Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacyΒ© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
pentx-vapt-skill β€” Open-source AI-powered 5-phase VAPT pentest agent β€” recon/scan/vuln/exploit/report with PoC | Kitploit
Tools/GitHubGitHub/yashas-13/pentx-vapt-skill
ReconnaissanceVulnerability ScannersPort ScanningVulnerability AnalysisExploitationInformation GatheringWeb SecurityPenetration TestingSubdomain Enumeration
GitHubyashas-13/pentx-vapt-skill

pentx-vapt-skill

Open-source AI-powered 5-phase VAPT pentest agent β€” recon/scan/vuln/exploit/report with PoC

2861 month agoNot yet reviewed

Most Popular

View all β†’

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools β†’
Share
View Repository

Pentx Logo

πŸ”₯ Pentx β€” Advanced VAPT Skill

AI-Powered Penetration Testing Agent for Pi Coding Agent

License Python Phase Tools Status

Pentx is an advanced 5-phase VAPT (Vulnerability Assessment & Penetration Testing) skill that executes full penetration testing and generates detailed Proof-of-Concept for every finding.

GitHub Stars GitHub Forks


πŸ“Έ Screenshots

Tool CheckScan ProgressReport
ToolsScanReport

πŸš€ Features

β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚  βœ… 5-Phase Pipeline    β”‚  Recon β†’ Scan β†’ Vuln β†’ Exploit β†’ Report  β”‚
β”‚  βœ… 30+ Tools           β”‚  nmap, nuclei, sqlmap, ffuf, owscan...  β”‚
β”‚  βœ… Auto-Install        β”‚  Missing tools via onex (370+ tools)     β”‚
β”‚  βœ… PoC Generation      β”‚  Every finding with proof-of-concept     β”‚
β”‚  βœ… Multi-Format Reportsβ”‚  HTML, Markdown, JSON, CSV, SARIF        β”‚
β”‚  βœ… Non-Standard Ports  β”‚  Full support for custom ports           β”‚
β”‚  βœ… Cross-Validation    β”‚  Two-source confirmation for accuracy    β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜

⚑ Quick Start

1. Install Dependencies

# Auto-install all tools via onex
cd ~/.pi/agent/skills/pentx/scripts
python3 lib/tool_manager.py auto

# Or manually check
bash tools_check.sh

2. Run Full VAPT Scan

python3 pentx.py https://target.com:4280/

3. Run Single Phase

python3 pentx.py https://target.com --phase 1   # Recon only
python3 pentx.py https://target.com --phase 3   # Vuln assessment
python3 pentx.py https://target.com --phase 5   # Report only

4. Fast Mode

python3 pentx.py https://target.com --fast      # Skip nmap + nuclei
python3 pentx.py https://target.com --no-exploit # Read-only

πŸ”§ Tool Stack

ToolPurposeRequired
nmapPort/service/vuln scanningβœ…
nucleiTemplate-based vuln scanningβœ…
httpxLive host probingβœ…
sqlmapSQL injection automationβœ…
ffufDirectory/file fuzzingβœ…
niktoWeb server scanning⚠️
owscanWeb vulnerability scanner⚠️
amassSubdomain enumeration⚠️

πŸ“Š 5-Phase Workflow

β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚                                                                      β”‚
β”‚  β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”  β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”  β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”  β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”  β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚  β”‚   PHASE 1   β”‚β†’ β”‚   PHASE 2   β”‚β†’ β”‚   PHASE 3   β”‚β†’ β”‚   PHASE 4   β”‚β†’ β”‚   PHASE 5   β”‚
β”‚  β”‚  Recon      β”‚  β”‚  Scan       β”‚  β”‚  Vuln       β”‚  β”‚  Exploit    β”‚  β”‚  Report     β”‚
β”‚  β”‚             β”‚  β”‚             β”‚  β”‚             β”‚  β”‚             β”‚  β”‚             β”‚
β”‚  β”‚ β€’ Subdomain β”‚  β”‚ β€’ Nmap      β”‚  β”‚ β€’ SQLi      β”‚  β”‚ β€’ SQLi Exp  β”‚  β”‚ β€’ HTML      β”‚
β”‚  β”‚ β€’ Tech Stackβ”‚  β”‚ β€’ Nikto     β”‚  β”‚ β€’ LFI/XSS   β”‚  β”‚ β€’ Auth Test β”‚  β”‚ β€’ Markdown  β”‚
β”‚  β”‚ β€’ Nuclei    β”‚  β”‚ β€’ FFUF      β”‚  β”‚ β€’ OWScan    β”‚  β”‚ β€’ PoC Gen   β”‚  β”‚ β€’ JSON/CSV  β”‚
β”‚  β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜  β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜  β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜  β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜  β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
β”‚                                                                      β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜

πŸ› οΈ Integration

onex Package Manager

# Check tool status
python3 lib/tool_manager.py status

# Auto-install all missing tools
python3 lib/tool_manager.py auto

# Install specific tool
python3 lib/tool_manager.py install nikto

# List all 370+ tools
python3 lib/tool_manager.py list

owscan Web Scanner

# Run owscan standalone
php tools/owscan/owscan.php -u https://target.com:4280/

# Via wrapper (auto-parses to pentx format)
python3 lib/owscan_wrapper.py https://target.com:4280/ output/owscan

πŸ“ Output Structure

output/
β”œβ”€β”€ phase1-recon/        # Recon assets, live hosts, nuclei, findings
β”œβ”€β”€ phase2-scan/         # Nmap XML, ffuf, nikto, findings
β”œβ”€β”€ phase3-vuln/         # SQLi, LFI/XSS/SSRF PoCs + findings
β”œβ”€β”€ phase4-exploit/      # PoC artifacts, banner verification
β”œβ”€β”€ report.html          # HTML report (exec + PoC cards)
β”œβ”€β”€ report.md            # Full technical Markdown report
β”œβ”€β”€ exec-summary.md      # Leadership summary
β”œβ”€β”€ findings-merged.json # Machine-readable findings
β”œβ”€β”€ findings.csv         # CSV for spreadsheets
β”œβ”€β”€ findings.sarif       # SARIF for CI/CD
└── poc-full/            # Per-finding PoC .txt artifacts

🎯 PoC Format Example

═══════════════════════════════════════════════════════════════
  SQL Injection on 'id' β€” https://target.com:4280/page
═══════════════════════════════════════════════════════════════

Request:
  GET /page?id=1'+AND+1=1-- HTTP/1.1
  Host: target.com:4280

Response:
  HTTP/1.1 200 OK
  [Page content with true condition]

Severity: Critical (CVSS 9.8)
Remediation: Use parameterized queries / prepared statements.
═══════════════════════════════════════════════════════════════

πŸ”’ Safety Rules

RuleDescription
⚠️ AuthorizationOnly run against authorized targets
πŸ“– Read-onlyDefault mode, use --no-exploit
🚫 No DestructiveNo DoS, no data destruction
⏱️ TimeoutsAll probes use short timeouts
πŸ” Safe SQLi--batch mode, limited level/risk

πŸ“š CLI Reference

python3 pentx.py <target> [output] [options]

Options:
  --phase N           Run single phase (1-5)
  --no-exploit        Skip Phase 4 (exploitation)
  --fast              Skip nmap + nuclei, fast scan
  --skip-nmap         Skip nmap scan
  --skip-nuclei       Skip nuclei scan
  --target-port N     Override target port
  --timeout N         Per-phase timeout (default: 300s)
  --check             Check tool availability
  --report <dir>      Regenerate report from output dir
  --tools <cmd>       Tool manager: status|install|list|auto
  --owscan <url>      Run owscan standalone

πŸ† Sponsored By

SponsorType
TermuxCommunity
OnexTool Provider
Gameye98Scanner Dev

Support Pentx β€” GitHub Sponsors | PayPal


πŸ™ Credits

Download Tool