Deploy Now

Stars

24,173

Forks

3,112

Watchers

145

Developer links

PentaGI

Autonomous red team execution without manual script coordination is what PentaGI delivers through a multi-agent penetration testing platform engineered for automated security assessments. Security engineers configure testing scopes, target IP ranges, domain lists, and rules of engagement through an interactive web console with real-time execution graphs. Autonomous agent personas break down high-level assessment goals into discrete tactical phases, orchestrating network port discovery, service banner fingerprinting, web application crawling, and CVE verification. Specialized agents query integrated Graphiti knowledge graphs and local vulnerability repositories to synthesize attack paths, validate exploitability, and confirm finding veracity before issuing alerts. Operators monitor live agent terminal streams, inspect sandboxed tool executions, and adjust active LLM provider routes across OpenAI, Anthropic, or local Ollama endpoints. The template editor allows red teams to compose reusable testing playbooks with customizable security prompt chains, safety constraints, and automated remediation reporting. Audit logs capture full command histories, raw tool outputs, and LLM reasoning steps to generate compliance-ready technical documentation. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. MIT licensed.

PentaGI
PentaGI
PentaGI
PentaGI
PentaGI
PentaGI

Benefits

  • Autonomous Multi-Agent Penetration Testing Coordination
  • Decomposes complex offensive security assessments into modular reconnaissance, discovery, and exploit verification phases, dispatching specialized AI agents that execute tools in parallel without human supervision.
  • Sandboxed Attack Tool Execution Environment
  • Isolates offensive security utilities within disposable Docker containers, protecting host systems and ensuring consistent tool execution environments across disparate network architectures and target environments.
  • Knowledge-Augmented Attack Path Planning
  • Integrates temporal knowledge graphs and vulnerability databases to contextualize discovered services, eliminating redundant scans and validating realistic attack vectors against defined scope parameters.
  • Deterministic Security Finding Verification
  • Validates potential vulnerabilities through active verification sequences before logging findings, drastically cutting false positive noise in security reports and executive penetration testing debriefs.

Features

  • Autonomous Agent Orchestrator
  • Coordinates specialized AI sub-agents through hierarchical planning loops to execute network reconnaissance and vulnerability assessments autonomously.
  • Interactive Flow Visualizer
  • Renders real-time directed acyclic execution graphs showing active agent tasks, tool outputs, and phase progression during security scans.
  • Sandboxed Tool Runner
  • Executes network scanners, web fuzzers, and exploit verification scripts inside isolated Docker containers with strict egress controls.
  • Knowledge Graph Integration
  • Maintains structured target topology and vulnerability state across multi-step engagements using Graphiti temporal graph storage engines.
  • Multi-Provider LLM Gateway
  • Connects to Anthropic Claude, OpenAI GPT, and self-hosted Ollama models with granular token spending limits and prompt configuration.
  • Custom Assessment Playbooks
  • Enables security teams to author, version, and share reusable penetration testing templates with customizable testing scopes and safety rules.