{"data":{"slug":"0xsteph-pentest-ai","name":"pentest-ai","tagline":"Offensive-security MCP server with security tools and agents","github_url":"https://github.com/0xSteph/pentest-ai","owner":"0xSteph","repo":"pentest-ai","owner_avatar_url":"https://avatars.githubusercontent.com/u/245668117?v=4","primary_language":"Python","stars":1441,"forks":286,"topics":["ai-security","bug-bounty","claude","ctf","cybersecurity","exploit","exploit-chaining","hacking-tools","mcp","model-context-protocol","nmap","offensive-security","osint","penetration-testing","pentest-ai","pentesting","python","red-team","security","vulnerability-scanner"],"archived":false,"github_pushed_at":"2026-07-05T07:23:16+00:00","maintenance_label":"Active","url":"https://www.graphcanon.com/tools/0xsteph-pentest-ai","markdown_url":"https://www.graphcanon.com/tools/0xsteph-pentest-ai.md","api_url":"https://www.graphcanon.com/api/graphcanon/tools/0xsteph-pentest-ai","graph_url":"https://www.graphcanon.com/api/graphcanon/graph?tool=0xsteph-pentest-ai","description":"Offensive-security MCP server with 205 wrapped tools, 17 specialist agents, and 60 SPA-aware probes for OWASP Top 10. CLI + MCP, BYO LLM. No API key needed on MCP path.","homepage_url":"https://pentestai.xyz","license":"MIT","open_issues":2,"watchers":16,"ai_summary":"Pentest-ai offers an offensive-security platform that includes various security tools for bug bounty, CTF, OSINT tasks, exploit chaining, and more.","readme_excerpt":"#    which tools the LLM will need and asks ONCE to install the missing\n\n---\n\n#    ~/.pentest-ai/install-preferences.json.\nptai start https://target.example.com\n\n---\n\n# 2. Batch install upfront. Skips the engagement-time prompt entirely.\nptai setup --tier core            # ~6 essentials, ~30s\nptai setup --tier recommended     # + fuzzers, crawlers, password tools, ~5m\nptai setup --tier full            # everything, ~30m\n\n---\n\n# 3. Install specific tools by name.\nptai setup --per-tool wpscan,dalfox,paramspider\nptai setup --wizard               # interactive picker\n```\n\nIn non-interactive contexts (`PTAI_NON_INTERACTIVE=1` or no TTY) ptai uses what's on PATH and logs (rather than prompts) for anything missing.\n\n<details>\n<summary><strong>Other paths</strong>: REST API, MCP composition, HITL teleoperation, cloud workspace, public benchmarks</summary>\n\n---\n\n## License\n\nMIT. Do whatever you want with it.\n\n<div align=\"center\">\n\n**If `ptai` saved you a Sunday, [star the repo](https://github.com/0xSteph/pentest-ai). It's the only payment I ask for.**\n\n</div>","github_created_at":"2026-04-04T06:58:30+00:00","created_at":"2026-07-11T11:52:19.372199+00:00","updated_at":"2026-07-27T00:00:53.626473+00:00","categories":[{"slug":"ai-agents","name":"AI Agents","url":"https://www.graphcanon.com/categories/ai-agents","markdown_url":"https://www.graphcanon.com/categories/ai-agents.md","api_url":"https://www.graphcanon.com/api/graphcanon/categories/ai-agents"},{"slug":"developer-tools","name":"Developer Tools","url":"https://www.graphcanon.com/categories/developer-tools","markdown_url":"https://www.graphcanon.com/categories/developer-tools.md","api_url":"https://www.graphcanon.com/api/graphcanon/categories/developer-tools"}],"tags":[{"slug":"cybersecurity","name":"cybersecurity"},{"slug":"mcp","name":"mcp"},{"slug":"pentesting","name":"pentesting"},{"slug":"security","name":"security"}],"trust":{"provenance":{"is_fork":false,"github_id":1201069034,"owner_type":"User","methodology":"github_public_v1","parent_repo":null,"near_duplicate_slugs":[]},"computed_at":"2026-07-27T00:00:52.838Z","maintenance":{"label":"Active","score":82,"methodology":"github_public_v1","releases_90d":19,"days_since_push":21,"last_release_at":"2026-06-29T05:41:14Z"},"security_summary":{"status":"no_manifest","scanner":null,"low_count":0,"high_count":0,"last_scan_at":"2026-07-11T11:52:21.124Z","medium_count":0,"scan_profile":"mcp_manifest","critical_count":0}},"capability_facts":{"scan":{"source":"repo_scan","observed_at":"2026-07-27T00:00:53.281Z"},"deploy":{"source":"dockerfile:Dockerfile","self_host":true,"observed_at":"2026-07-27T00:00:53.281Z","managed_saas":false},"has_cli":{"value":true,"source":"pyproject.toml:[project.scripts]","observed_at":"2026-07-27T00:00:53.281Z"},"languages":{"value":["python"],"source":"github.language+pyproject.toml","observed_at":"2026-07-27T00:00:53.281Z"},"has_docker":{"value":true,"source":"dockerfile:Dockerfile","observed_at":"2026-07-27T00:00:53.281Z"},"license_spdx":{"value":"MIT","source":"github.license","observed_at":"2026-07-27T00:00:53.281Z"}},"decision_facts":{"hosting":null,"pricing":null,"requirements":null,"constraints":null,"when_to_use":["When you need a comprehensive suite that includes more than 205 security tools and 17 specialist agents.","For projects requiring exploitation techniques covered by the OWASP Top 10, leveraging the platform's 60 SPA-aware probes."],"when_not_to_use":["If your requirements do not include offensive-security capabilities or exploit chaining.","When you want to avoid MIT-licensed open-source code and prefer proprietary solutions without sharing obligations."],"source":"enrich:decision_facts","observed_at":"2026-07-17T12:34:36.983Z"},"constraint_facets":null,"decision_summary":[{"label":"Adopt for","value":"Pentest-ai is an offensive-security platform featuring over 200 security tools and agents for various security tasks including exploit chaining and osint, licensed under MIT."}]}}