Skip to main content

PentestAI - AI-assisted pentest CLI workflow (recon -> analysis -> scan -> validate -> report)

Project description

PentestAI

PentestAI is a CLI-first, AI-assisted penetration testing framework for Linux.

It combines real-world pentest tools with multiple LLM providers to assist with analysis, triage, validation, and reporting — without replacing the pentester.

Human-in-the-loop by design.

What PentestAI Is (and Is Not)

PentestAI IS

  • A CLI tool for authorized penetration testing
  • AI-assisted analysis, validation, triage, and reporting
  • Built on real tools: subfinder, httpx, nmap, nuclei
  • Safe-by-default, scope-aware

PentestAI IS NOT

  • An auto-exploitation framework
  • A payload generator
  • A replacement for human decision-making

Requirements

  • Linux (Parrot / Kali / Ubuntu recommended)
  • Python 3.12+
  • The following tools available in $PATH:
    • subfinder
    • httpx
    • nmap
    • nuclei

Installation (Recommended)

pip install pentestai-cli

Verify installation:

pentestai --help

API Keys Configuration (REQUIRED)

PentestAI uses environment variables for AI providers.

You must export at least one API key before running.

OpenAI (default)

export OPENAI_API_KEY="sk-..."

(Optional – persist across sessions)

echo 'export OPENAI_API_KEY="sk-..."' >> ~/.bashrc
source ~/.bashrc

Optional Providers

export ANTHROPIC_API_KEY="sk-ant-..."
export GEMINI_API_KEY="AIza..."
export DEEPSEEK_API_KEY="sk-..."

PentestAI will automatically route AI requests based on availability.

Workspace Behavior (Automatic)

PentestAI automatically creates a workspace directory per target.

Default location:

/home/<user>/workspaces/

Example:

/home/user/workspaces/example.com/
├── recon/
├── scan/
├── validate/
└── reports/

You do not need to create this manually.

Quick Start

PentestAI can be run from any directory.

Reconnaissance

pentestai recon run --target example.com

AI Attack Surface Analysis

pentestai surface analyze --target example.com

Vulnerability Scanning

pentestai scan run --target example.com

Validation & Triage (AI-assisted)

pentestai validate run --target example.com

Report Generation

pentestai report build --target example.com

Reports are written to:

~/workspaces/example.com/reports/report.md

Required External Tools

Ensure the following tools are installed:

which subfinder httpx nmap nuclei

Design Philosophy

  • CLI-first
  • Human-in-the-loop
  • Safe-by-default
  • AI assists analysis — never auto-exploits
  • Works anywhere on the filesystem

Legal & Ethical Use

PentestAI must only be used on systems you own or have explicit authorization to test.

Notes for Advanced Users

  • No config.yaml required for default usage
  • Workspace paths are auto-resolved per user
  • AI provider routing is handled internally
  • Future versions may expose optional configuration overrides

Contributing

Contributions are welcome.

You can contribute by:

  • Adding tool integrations
  • Improving AI prompts
  • Improving reports
  • Improving documentation

License

MIT License See LICENSE.

Why PentestAI?

PentestAI is built for:

  • Students learning real pentest workflows
  • Security interns & junior pentesters
  • Professionals who want faster analysis and cleaner reports
  • Open-source contributors interested in AI + security

If PentestAI helps you, consider starring the project.

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

pentestai_cli-0.1.2.tar.gz (17.8 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

pentestai_cli-0.1.2-py3-none-any.whl (24.8 kB view details)

Uploaded Python 3

File details

Details for the file pentestai_cli-0.1.2.tar.gz.

File metadata

  • Download URL: pentestai_cli-0.1.2.tar.gz
  • Upload date:
  • Size: 17.8 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.7

File hashes

Hashes for pentestai_cli-0.1.2.tar.gz
Algorithm Hash digest
SHA256 3a474aa56b87bae1171dab67f75ff9dfb2e374bef92dabfc8a4dc70d974b01e0
MD5 408e73cb4e26cd294048833402d3f47d
BLAKE2b-256 b1d84ef99b37828365b4a4e5224dfb6d6284144d7858e663193c85cc1874d53e

See more details on using hashes here.

Provenance

The following attestation bundles were made for pentestai_cli-0.1.2.tar.gz:

Publisher: release.yml on dinhvaren/PentestAI

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file pentestai_cli-0.1.2-py3-none-any.whl.

File metadata

  • Download URL: pentestai_cli-0.1.2-py3-none-any.whl
  • Upload date:
  • Size: 24.8 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.7

File hashes

Hashes for pentestai_cli-0.1.2-py3-none-any.whl
Algorithm Hash digest
SHA256 7ceb65b1e84a6da135f401db5f00616404c850adb000919a50cfacd0a47ea56f
MD5 95ff86ca65589266f9f94cb42a8a9e3f
BLAKE2b-256 37cdd4b4024d90e7b167007b197c150454f3194551a268a16bb7f0ac4542945d

See more details on using hashes here.

Provenance

The following attestation bundles were made for pentestai_cli-0.1.2-py3-none-any.whl:

Publisher: release.yml on dinhvaren/PentestAI

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page