Pentest AI Agents 🤖 Agent Open source
50 Claude Code subagents for authorized penetration testing, scope-gated
- GitHub stars
- 2.3k
- Stars this week
- +31
- Forks
- 434
- Licence
- MIT
- Last push
- 2026-08-16
- Maintainer
- 0xSteph
curl -fsSL https://raw.githubusercontent.com/0xSteph/pentest-ai-agents/main/install.sh | bashThird-party subagents & agents run with your permissions. Read the source before installing, and prefer pinned versions.
Works with
About Pentest AI Agents
What it does
pentest-ai-agents turns Claude Code into an offensive-security research assistant for authorized penetration testing. It installs around fifty subagents, each carrying deep domain knowledge in one area (recon and OSINT, web and API testing, Active Directory, cloud, containers, mobile, wireless, social engineering, credential attacks, LLM red teaming, plus defensive analysis, forensics, and reporting). You describe a task and Claude routes it to the right specialist, which produces methodology, prioritised targets, and concrete next commands, with MITRE ATT&CK mappings where relevant.
What is inside
Agents are split into Tier 1 (advisory: you paste tool output and run the tools yourself) and Tier 2 (execution-capable: they can compose and run commands, but only after you declare an authorized scope, which every target is validated against, and Claude shows each command for approval). A shared scope-guard file enforces a hard-refusal list covering denial of service, mass scanning, unattended worms, false-flag operations, and safety-of-life systems, and CI checks that every Bash-capable agent carries the scope block. Supporting scripts include a persistent SQLite findings database, a session handoff report, a tool-availability doctor, and an optional installer for the underlying CLI tools. A companion MCP server project exists separately for automated pipelines.
Works with
Claude Code (Pro or Max). The agents are plain Markdown system prompts, so they can also run against any Anthropic-compatible endpoint or be copied into another runner.
How to install
curl -fsSL https://raw.githubusercontent.com/0xSteph/pentest-ai-agents/main/install.sh | bash
Maintenance and safety
MIT licensed and actively maintained, with a SHA-pinned CI validator. The README is explicit that the toolkit is for authorized testing only and requires signed rules of engagement and a defined scope; a disclaimer spells out the terms. Tier 2 agents run real security tooling, so authorization and scope discipline matter.
Who should use it
Penetration testers and red teamers with written authorization who want a structured specialist bench inside Claude Code.
Pros
- Broad specialist coverage with MITRE ATT&CK mappings and a findings DB
- Tier system, scope validation, per-command approval, and CI-enforced scope guard
Cons
- Requires written authorization and defined scope; Tier 2 runs real tools
- Claude Pro or Max needed for full use
Similar subagents & agents
All subagent collections →wshobson/agents 🤖 AgentFree
Large plugin marketplace of specialist subagents, skills and commands for Claude Code
Awesome Claude Code Subagents (VoltAgent) 🤖 AgentFree
160+ production-ready Claude Code subagents organised by category
Power Platform Skills 🤖 AgentOpen source
Official Microsoft plugins for building Power Platform apps, pages and flows with Claude Code or Copilot
Awesome Claude Agents 🤖 AgentFree
An orchestrated dev team of Claude Code subagents with a tech-lead coordinator
Contains Studio Agents 🤖 AgentFree
Subagents for a rapid product studio: engineering, design, marketing and ops
Awesome Codex Subagents 🤖 AgentOpen source
175+ Codex-native .toml subagents across 13 development categories