{"repo":"bhavsec/autopentest-ai","free":true,"listed":false,"github":"https://github.com/bhavsec/autopentest-ai","clone":"git clone https://github.com/bhavsec/autopentest-ai.git","description":"Agentic Pentesting MCP server that discovers, exploits, and reports web application vulnerabilities.","language":"Python","stars":212,"topics":[],"license":"Apache-2.0","category":"mcp-servers","readme_excerpt":"AutoPentest An agentic pentesting MCP server that automates web application penetration testing using the full OWASP Web Security Testing Guide and PortSwigger Web Security Academy technique references. Point it at a target — it crawls your app, maps every endpoint, then spawns role-specialized agents (Scout, Analyzer, Exploiter, Reporter) to test for XSS, SQLi, SSRF, SSTI, IDOR and more. No false positives — every finding is backed by real, reproducible evidence with quality gates enforcing proof at every phase. Includes 31 PortSwigger technique guides, adaptive WAF evasion for 12 vendors, cross-phase vulnerability chaining, and risk-weighted endpoint prioritization. Run it with Claude Code, the API, or go fully offline using Ollama models. Think of it as: A senior pentester's methodology encoded into an MCP server — 109 OWASP tests, 31 PortSwigger attack technique guides, 68+ MCP tools, 27 security tools, 4 specialized agent roles, 7 structured phases, automated quality assurance, and a zero-context final review. --- Table of Contents - Why AutoPentest? - Architecture - Features - Agent Role System - Quick Start - Usage - Testing Phases - Security Tools - WSTG Knowledge Base - PortSwigger Technique Guides - Quality Assurance System - Benchmarking - Example Report - Configuration - Multi-Domain Testing - Crash Recovery - Project Structure - Requirements - FAQ - Disclaimer --- Why AutoPentest? Manual penetration testing is thorough but slow. Automated scanners are fast but sh","default_branch":null,"files":null,"tree":[],"storefront":"/r/bhavsec","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/bhavsec/autopentest-ai/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}