
Open-source AI-powered 5-phase VAPT pentest agent β recon/scan/vuln/exploit/report with PoC

Pentx is an advanced 5-phase VAPT (Vulnerability Assessment & Penetration Testing) skill that executes full penetration testing and generates detailed Proof-of-Concept for every finding.
| Tool Check | Scan Progress | Report |
|---|---|---|
![]() | ![]() | ![]() |
βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
β β
5-Phase Pipeline β Recon β Scan β Vuln β Exploit β Report β
β β
30+ Tools β nmap, nuclei, sqlmap, ffuf, owscan... β
β β
Auto-Install β Missing tools via onex (370+ tools) β
β β
PoC Generation β Every finding with proof-of-concept β
β β
Multi-Format Reportsβ HTML, Markdown, JSON, CSV, SARIF β
β β
Non-Standard Ports β Full support for custom ports β
β β
Cross-Validation β Two-source confirmation for accuracy β
βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
# Auto-install all tools via onex
cd ~/.pi/agent/skills/pentx/scripts
python3 lib/tool_manager.py auto
# Or manually check
bash tools_check.sh
python3 pentx.py https://target.com:4280/
python3 pentx.py https://target.com --phase 1 # Recon only
python3 pentx.py https://target.com --phase 3 # Vuln assessment
python3 pentx.py https://target.com --phase 5 # Report only
python3 pentx.py https://target.com --fast # Skip nmap + nuclei
python3 pentx.py https://target.com --no-exploit # Read-only
| Tool | Purpose | Required |
|---|---|---|
| Port/service/vuln scanning | β | |
| Template-based vuln scanning | β | |
| Live host probing | β | |
| SQL injection automation | β | |
| Directory/file fuzzing | β | |
| Web server scanning | β οΈ | |
| Web vulnerability scanner | β οΈ | |
| Subdomain enumeration | β οΈ |
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
β β
β βββββββββββββββ βββββββββββββββ βββββββββββββββ βββββββββββββββ βββββββββββββββ
β β PHASE 1 ββ β PHASE 2 ββ β PHASE 3 ββ β PHASE 4 ββ β PHASE 5 β
β β Recon β β Scan β β Vuln β β Exploit β β Report β
β β β β β β β β β β β
β β β’ Subdomain β β β’ Nmap β β β’ SQLi β β β’ SQLi Exp β β β’ HTML β
β β β’ Tech Stackβ β β’ Nikto β β β’ LFI/XSS β β β’ Auth Test β β β’ Markdown β
β β β’ Nuclei β β β’ FFUF β β β’ OWScan β β β’ PoC Gen β β β’ JSON/CSV β
β βββββββββββββββ βββββββββββββββ βββββββββββββββ βββββββββββββββ βββββββββββββββ
β β
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
# Check tool status
python3 lib/tool_manager.py status
# Auto-install all missing tools
python3 lib/tool_manager.py auto
# Install specific tool
python3 lib/tool_manager.py install nikto
# List all 370+ tools
python3 lib/tool_manager.py list
# Run owscan standalone
php tools/owscan/owscan.php -u https://target.com:4280/
# Via wrapper (auto-parses to pentx format)
python3 lib/owscan_wrapper.py https://target.com:4280/ output/owscan
output/
βββ phase1-recon/ # Recon assets, live hosts, nuclei, findings
βββ phase2-scan/ # Nmap XML, ffuf, nikto, findings
βββ phase3-vuln/ # SQLi, LFI/XSS/SSRF PoCs + findings
βββ phase4-exploit/ # PoC artifacts, banner verification
βββ report.html # HTML report (exec + PoC cards)
βββ report.md # Full technical Markdown report
βββ exec-summary.md # Leadership summary
βββ findings-merged.json # Machine-readable findings
βββ findings.csv # CSV for spreadsheets
βββ findings.sarif # SARIF for CI/CD
βββ poc-full/ # Per-finding PoC .txt artifacts
βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
SQL Injection on 'id' β https://target.com:4280/page
βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
Request:
GET /page?id=1'+AND+1=1-- HTTP/1.1
Host: target.com:4280
Response:
HTTP/1.1 200 OK
[Page content with true condition]
Severity: Critical (CVSS 9.8)
Remediation: Use parameterized queries / prepared statements.
βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
| Rule | Description |
|---|---|
| β οΈ Authorization | Only run against authorized targets |
| π Read-only | Default mode, use --no-exploit |
| π« No Destructive | No DoS, no data destruction |
| β±οΈ Timeouts | All probes use short timeouts |
| π Safe SQLi | --batch mode, limited level/risk |
python3 pentx.py <target> [output] [options]
Options:
--phase N Run single phase (1-5)
--no-exploit Skip Phase 4 (exploitation)
--fast Skip nmap + nuclei, fast scan
--skip-nmap Skip nmap scan
--skip-nuclei Skip nuclei scan
--target-port N Override target port
--timeout N Per-phase timeout (default: 300s)
--check Check tool availability
--report <dir> Regenerate report from output dir
--tools <cmd> Tool manager: status|install|list|auto
--owscan <url> Run owscan standalone
| Sponsor | Type |
|---|---|
| Community | |
| Tool Provider | |
| Scanner Dev |
Support Pentx β GitHub Sponsors | PayPal