pentest-ai (ptai)
An autonomous AI pentester that proves every finding: verified bugs ship a proof capsule you can replay
High risk
We rate an entry high when the tool writes to external systems, handles money, production databases or secrets, or runs arbitrary commands. The CLI installs it only with your consent.
Why this level
- Performs real offensive actions against a target
- Works with credentials and network services
Install
In your terminal, with SkillFoxx CLI
npx skillfoxx add cli/pentest-ai-ptaiDetects the agents on your machine, checks the risk and pins the version.
Other ways to install
Install the tool
pipx install ptaiWithout pipx, pip install ptai works too.
Install pipx, then pipx install ptai. For a local model set PENTEST_AI_LLM_PROVIDER=ollama and the model in PENTEST_AI_MODEL. Export findings: ptai export <engagement-id> --sarif pentest.sarif.
Other ways from the author
pipx install ptaiRequires Python 3.10-3.14 and pipx.
This is third-party code. Review the repository files before installing.
What it does
ptai runs authorized penetration testing with a set of agents by area: reconnaissance, API security, cloud, browser, credential testing and more. The key idea is that each finding is re-verified independently, and only confirmed vulnerabilities reach the report with a capsule you can replay. Results are exported by engagement id, there is SARIF export and a CI step. It installs via pipx as the ptai CLI.
Who it is for. For security professionals running authorized penetration testing.
Good fit when
- You need an automated pentest run against an authorized target
- You want only confirmed findings with proof
- You need to embed a security check in CI
Not a fit when
- You do not have written authorization for the target
- You need a manual focused audit rather than an automated run
Example request
Run a ptai check against this authorized lab and export only the confirmed findingsLimitations
The tool performs real offensive actions, so use it only against targets you are authorized to test. It needs model access: you can point it at a local model via ollama or another provider, whose availability from Russia should be checked.
How to disable. Remove the CLI with pipx uninstall ptai.
Security check
- Performs real offensive actions against a target
- Works with credentials and network services
README in short
The README describes pentest-ai as an autonomous pentester with the ptai CLI that proves every finding. Installation is via pipx, with pipx upgrade for updates, and a local ollama model is supported. Results are exported by engagement id, with SARIF export and a GitHub Action step. It stresses that the tool is for authorized testing only.
FAQ
How is this different from a plain scanner?
Each finding is re-verified, and only confirmed vulnerabilities reach the report with a replayable capsule.
Can it run without a cloud model?
Yes, a local ollama provider is supported and set via environment variables.
Related
A code security audit skill by Cloudflare: the agent runs recon, coverage-led hunting and independent verification of findings, then produces a structured repor
NVIDIA's open stack for running OpenClaw, Hermes and LangChain Deep Agents in OpenShell sandboxes with network policy and managed inference
Security scanner for agent skills and MCP servers: finds prompt injection, data exfiltration and supply chain risks before install
Static code analysis with rules that look like source code, plus a built-in MCP server for AI agents