🤖 Trợ lý AI•Mã nguồn mở•Đang hoạt động
Pentest AI
Bộ 28 subagent bảo mật cho Claude Code, bao phủ toàn bộ quy trình penetration testing từ trinh sát đến báo cáo, có MITRE ATT&CK mapping.
#pentest-ai
Danh mục
🤖 Trợ lý AI
Giá
Mã nguồn mở
GitHub Stars
⭐ 1,717
Ngôn ngữ
Python
License
MIT
Ngày thêm
2026-03-31
Tóm tắt từ README GitHub
Website · Quick start · Verification · Documentation · Issues
Pentest-AI connects an AI client or model to a penetration-testing workflow. It investigates applications, records findings, and uses machine oracles to check whether an exploit can be reproduced . Verified findings carry evidence you can replay.
Use it through MCP , from the CLI , or in CI . The model helps drive the investigation; an oracle determines whether a finding earns a verified verdict.
Test only systems you own or have explicit authorization to assess. Read the acceptable-use policy and terms before running an engagement.
Quick start
Recommended: Codex or Claude Code
Use Python 3.10–3.14 and install pipx
first. Run and reopen your terminal if needed. pipx isolates
Pentest-AI's dependencies and makes its commands available across folders.
Install your AI client's CLI first. Setup asks before connecting all detected
supported clients , including both Codex and Claude Code when installed. It
preserves existing registrations. Restart your client afterward.
The wizard uses user-wide settings . It does not install clients, sign you in,
download models or configure Ollama. Your AI client supplies the mod
Xem thêm từ README.mdThu gọn README.md
Đánh giá chi tiết
Tổng quan
Pentest AI biến Claude Code thành trợ lý penetration testing với 28 subagent chuyên biệt. Mỗi agent phụ trách một giai đoạn: lập kế hoạch, trinh sát, khai thác, leo quyền, và viết báo cáo. Chia làm 2 tầng: Tier 1 chỉ tư vấn, Tier 2 thực thi tool trực tiếp (Nmap, BloodHound, Impacket) khi được phê duyệt.
Tính năng chính
- 28 subagent: Engagement Planner, Recon Advisor, OSINT Collector, Exploit Guide, Privilege Escalation, Cloud Security, API Security và nhiều hơn
- Tier 2 agents chạy tool trực tiếp với approval flow
- Autonomous exploit chaining và PoC-validated findings
- MITRE ATT&CK mapping cho mọi technique
- Dual offensive/defensive perspective
Stack kỹ thuật
Markdown-based agent definitions cho Claude Code. Tích hợp Nmap, Nessus, BloodHound, Impacket và 20+ security tools. Chạy trên Linux, macOS, Windows WSL.
Điểm mạnh
- 28 agent phủ mọi phase pentest, routing tự động theo ngôn ngữ tự nhiên
- Hai chế độ rõ ràng: advisory (Tier 1) và execution (Tier 2)
Hạn chế
- Phụ thuộc hoàn toàn vào Claude Code, tốn token Anthropic
- Cần cài sẵn các security tool trên hệ thống
Phù hợp khi nào
Pentester hoặc security researcher muốn tăng tốc workflow, đặc biệt cho phân tích output trinh sát và tự động hóa các bước lặp lại.