Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
autopentest-ai — Agentic Pentesting MCP server that discovers, exploits, and reports web application vulnerabilities. | Kitploit
Tools/GitHubGitHub/bhavsec/autopentest-ai
Penetration Testing FrameworksReconnaissanceVulnerability ScannersExploit FrameworksWeb Application ExploitationInformation GatheringWAF BypassWeb SecurityPenetration TestingLearning & EducationCrawler
21053247 months agoReviewed by Kitploit
GitHubbhavsec/autopentest-ai

autopentest-ai

Agentic Pentesting MCP server that discovers, exploits, and reports web application vulnerabilities.

View Repository

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

WSTG Tests PortSwigger Guides MCP Tools Security Tools WAF Bypass Evidence Based License

AutoPentest

An agentic pentesting MCP server that automates web application penetration testing using the full OWASP Web Security Testing Guide and PortSwigger Web Security Academy technique references.

Point it at a target — it crawls your app, maps every endpoint, then spawns role-specialized agents (Scout, Analyzer, Exploiter, Reporter) to test for XSS, SQLi, SSRF, SSTI, IDOR and more. No false positives — every finding is backed by real, reproducible evidence with quality gates enforcing proof at every phase. Includes 31 PortSwigger technique guides, adaptive WAF evasion for 12 vendors, cross-phase vulnerability chaining, and risk-weighted endpoint prioritization. Run it with Claude Code, the API, or go fully offline using Ollama models.

Think of it as: A senior pentester's methodology encoded into an MCP server — 109 OWASP tests, 31 PortSwigger attack technique guides, 68+ MCP tools, 27 security tools, 4 specialized agent roles, 7 structured phases, automated quality assurance, and a zero-context final review.


AutoPentest CLI Output

Table of Contents

  • Why AutoPentest?
  • Architecture
  • Features
  • Agent Role System
  • Quick Start
  • Usage
  • Testing Phases
  • Security Tools
  • WSTG Knowledge Base
  • PortSwigger Technique Guides
  • Quality Assurance System
  • Benchmarking
  • Example Report
  • Configuration
  • Multi-Domain Testing
  • Crash Recovery
  • Project Structure
  • Requirements
  • FAQ
  • Disclaimer

Why AutoPentest?

Manual penetration testing is thorough but slow. Automated scanners are fast but shallow. AutoPentest bridges the gap:

CapabilityManual PentestAutomated ScannerAutoPentest
Full OWASP WSTG coverageDepends on testerPartial109 tests
Business logic testingYesNoYes
Multi-step exploitationYesLimitedYes
Vulnerability chainingYesNoYes
Evidence-based findingsYesTemplate outputReproducible curl commands
Consistent qualityVariesYesPhase gates + Final Judge
SpeedDaysMinutesHours
Cross-domain auth (SSO/OIDC)Manual setupUsually failsAutomated handling

Architecture

┌─────────────────────────────────────────────────────────────┐
│                  LLM Orchestrator (Claude)                  │
│                                                             │
│  Reads CLAUDE.md workflow, manages phases,                  │
│  spawns role-specialized subagents                          │
└──────────┬──────────┬──────────┬──────────┬─────────────────┘
           │          │          │          │
     ┌─────▼────┐ ┌───▼─────┐ ┌──▼───────┐ ┌▼─────────┐
     │  Scout   │ │Analyzer │ │Exploiter │ │ Reporter │
     │  (recon) │ │ (vuln   │ │ (proof)  │ │ (QA /    │
     │          │ │  disc.) │ │          │ │  judge)  │
     └──────────┘ └─────────┘ └──────────┘ └──────────┘
           │          │          │          │
           │     MCP  │          │     MCP  │
           ▼          ▼          ▼          ▼
┌──────────────────────────┐  ┌──────────────────────┐
│  WSTG MCP Server         │  │  Playwright MCP      │
│  (68+ tools)             │  │  (Browser Testing)   │
│                          │  │                      │
│  ◦ 109 WSTG tests        │  │  ◦ DOM XSS proof     │
│  ◦ 31 technique guides   │  │  ◦ Clickjacking      │
│  ◦ Task tree             │  │  ◦ JS-rendered auth  │
│  ◦ Knowledge graph       │  └──────────────────────┘
│  ◦ WAF evasion           │
│  ◦ Tool output parser    │
│  ◦ Results verification  │  docker exec
│  ◦ Context compression   │       │
│  ◦ Endpoint priority     │       ▼
│  ◦ Quality gates         │  ┌──────────────────────┐
│  ◦ Report generation     │  │  autopentest-tools   │
└──────────────────────────┘  │  (Docker Container)  │
                              │                      │
                              │  27 security tools:  │
                              │  nuclei, sqlmap,     │
                              │  dalfox, katana,     │
                              │  ffuf, nmap ...      │
                              │                      │
                              │  Burp proxy          │
                              │  passthrough         │
                              └──────────────────────┘

How it works:

  1. Claude Code reads CLAUDE.md for the complete pentest methodology and orchestrates the 7-phase workflow
  2. Role-specialized subagents (Scout, Analyzer, Exploiter, Reporter) execute focused tasks with dedicated prompt templates, tool guidance, and anti-patterns
  3. WSTG MCP Server (68+ tools) provides OWASP test procedures, 31 PortSwigger technique guides, hierarchical task tree, knowledge graph, WAF evasion, endpoint prioritization, results verification, context compression, quality gates, and report generation
  4. Docker Container runs all 27 security tools — traffic optionally routes through Burp Suite for passive monitoring
  5. Playwright MCP handles browser-based testing (DOM XSS, clickjacking, JS-rendered login pages)

Features

Comprehensive OWASP Coverage

  • 109 WSTG test cases across 12 categories — from information gathering to API testing
  • Each test includes step-by-step CLI procedures, context-specific payloads, detection criteria, and severity rubrics
  • Tests are prioritized (MUST/SHOULD) with conditional triggers so nothing relevant is skipped

31 PortSwigger Attack Technique Guides

  • Sourced from PortSwigger Web Security Academy — detection methods, exploitation techniques, payloads, cheat sheets, and WAF bypass patterns
  • Organized by vulnerability class (SQLi, XSS, SSRF, JWT, OAuth, etc.) for direct use during testing
  • Integrated into every testing phase — agents automatically load the relevant technique guide before testing each vulnerability class
  • Database/platform-specific payload tables (Oracle vs MySQL vs PostgreSQL vs MSSQL for SQLi, Jinja2 vs Twig vs Freemarker for SSTI, etc.)
  • WAF bypass patterns organized by bypass level (basic → intermediate → advanced)

27 Pre-Configured Security Tools

  • All tools pre-installed in a single Docker image — make setup and you're ready
  • Tools organized by phase: discovery, injection testing, authentication, cryptography, API testing
  • Automatic Burp Suite proxy integration for passive traffic monitoring
Download Tool