Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.
-
Updated
Sep 5, 2026 - Python
Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.
Shannon is an AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes real exploits to prove vulnerabilities before they reach production.
HexStrike AI MCP Agents is an advanced MCP server that lets AI agents (Claude, GPT, Copilot, etc.) autonomously run 150+ cybersecurity tools for automated pentesting, vulnerability discovery, bug bounty automation, and security research. Seamlessly bridge LLMs with real-world offensive security capabilities.
The system of action for AI-native cybersecurity—where intent becomes governed execution, evidence becomes operational memory, and every operation improves the next.
Open-source AI-powered offensive security harness for automated penetration testing.
Open-source AI pentester that proves every finding. Machine oracles re-run each exploit; verified bugs ship a proof capsule you can replay yourself.
Autonomous AI-powered security scanning platform — CLI scanner, web dashboard, and one-command Docker deployment
Cyberful is an open-source AI Red Team for discovering, exploiting, verifying, and remediating vulnerabilities.
Shannon-Uncontained. A Docker-free, black‑box‑first fork that treats AI as a fallible witness rather than an oracle: treats uncertainty as a first class citizen via EQBSL epistemic bookkeeping, and agentic recon/analysis/synthesis tuned for “paste url -> pwn box -> ???? -> profit”
open-source pentest management built to be operated by an AI agent
The autonomous pentester that proves its findings — AI-driven, evidence-first, behind-login.
The security engine of your Agentic Company
Mergen is an MCP server that gives your AI a real red team brain. It doesn't just run tools, it picks the right ones, chains them together, and actually makes sense of the output. Built by pentesters, for pentesters who are tired of babysitting scripts.
Semantic Stealth Attacks & Symbolic Prompt Red Teaming on GPT and other LLMs.
RAG Poisoning Lab — Educational AI Security Exercise
Zentra is an open source CLI agent harness tool designed to assist with SAST and DAST on your application
A terminal interface to swarm of AI agents to assist during a penetration testing engagement given a RoE.md(Rules of Engagement)
AI-Pentesting-Tool is an educational workflow for using an AI agent with Kali tooling through MCP (Model Context Protocol) in VS Code insiders for white-box and black-box pentesting..
Automate authorized pentesting with LLMs, combining scanning, RAG, and exploit research for faster target analysis, vuln discovery, and reporting
🤖 Build advanced AI agents with a collection of production-ready applications using modern frameworks for single and multi-agent systems.
To associate your repository with the ai-penetration-testing topic, visit your repo's landing page and select "manage topics."