{"repo":"0xSteph/pentest-ai","free":true,"listed":false,"github":"https://github.com/0xSteph/pentest-ai","clone":"git clone https://github.com/0xSteph/pentest-ai.git","description":"Open-source AI pentester that proves every finding. Machine oracles re-run each exploit; verified bugs ship a proof capsule you can replay yourself.","language":"Python","stars":1598,"topics":["ai-security","bug-bounty","claude","ctf","cybersecurity","hacking-tools","mcp","model-context-protocol","offensive-security","penetration-testing"],"license":"MIT","category":"security-tools","readme_excerpt":"pentest-ai It doesn't flag. It proves. Website · Install · Why verification · Benchmarks · Limits · Discord ⚠️ Offensive tooling, authorized testing only. By installing you accept the AUP and Terms. See Responsible use ↓ Two minutes, no API key, no target of your own ptai demo scans a bundled vulnerable app and prints 4 findings, 3 oracle-VERIFIED . It replays one live from a proof capsule ( replay 3/3 ), then runs the same routes hardened and prints 0 findings . Two things to notice. The findings appear and disappear with the vulnerability rather than because the tool went quiet — the only thing that changed between the two runs is the fix. And one of the four stays a candidate : the SQLi login bypass is real, but no oracle could re-prove it on that route, so it does not get a badge. That gap is the product working, not a bug in the demo. What VERIFIED actually means here Most scanners tell you a thing might be exploitable and leave the triage to you. ptai treats a finding as a candidate until a named machine oracle re-runs the exploit and reproduces it N out of N times. Only then does it earn VERIFIED. Three properties make that more than a slogan: No LLM ever produces a verdict. The rule is enforced in code, not by policy: a verdict that cannot name the oracle that earned it is rejected. An LLM coordinates the run and reasons about results. It never decides whether a bug is real. Every oracle has a control that must fail. A trusted-header bypass has to return privileged co","default_branch":null,"files":null,"tree":[],"storefront":"/r/0xSteph","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/0xSteph/pentest-ai/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}