Description
AutoPentest AI is an agentic penetration testing system that automates web application security testing using the OWASP Web Security Testing Guide (WSTG). It crawls target applications, maps endpoints, and spawns parallel agents to test for vulnerabilities including XSS, SQL injection, SSRF, SSTI, and IDOR. The system bundles pre-configured security tools such as nuclei, sqlmap, dalfox, katana, ffuf, and nmap within a Docker container, and integrates Playwright for browser-based testing of DOM XSS, clickjacking, and JavaScript-rendered authentication flows.
🔬 Playground
Try AutoPentest AI live in the browser with security context.
Installation
git clone https://github.com/bhavsec/autopentest-ai Claude Desktop Configuration
Add this configuration to your Claude Desktop config file to enable this MCP server:
Config file location: ~/Library/Application Support/Claude/claude_desktop_config.json
Config file location: %APPDATA%\Claude\claude_desktop_config.json
Config file location: ~/.config/Claude/claude_desktop_config.json
{
"mcpServers": {
"autopentest-ai": {
"command": "node",
"args": [
"path/to/server.js"
]
}
}
} Community Reviews
Authenticated reviews from GitHub users. No anonymous submissions. Your experience helps others choose wisely.
No reviews yet. Be the first to share your experience.