No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →
by pensarai · Agent Tool · ★ 312
Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h
🔒 Is apex safe to install? View the security audit →
Pensar Apex AI-powered penetration testing using autonomous agents — directly in your terminal. Run blackbox and whitebox pentests that explore, reason, and surface real vulnerabilities. Want to run from the cloud or integrate it with your CI/CD? See Pensar Console. -- -- Use Cases Developers Run before merging a PR — catch v
| Stars | 312 |
| Forks | 58 |
| Language | TypeScript |
| Category | Agent Tool |
| License | Apache-2.0 |
| Quality Score | 67.7672867532874/100 |
| Open Issues | 63 |
| Last Updated | 2026-09-22 |
| Created | 2025-10-10 |
| Platforms | node |
| Est. Tokens | ~15k |
These tools work well together with apex for enhanced workflows:
Looking for a apex alternative? If you're comparing apex with other agent tool tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.
The pipe layer of an AI nervous system — one interface connecting provider neurons to your application, across
Simple orchestration for AI Agents built around Vercel's streamText. Lightweight alternative to LangGraph for
A growing collection of MCP servers bringing offensive security tools to AI assistants. Nmap, Ghidra, Nuclei,
Agentic pentest tooling. Currently achieving 81% (KIMI K2.5) on XBOW's benchmark in full black-box. Completely
Torque is a Declarative, typesafe DSL for building synthetic LLM datasets — compose conversations like React c
htop for your AI costs — real-time terminal monitoring of LLM token usage and spending across providers and co
Explore other popular agent tool tools:
apex is AI-powered offensive security testing using autonomous agents, directly in your terminal.. It is categorized as a Agent Tool with 312 GitHub stars.
apex is primarily written in TypeScript. It covers topics such as agents, ai, ai-sdk.
You can find installation instructions and usage details in the apex GitHub repository at github.com/pensarai/apex. The project has 312 stars and 58 forks, indicating an active community.
apex is released under the Apache-2.0 license, making it free to use and modify according to the license terms.
The top alternatives to apex on Agent Skills Hub include neurolink, ai-orchestra, mcp-security-hub. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.
Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.
The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.
Sources & who's responsible: