Self-hosted, autonomous AI penetration-testing platform that runs security tests in an isolated Docker sandbox using a team of specialized agents.
Open-source, self-hosted autonomous AI penetration-testing platform with 20+ security tools in a Docker sandbox and multi-agent orchestration.
PentAGI (Penetration testing Artificial General Intelligence) is an open-source, self-hosted platform for automated security testing aimed at information-security professionals, researchers, and enthusiasts. It runs an AI-powered agent that autonomously determines and executes penetration-testing steps, with optional execution monitoring and intelligent task planning for reliability. All operations happen inside a fully isolated, sandboxed Docker environment, and the platform bundles more than 20 professional security tools such as nmap, metasploit, and sqlmap. Rather than a single monolithic agent, PentAGI uses a team of specialists with a delegation system: an orchestrator coordinates researcher, developer, and executor agents that share discoveries and chain findings. It has a smart long-term memory system for storing successful approaches, plus a Graphiti-powered knowledge graph on Neo4j for semantic relationship tracking. Built-in web intelligence includes an isolated browser scraper and integrations with external search systems such as Tavily, Traversaal, Perplexity, DuckDuckGo, Google Custom Search, Sploitus, and Searxng. For builders and teams, PentAGI ships a clean web UI plus full REST and GraphQL APIs secured with Bearer tokens for automation and integration. It supports 10+ LLM providers including OpenAI, Anthropic, Google AI/Gemini, AWS Bedrock, Ollama, DeepSeek, GLM, Kimi, and Qwen, plus aggregators like OpenRouter and DeepInfra, and custom OpenAI-compatible endpoints. Observability is first-class, with Langfuse for LLM analytics and Grafana/Prometheus, Jaeger, and Loki for monitoring. Data persists in PostgreSQL with the pgvector extension, and the microservices architecture supports horizontal scaling. It generates detailed vulnerability reports with exploitation guides and is deployed quickly via Docker Compose. Note it is an autonomous and assistant-guided pentesting platform, not a breach-and-attack-simulation product. Use only on systems you are authorized to test.
Was this helpful?
PentAGI is an autonomous, self-hosted AI pentesting platform with a multi-agent orchestrator, 20+ professional tools in a Docker sandbox, and a Neo4j knowledge graph for tracking findings. Broad LLM support, REST/GraphQL APIs, and deep observability set it apart from chatbot-plus-scanner tools. It's investigative pentesting, not breach-and-attack simulation, and demands security expertise.
$0 (self-hosted)
Ready to get started with PentAGI?
View Pricing Options →We believe in transparent reviews. Here's what PentAGI doesn't handle well:
Weekly insights on the latest AI tools, features, and trends delivered to your inbox.
No reviews yet. Be the first to share your experience!
Get started with PentAGI and see if it's the right fit for your needs.
Get Started →Take our 60-second quiz to get personalized tool recommendations
Find Your Perfect AI Stack →Explore 20 ready-to-deploy AI agent templates for sales, support, dev, research, and operations.
Browse Agent Templates →Explore MCP Security Best Practices: Keep Your AI Tools Safe with our comprehensive guide. Practical insights, expert analysis, and actionable strategies to help you succeed.
Comprehensive guide to securing AI agents in enterprise environments. Learn governance, compliance, and deployment strategies for production-ready AI systems.
A2A protocol was built with enterprise security from day one. Here's how it handles authentication, authorization, and trust between AI agents — plus the governance challenges you need to prepare for.
AI agents that handle business operations introduce new security risks that traditional cybersecurity doesn't cover. Here's how to protect your agents from prompt injection, data theft, and operational failures — with practical tools and implementation strategies.