pentest-ai-agents

A pack of about fifty Claude Code subagents for authorized pentesting: planning, recon, exploit research and chaining, post-exploitation, detection and reportin

Plugin

High risk

We rate an entry high when the tool writes to external systems, handles money, production databases or secrets, or runs arbitrary commands. The CLI installs it only with your consent.

Why this level

  • Offensive agents deal with exploits, payloads and post-exploitation against real targets
  • Shell-capable agents run security tools and network commands on hosts
All reasons and checks

0xsteph/pentest-ai-agents

Install

In your terminal, with SkillFoxx CLI

npx skillfoxx add plugins/pentest-ai-agents

Detects the agents on your machine, checks the risk and pins the version.

Other ways to install

Run one by one in the Claude Code chat

/plugin marketplace add 0xsteph/pentest-ai-agents
/plugin install pentest-ai-agents@pentest-ai-agents

Checked against the repository on Sep 25, 2026, commit e5d7aa0.

Text for your agent

Install the plugin: /plugin marketplace add 0xSteph/pentest-ai-agents, then /plugin install pentest-ai-agents@pentest-ai-agents. Or install by script: curl -fsSL https://raw.githubusercontent.com/0xSteph/pentest-ai-agents/main/install.sh | bash. Start with the engagement-planner agent.

Other ways from the author
/plugin marketplace add 0xSteph/pentest-ai-agents
/plugin install pentest-ai-agents@pentest-ai-agents

Installs the agents and slash commands from the plugin manifest.

This is third-party code. Review the repository files before installing.

What it does

The plugin adds a large set of specialized subagents to Claude Code, each with its own domain: engagement planning and threat modeling, OSINT and recon, web and API, Active Directory, cloud, mobile and wireless, payload crafting, reverse engineering, exploit chaining, post-exploitation, detection engineering, forensics and report generation. You describe a task in plain text and Claude routes it to the right specialist. Shell-capable agents carry a mandatory scope-check block, and a shared scope guard hard-refuses denial of service, mass scanning, unattended worms and safety-of-life systems. It also ships a local SQLite findings database, a token-saving mode and an optional path to run tools inside a container.

Who it is for. For pentesters, red team operators and security researchers working in Claude Code on authorized engagements.

Good fit when

  • You need to plan an authorized pentest and break it into stages
  • You need to analyze recon data and research and validate exploits for a target
  • You need to collect findings into a database and assemble a report

Not a fit when

  • You have no written authorization to test the target
  • You need a one-off security tip without installing a set of agents

Example request

Plan an external pentest of a small web application and break the work into stages

Limitations

Use only on authorized engagements; the user is responsible for the legality of use. The agents themselves are instructions for Claude Code, while the actual tools such as nmap, nuclei and ffuf must be installed separately, either via the --tools flag or checked with db/doctor.sh. The findings database and some features are available only through the script install; manual copy places only the agent files. A Claude Pro or Max subscription is required.

How to disable. If installed as a plugin, remove it via /plugin. If installed by script, run install.sh --uninstall, which removes the agents and commands. For a manual install, delete the agent files from ~/.claude/agents/ or the project's .claude/agents/.

Security check

  • Offensive agents deal with exploits, payloads and post-exploitation against real targets
  • Shell-capable agents run security tools and network commands on hosts

README in short

The README describes a set of Claude Code subagents that turn it into an offensive security assistant, split by domain: recon, web, Active Directory, cloud, post-exploitation, detection, forensics and reporting. It installs as a marketplace plugin, via the install.sh script or by copying files into the agents directory. Offensive agents carry a scope check and a shared scope guard hard-refuses destructive scenarios. It also adds a SQLite findings database, token savings, containerized tool runs and a cheaper-model mode for advisory agents. MIT licensed.

FAQ

Is this legal?

The set targets authorized testing, in-scope bug bounty, CTF and education. A shared scope guard refuses destructive actions, and offensive agents require staying inside the agreed scope.

Do I need to install the security tools myself?

Yes. The agents provide methodology and analysis, while nmap, nuclei, ffuf and others are installed separately, via install.sh --tools or by hand. Use db/doctor.sh to audit which tools are present.

Editors’ pick

A code security audit skill by Cloudflare: the agent runs recon, coverage-led hunting and independent verification of findings, then produces a structured repor

SkillMedium riskNo VPN needed22.6KRepository stars
Editors’ pick

NVIDIA's open stack for running OpenClaw, Hermes and LangChain Deep Agents in OpenShell sandboxes with network policy and managed inference

CLIHigh risk22.6KRepository stars
Editors’ pick

Security scanner for agent skills and MCP servers: finds prompt injection, data exfiltration and supply chain risks before install

CLIMedium riskNo VPN needed18.5KRepository stars
Official

Static code analysis with rules that look like source code, plus a built-in MCP server for AI agents

CLIMedium risk16.8KRepository stars
Foxx AIpentest-ai-agents

I am Foxx AI and I have already vetted this tool. Ask about install, setup or anything else, and I will keep it simple.