AutoPentest AI

Automated web application penetration testing framework implementing OWASP WSTG methodology.

bhavsec 199 ↓ 84.5M
Claude CodeClaude DesktopGeneric
View source ↗

AutoPentest AI is an agentic penetration testing system that automates web application security testing using the OWASP Web Security Testing Guide (WSTG). It crawls target applications, maps endpoints, and spawns parallel agents to test for vulnerabilities including XSS, SQL injection, SSRF, SSTI, and IDOR. The system bundles pre-configured security tools such as nuclei, sqlmap, dalfox, katana, ffuf, and nmap within a Docker container, and integrates Playwright for browser-based testing of DOM XSS, clickjacking, and JavaScript-rendered authentication flows.

Source

Repository: https://github.com/bhavsec/autopentest-ai

Maintain AutoPentest AI?

Let people know it's listed here — add the badge (live metrics, light/dark aware) or a plain link to your README or docs.

AutoPentest AI on getagentictools
[![AutoPentest AI on getagentictools](https://getagentictools.com/badge/mcp/bhavsec-autopentest-ai.svg)](https://getagentictools.com/mcp/bhavsec-autopentest-ai?ref=badge)