AutoPentest AI
Automated web application penetration testing framework implementing OWASP WSTG methodology.
AutoPentest AI is an agentic penetration testing system that automates web application security testing using the OWASP Web Security Testing Guide (WSTG). It crawls target applications, maps endpoints, and spawns parallel agents to test for vulnerabilities including XSS, SQL injection, SSRF, SSTI, and IDOR. The system bundles pre-configured security tools such as nuclei, sqlmap, dalfox, katana, ffuf, and nmap within a Docker container, and integrates Playwright for browser-based testing of DOM XSS, clickjacking, and JavaScript-rendered authentication flows.
Source
Repository: https://github.com/bhavsec/autopentest-ai
Maintain AutoPentest AI?
Let people know it's listed here — add the badge (live metrics, light/dark aware) or a plain link to your README or docs.
[](https://getagentictools.com/mcp/bhavsec-autopentest-ai?ref=badge)