pentest-ai-agents
FreeTurn Claude Code into your offensive security research assistant. Specialized AI subagents for authorized penetration testing plan engagements, analyze recon, research exploits, build detections, audi
About pentest-ai-agents
ptai is an open-source AI penetration testing tool that runs locally as a CLI and MCP server. It integrates with Claude Code (or Cursor) to act as offensive security agents that plan engagements, analyze reconnaissance data, research exploits, build detections, audit STIGs, and write reports. Findings are structurally verified: a candidate claim becomes VERIFIED only when a named machine oracle re-runs the exploit and reproduces it three-for-three. The tool supports 14 vulnerability classes including SQL injection, stored/reflected XSS, SSRF, XXE, BOLA/IDOR, JWT alg:none, and more. Every verified finding ships as a portable proof capsule that can be replayed by anyone. It outputs SARIF for CI integration (e.g., GitHub Code Scanning) and can gate builds on verified findings only. Runs entirely on the user's machine with local SQLite storage, no telemetry, and no data exfiltration. Can operate without any API key (deterministic mode) or bring your own LLM key.
Key Features
Pros & Cons
- Machine-verified findings eliminate false positives; every badge is backed by reproducible proof
- Fully local operation with no data exfiltration or telemetry
- Portable proof capsules enable trust by reproduction, not screenshots
- Seamless integration with Claude Code and Cursor for AI-driven attack planning
- Wide coverage of common web vulnerability classes (14 types)
- Can run without any API key in deterministic mode
- CI-ready with SARIF and build-failing on verified findings only
- Requires technical expertise to install and configure (CLI and MCP setup)
- Currently supports only 14 vulnerability classes; not exhaustive
- AI-driven attack planning depends on an external LLM (Claude subscription or bring-your-own)
- Primarily designed for authorized penetration testing; not for casual security scanning
- Limited out-of-the-box integration with other security tools beyond SARIF and MCP
Best For
Alternatives to pentest-ai-agents
Verkada
Advanced and User-Friendly Security Cameras by Verkada
SecureGPT
Build and Secure Your ChatGPT Plugins with SecureGPT by Escape
Fraud.net
Harness AI & Machine Learning for Superior Fraud Detection
MaskmyPrompt
Use MaskMyPrompt to anonymize your ChatGPT prompts
Final Touch
Enhance Your Browsing Experience with Customized Cookie Preferences
Skoot
Skoothere.com: Tailor Your Cookie Consent Preferences