Source snapshots of the most popular open-source AI penetration-testing / security tooling. Refreshed daily · old versions are kept.
| Tool | Version | Updated | Snapshots |
|---|---|---|---|
| strixApache-2.0 Autonomous AI pentesting agents — run code dynamically, find vulnerabilities, validate them with real PoCs. | v1.7.0 tag | 2026-10-09 | strix-v1.7.0.tar.gz 4.9 MB |
| shannonAGPL-3.0 Fully autonomous AI pentester for web apps and APIs — white-box, reads your source code. | v3.4.0 tag | 2026-10-09 | shannon-v3.4.0.tar.gz 51.5 MB |
| pentagiMIT Fully autonomous multi-agent penetration testing system (self-hosted, Docker + web UI). | v2.2.0 tag | 2026-10-09 | pentagi-v2.2.0.tar.gz 50.2 MB |
| DecepticonApache-2.0 Autonomous hacking agent for red-team engagements. | v1.2.5 tag | 2026-10-09 | Decepticon-v1.2.5.tar.gz 26.1 MB |
| redamon Self-hosted AI pentesting framework — maps attack surface into a graph, autonomous exploitation. | v6.14.1 tag | 2026-10-09 | redamon-v6.14.1.tar.gz 196.9 MB |
| Pentest-Swarm-AIAGPL-3.0 Swarm of AI agents orchestrating recon, classification, exploitation and reporting. | v0.2.31 tag | 2026-10-09 | Pentest-Swarm-AI-v0.2.31.tar.gz 6.1 MB |
| LuaN1aoAgent Autonomous AI pentest agent with graph-based cognitive reasoning. | v2.0.0 tag | 2026-10-09 | LuaN1aoAgent-v2.0.0.tar.gz 1.7 MB |
| xalgorixApache-2.0 Autonomous AI pentesting agents — real-time recon, vulnerability detection, exploitation. | v4.6.153 tag | 2026-10-09 | xalgorix-v4.6.153.tar.gz 7.5 MB |
| nebulaBSD-2-Clause AI-powered pentesting assistant — automated recon, note-taking, vulnerability analysis. | nebula-v3.0.0-beta.3 tag | 2026-10-09 | nebula-nebula-v3.0.0-beta.3.tar.gz 30.7 MB |
| Tool | Version | Updated | Snapshots |
|---|---|---|---|
| PentestGPTMIT The original LLM pentesting agent framework (USENIX Security 2024). | v1.0.0 tag | 2026-10-09 | PentestGPT-v1.0.0.tar.gz 33.1 MB |
| cai Cybersecurity AI framework — build your own security AI agents. ⚠ Archived by upstream in Aug 2026 — kept for reference; the framework is still widely used. | HEAD-6dc7925 head | 2026-10-09 | cai-HEAD-6dc7925.tar.gz 216.5 MB |
| Cairn State-space search engine for autonomous agents — first proven on AI penetration testing. | v0.2.1 tag | 2026-10-09 | Cairn-v0.2.1.tar.gz 2.9 MB |
| pentestagentMIT AI agent framework for black-box security testing (bug bounty / red team / CTF). | HEAD-87d763a head | 2026-10-09 | pentestagent-HEAD-87d763a.tar.gz 3.3 MB |
| pentest-copilotMIT Browser-based AI hacking assistant with agentic command execution. | HEAD-cd512ed head | 2026-10-09 | pentest-copilot-HEAD-cd512ed.tar.gz 19.3 MB |
| hackingBuddyGPTMIT Teaching and research harness for LLM-assisted pentesting in minimal code. | v0.5.0 tag | 2026-10-09 | hackingBuddyGPT-v0.5.0.tar.gz 1.1 MB |
| pentest-agents Bug-bounty agent framework for Claude Code, Codex, Gemini, Cursor etc. (48 agents). | HEAD-41d49b6 head | 2026-10-09 | pentest-agents-HEAD-41d49b6.tar.gz 2.9 MB |
| Tool | Version | Updated | Snapshots |
|---|---|---|---|
| hexstrike-aiMIT MCP server that lets AI agents drive 150+ security tools (12+ agents, FastMCP). | HEAD-d689933 head | 2026-10-09 | hexstrike-ai-HEAD-d689933.tar.gz 2.0 MB |
| MCP-Kali-ServerMIT MCP bridge connecting AI agents to a Kali Linux machine. | HEAD-00154c0 head | 2026-10-09 | MCP-Kali-Server-HEAD-00154c0.tar.gz 10.6 KB |
| Tool | Version | Updated | Snapshots |
|---|---|---|---|
| vulnhuntrAGPL-3.0 LLM-powered zero-shot vulnerability discovery in Python source code. ⚠ Upstream dormant since Feb 2025 — kept for reference; still widely cited. | HEAD-ead88c5 head | 2026-10-09 | vulnhuntr-HEAD-ead88c5.tar.gz 79.4 KB |
| oss-fuzz-genApache-2.0 LLM-powered fuzzing — generates and validates OSS-Fuzz targets. | v1.0 tag | 2026-10-09 | oss-fuzz-gen-v1.0.tar.gz 859.6 KB |
| Tool | Version | Updated | Snapshots |
|---|---|---|---|
| promptfooMIT Test and red-team prompts, agents and RAGs — pentesting for AI systems. | 0.124.1 tag | 2026-10-09 | promptfoo-0.124.1.tar.gz 174.6 MB |
| garakApache-2.0 LLM vulnerability scanner — probes, detectors, automated reporting. | v0.17.0 tag | 2026-10-09 | garak-v0.17.0.tar.gz 3.8 MB |
| AI-Infra-Guard Full-stack AI red-teaming platform — agent, skills and MCP scanning. | v4.6.5 tag | 2026-10-09 | AI-Infra-Guard-v4.6.5.tar.gz 102.5 MB |
| PyRITMIT Microsoft's Python Risk Identification Toolkit for generative AI red teaming. | v1.1.0 tag | 2026-10-09 | PyRIT-v1.1.0.tar.gz 72.0 MB |
| deepteamApache-2.0 Red-teaming framework for LLMs and AI agents (vulnerability scanning, attacks). | v1.0.9 tag | 2026-10-09 | deepteam-v1.0.9.tar.gz 26.7 MB |
| agentic_securityApache-2.0 Agentic LLM vulnerability scanner and AI red-team kit. | 0.7.5 tag | 2026-10-09 | agentic_security-0.7.5.tar.gz 9.9 MB |