conte

  • open-kritt by Kritt-ai · ⭐ 2.2k

    Open-source, self-hosted AI vulnerability research tool that orchestrates agents to find and validate security

More MCP Server Tools

Explore other popular mcp server tools:

View all MCP Server tools →

Popular Python Agent Tools

Frequently Asked Questions

What is pentest-agents?

pentest-agents is Bug bounty agent framework for Claude Code, Codex, Gemini, Cursor, Windsurf, Copilot, and OpenClaw — 48 agents, 26 commands, 19 CLI tools, 2 MCP servers, autonomous hunt loops, exploit chain builder.. It is categorized as a MCP Server with 794 GitHub stars.

What programming language is pentest-agents written in?

pentest-agents is primarily written in Python. It covers topics such as agents, bug-bounty, bugcrowd.

How do I install or use pentest-agents?

You can find installation instructions and usage details in the pentest-agents GitHub repository at github.com/H-mmer/pentest-agents. The project has 794 stars and 158 forks, indicating an active community.

What are the best alternatives to pentest-agents?

The top alternatives to pentest-agents on Agent Skills Hub include pentest-ai-agents, src-hunter-skill, h1-brain. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.

How this security grade is produced

Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.

The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.

Sources & who's responsible:

View on GitHub → Browse MCP Server tools