Favicon of pentest-agents

pentest-agents Skill

AI Agent SkillCode & Developer ToolsPythonOpen source

pentest-agents is a Python AI agent skill for Cursor, Windsurf, VS Code with uvx/pip, git clone. Bug bounty agent framework for Claude Code, Codex, Gemini, Cursor, Windsurf, Copilot, and OpenClaw — 48 agents, 26 commands, 19 CLI tools, 2 MCP servers, autonomous hunt loops, explo.

How to use pentest-agents Skill

Install or run

git clone https://github.com/H-mmer/pentest-agents-suite
cd pentest-agents-suite/pentest-agents/providers/codex
codex                       # or: cd ../gemini && gemini, etc.

Client configuration

{
  "servers": {
    "bounty-platforms": {
      "type": "stdio",
      "command": "uv",
      "args": [
        "run",
        "--with",
        "mcp",
        "../../mcp-bounty-server/server.py"
      ]
    },
    "writeup-search": {
      "type": "stdio",
      "command": "uv",
      "args": [
        "run",
        "--with",
        "mcp",
        "../../mcp-writeup-server/server.py"
      ]
    }
  }
}

Compatible clients

CursorWindsurfVS CodeCodex

What is pentest-agents Skill?

pentest-agents is a Python AI agent skill for Cursor, Windsurf, VS Code with uvx/pip, git clone. Bug bounty agent framework for Claude Code, Codex, Gemini, Cursor, Windsurf, Copilot, and OpenClaw — 48 agents, 26 commands, 19 CLI tools, 2 MCP servers, autonomous hunt loops, explo. This profile combines repository metadata with install, compatibility, and usage signals so developers can quickly decide whether it fits their agent workflow before opening the source repository.

Trust signal
80/100
Maintenance signal
95/100
Adoption signal
71/100

Automated repository signals based on public metadata such as recency, license, installation evidence, and adoption. These are not a security audit or endorsement.

Key capabilities

  • Reusable instructions support
  • Includes SKILL.md support
  • Shell commands support
  • Browser use support
  • Document generation support
  • OpenAI provider support
  • Anthropic provider support

Available tools

list_platforms
search_writeups

Technical details

Install or run pentest-agents using uvx/pip. Check H-mmer/pentest-agents for the latest setup command.

uvx/pipgit cloneCursorWindsurfVS CodeCodexSSE
  • Built for Python
  • Built for Rust
  • Install or run with uvx/pip
  • Install or run with git clone
  • Works with Cursor
  • Works with Windsurf
  • Works with VS Code
  • Works with Codex

Requirements and access

PythonRustAPI key requiredOAuthDatabase accessAPI key requiredOAuthDatabase accessNetwork access

Security and permissions

Review permissions before connecting any MCP server to an agent. Pay special attention to whether it can read local files, write data, call external services, or perform destructive actions.

Destructive actionsWrite actionsDatabase accessNetwork accessCredentials requiredCan write or update dataMay support destructive actionsAPI key required authenticationHosted or remote

When to use pentest-agents Skill

  • Use it for reusing agent instructions, scripts, and references.
  • Use it for agent skills workflows.
  • Use it for coding workflows.
  • Use it for data workflows.
  • Use it for cursor users.

Built with

PythonRustuvx/pipgit cloneCursorWindsurfVS CodeCodexSSE

Explore related resources

Frequently asked questions

What is pentest-agents?

pentest-agents is a Python AI agent skill for Cursor, Windsurf, VS Code with uvx/pip, git clone. Bug bounty agent framework for Claude Code, Codex, Gemini, Cursor, Windsurf, Copilot, and OpenClaw — 48 agents, 26 commands, 19 CLI tools, 2 MCP servers, autonomous hunt loops.

Who is pentest-agents best for?

pentest-agents is best for reusing agent instructions, scripts, and references, agent skills workflows, coding workflows, data workflows, cursor users.

How do I install pentest-agents?

Install or run pentest-agents using uvx/pip. Check pentest-agents for the latest setup command.

Is pentest-agents actively maintained?

pentest-agents may need a closer maintenance check before production use.

Share:

Stars
725
Forks
136
Last commit
1 month ago
Repository age
4 months
License
Unknown

Auto-fetched from GitHub.

Similar to pentest-agents