Skip to content

Repository files navigation

pentest-agent

An AI web-application penetration-testing specialist for authorized bug-bounty and pentest work. Built as a Claude Code subagent (pentest-web) plus a compounding library of methodology, scope-authorization, and reporting assets. Orchestrator + advisor: you run the tools, the agent plans, interprets, and reports.

For good only. Every target-specific test is gated behind a written authorization scope. See the agent's authorization rules and SCOPE.template.md.

What's here

pentest-agent/
├── .claude/agents/pentest-web.md   — the agent (canonical source; also installed to ~/.claude/agents/)
├── SCOPE.template.md               — per-engagement authorization record (the guardrail)
├── methodology/
│   ├── web-app-methodology.md      — the recon → test → report playbook (your IP)
│   ├── payloads.md                 — detection/PoC probe reference (confirmation-first, no weaponization)
│   └── checklists/                 — per-vuln-class checklists (index + 7 classes)
├── templates/
│   ├── finding-report.md           — professional bug-bounty finding format
│   └── engagement-log.md           — per-engagement audit trail (what/where/when/result)
└── engagements/                    — one folder per program/target (gitignored; holds real scope, log, findings)

Using it

  1. Start an engagement: cp SCOPE.template.md engagements/<program>/SCOPE.md and fill it in from the program policy — in-scope assets, excluded vuln types, rate limits, required identifier header. Then open the audit trail: cp templates/engagement-log.md engagements/<program>/log.md (the agent appends to it as it works).
  2. Invoke the agent (from anywhere, since it's installed globally):

    "Use the pentest-web agent. Here's the scope: <paste or point at engagements/acme/SCOPE.md>. Let's start recon on the in-scope assets."

  3. You run the commands it gives you (subfinder, httpx, katana, nuclei, Burp, ffuf, …) and paste results back.
  4. The agent interprets, forms hypotheses, hands you the next probes, and writes findings with the template.

Guardrails (non-negotiable, by design)

  • No target-specific attack steps without an authorized scope. Permission is a document, not a claim.
  • Hard-refuses: DoS/stress, social engineering, out-of-scope assets, real-user-data exfiltration, persistence/lateral-movement/destructive actions on targets you don't own.
  • The agent has no Bash and no scanning tools — it cannot send traffic. That's intentional: it advises, you execute. It keeps you fast and inside the lines.

Roadmap (as this grows toward a practice)

  • Now: advisor subagent + methodology/report library (this).
  • Next: an engagements/ workflow, checklists per vuln class, a payload/wordlist reference.
  • Later (opt-in): a standalone Claude Agent SDK app that can run read-only recon tooling against in-scope targets under hard scope-gating — the productizable core. Nothing here is thrown away when you get there.

Legal

Only test what you're authorized to test. Bug-bounty authorization = the published program scope; pentest authorization = a signed rules-of-engagement. This tooling assumes and enforces that; it does not grant it.

About

AI web-app pentest specialist (pentest-web agent) + methodology/scope/report library. Authorized bug-bounty / pentest use only.

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors