Try “Claude Code skills”, “MCP servers for Cursor” or “Codex” · Esc to close

Pentest AI Agents 🤖 Agent Open source

50 Claude Code subagents for authorized penetration testing, scope-gated

Subagent collections · Open source ★ 2.3k · +31 this week · MIT · updated 2026-08-16

7.4editor score
Visit Pentest AI Agents ↗
GitHub stars
2.3k
Stars this week
+31
Forks
434
Licence
MIT
Last push
2026-08-16
Maintainer
0xSteph
Installcurl -fsSL https://raw.githubusercontent.com/0xSteph/pentest-ai-agents/main/install.sh | bash

Third-party subagents & agents run with your permissions. Read the source before installing, and prefer pinned versions.

Works with

About Pentest AI Agents

What it does

pentest-ai-agents turns Claude Code into an offensive-security research assistant for authorized penetration testing. It installs around fifty subagents, each carrying deep domain knowledge in one area (recon and OSINT, web and API testing, Active Directory, cloud, containers, mobile, wireless, social engineering, credential attacks, LLM red teaming, plus defensive analysis, forensics, and reporting). You describe a task and Claude routes it to the right specialist, which produces methodology, prioritised targets, and concrete next commands, with MITRE ATT&CK mappings where relevant.

What is inside

Agents are split into Tier 1 (advisory: you paste tool output and run the tools yourself) and Tier 2 (execution-capable: they can compose and run commands, but only after you declare an authorized scope, which every target is validated against, and Claude shows each command for approval). A shared scope-guard file enforces a hard-refusal list covering denial of service, mass scanning, unattended worms, false-flag operations, and safety-of-life systems, and CI checks that every Bash-capable agent carries the scope block. Supporting scripts include a persistent SQLite findings database, a session handoff report, a tool-availability doctor, and an optional installer for the underlying CLI tools. A companion MCP server project exists separately for automated pipelines.

Works with

Claude Code (Pro or Max). The agents are plain Markdown system prompts, so they can also run against any Anthropic-compatible endpoint or be copied into another runner.

How to install

curl -fsSL https://raw.githubusercontent.com/0xSteph/pentest-ai-agents/main/install.sh | bash

Maintenance and safety

MIT licensed and actively maintained, with a SHA-pinned CI validator. The README is explicit that the toolkit is for authorized testing only and requires signed rules of engagement and a defined scope; a disclaimer spells out the terms. Tier 2 agents run real security tooling, so authorization and scope discipline matter.

Who should use it

Penetration testers and red teamers with written authorization who want a structured specialist bench inside Claude Code.

pentest offensive-security red-team mitre-attack subagents

Pros

  • Broad specialist coverage with MITRE ATT&CK mappings and a findings DB
  • Tier system, scope validation, per-command approval, and CI-enforced scope guard

Cons

  • Requires written authorization and defined scope; Tier 2 runs real tools
  • Claude Pro or Max needed for full use

Similar subagents & agents

All subagent collections →

wshobson/agents 🤖 AgentFree

Large plugin marketplace of specialist subagents, skills and commands for Claude Code

★ 40k · +192 this week

Power Platform Skills 🤖 AgentOpen source

Official Microsoft plugins for building Power Platform apps, pages and flows with Claude Code or Copilot

★ 947 · +19 this week

8.0 Visit ↗

Popular searches