Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
pentest-copilot — AI-driven penetration testing agent that connects to a Kali box, autonomously runs security tools, analyzes results, and iterates through browser-based workflows. | Kitploit
Tools/GitHubGitHub/bugbasesecurity/pentest-copilot
Penetration Testing FrameworksReconnaissanceWeb Proxies & InterceptionScripting & AutomationWeb Application ExploitationCTFPenetration TestingCommand and Control
Learning & Education
Red Teaming
AI Security
GitHubbugbasesecurity/pentest-copilot

pentest-copilot

AI-driven penetration testing agent that connects to a Kali box, autonomously runs security tools, analyzes results, and iterates through browser-based workflows.

View RepositoryWebsite
1.5k2861151 month agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Pentest Copilot Banner

Pentest Copilot

GitHub License GitHub Repo stars GitHub forks

An open-source, AI-driven penetration testing agent. Connects to a Kali attack box, runs tools autonomously, analyzes results, and iterates. You describe the target. It does the rest.

Built for real-world engagements, boot2root boxes, and CTFs.

In Action

Pentest Copilot performing an auth bypass in OWASP Juice Shop:

Watch it on YouTube

Star History

Star History Chart

What It Does

  • Agentic execution - the AI runs commands directly on the attack box, reads output, decides next steps, and loops. Up to 25 iterations per turn, no manual nudging required.
  • 16 agent tools - bash, Python scripts, tool installation, shell management, Google search, subagent spawning, Burp Suite (proxy history, Repeater, Intruder, Collaborator), and browser automation.
  • 100+ capabilities - curated registry of security tools and Python packages across 7 categories (network, rev, pwn, crypto, forensics, stego, core). Select what you need, the agent installs the rest.
  • Burp Suite integration - proxy history viewer, send requests to Repeater/Intruder, Collaborator for out-of-band testing. All accessible to the agent and through the UI.
  • Browser agent - real browser automation via Magnitude. Test login flows, fill forms, interact with JavaScript-heavy apps. Optionally proxy traffic through Burp. In Docker mode, watch the browser via the built-in VNC stream; in developer mode, the browser opens on your local desktop.
  • VPN management - upload .ovpn/.conf bundles with referenced certificates, keys, or credentials and connect/disconnect from the browser. Multiple simultaneous connections supported.
  • Subagent parallelism - spawn background agents to run tasks concurrently (e.g. directory brute-force + subdomain enum at the same time).
  • Safety checks - dangerous commands (recursive deletes, device writes, fork bombs) require explicit approval, even in auto-run mode.
  • Bring your own model - OpenAI, Anthropic (API key or OAuth), Google, Mistral, or any OpenAI-compatible endpoint.
  • Use existing local subscriptions - Pentest Copilot can use an authenticated Codex CLI in Docker or host mode, and Claude Code in host/developer mode, as normal inference providers while retaining its own tool and consent loop.

Quick Start

git clone https://github.com/bugbasesecurity/pentest-copilot.git
cd pentest-copilot
./run.sh start

Open http://localhost:3000, register, and start a session.

run.sh waits for the frontend, backend, MongoDB, and Redis to be ready before reporting success. If startup fails, it prints the affected container status and recent logs. Configure and assign a model under Settings -> Models after the first start.

On Windows, run Pentest Copilot inside WSL2 with Docker Desktop's WSL integration enabled. Native PowerShell and Windows SSH work hosts are not supported because workspace commands require a POSIX shell. For reliable file permissions and performance, clone the repository into the WSL filesystem, not under /mnt/c.

Codex and Claude subscription inference

Settings -> Models detects authenticated Codex and Claude Code CLIs. Authenticate once on the machine that runs the CLI:

codex login
claude auth login

Then select Use Codex or Use Claude Code. The official CLI owns login, refresh, and subscription entitlement handling; Pentest Copilot does not copy or replay OAuth tokens. Subscription transports receive the same conversation history and function schemas as API providers and return the same assistant/tool call contract, so Pentest Copilot continues to execute tools and consent checks.

The Docker backend includes the Linux Codex CLI and mounts only the host's file-based ~/.codex/auth.json, following Codex's documented headless/Docker login transfer flow. Set CODEX_AUTH_FILE before docker compose up if your credential file lives elsewhere. The CLI may refresh that file during normal use; never commit or share it. Host Keychain-only credentials and Claude Code remain available only in developer/host mode until a host inference bridge is configured. Claude subscription use is local CLI control and must comply with Anthropic's current third-party product and subscription terms.

Current first-class model families include GPT-5.6 Sol/Terra/Luna, Claude Fable/Opus/Sonnet 5, and Kimi K3 (direct Moonshot API or OpenRouter).

Workspace-scoped SSH profiles

In Docker mode, Pentest Copilot mounts the host's ~/.ssh and ~/keys directories read-only. Each workspace can select a concrete Host alias from ~/.ssh/config under Connection. Every session in that workspace uses the same host and work folder without copying private keys into MongoDB. Set HOST_SSH_DIR or HOST_SSH_KEYS_DIR before starting Docker when those directories live elsewhere.

Use named aliases rather than wildcard-only entries:

Host lab-box
  HostName 10.10.10.10
  User root
  IdentityFile ~/.ssh/lab-box.pem

run.sh handles config file generation, Docker builds, and container orchestration. Use ./run.sh start -q to reuse the previous launch mode and skip prompts on subsequent runs.

For the complete OS, Docker, SSH, VPN, proxy, permissions, recovery, and deployment scenario matrix, see Setup and Troubleshooting.

Download Tool