No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →
by s0ld13rr · Agent Tool · ★ 599
Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h
🔒 Is pentestcode safe to install? View the security audit →
PentestCode AI penetration testing agent in your terminal. Multi-agent architecture • Engagement state tracking • 20+ LLM providers PentestCode is an AI pentesting agent that runs tools, analyzes results, and makes decisions in your terminal. Hard fork of OpenCode (MIT), rebuilt for offensive security. Alpha — works on real engagements and CTFs, but expect rough edges. Open an issue if something breaks. What It Actually Does You give it a target — it does the rest:
| Stars | 599 |
| Forks | 94 |
| Language | TypeScript |
| Category | Agent Tool |
| License | MIT |
| Quality Score | 73.6216705335262/100 |
| Open Issues | 1 |
| Last Updated | 2026-09-02 |
| Created | 2026-07-08 |
| Platforms | node |
| Est. Tokens | ~16k |
Looking for a pentestcode alternative? If you're comparing pentestcode with other agent tool tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.
Turn Claude Code into your offensive security research assistant. Specialized AI subagents for authorized pene
Autonomous AI pentesting engine across web, cloud, identity, CI/CD, IaC, databases, Active Directory, Kubernet
Autonomous penetration testing using a swarm of AI agents. Orchestrates recon, classification, exploitation, a
Open-source AI-augmented offensive security harness. 13+ autonomous agents, 150+ LLM providers, 5,300+ models,
The AI Agent for Cyber Security.
Self-hosted framework for orchestrating fleets of specialist AI agents — ensemble reasoning and a full agentic
Explore other popular agent tool tools:
pentestcode is PentestCode - Multi-agent AI penetration testing system with persistent engagement state, strategic coordination, and parallel autonomous operations.. It is categorized as a Agent Tool with 599 GitHub stars.
pentestcode is primarily written in TypeScript. It covers topics such as ai-agents, ai-security, ai-security-tool.
You can find installation instructions and usage details in the pentestcode GitHub repository at github.com/s0ld13rr/pentestcode. The project has 599 stars and 94 forks, indicating an active community.
pentestcode is released under the MIT license, making it free to use and modify according to the license terms.
The top alternatives to pentestcode on Agent Skills Hub include pentest-ai-agents, Dark-Moon, Pentest-Swarm-AI. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.
Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.
The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.
Sources & who's responsible: