Skip to main content
ClaudeWave
0xSteph avatar
0xSteph

pentest-ai-agents

View on GitHub

Turn Claude Code into your offensive security research assistant. Specialized AI subagents for authorized penetration testing plan engagements, analyze recon, research exploits, build detections, audit STIGs, and write reports.

Subagents2k stars392 forksShellMITUpdated 1mo ago
ClaudeWave Trust Score
92/100
Verified
Passed
  • Open-source license (MIT)
  • Recently active
  • Healthy fork ratio
  • Clear description
  • Topics declared
Last scanned: 6/11/2026
Install as a Claude Code subagent
Method: Clone
Terminal
git clone https://github.com/0xSteph/pentest-ai-agents && cp pentest-ai-agents/*.md ~/.claude/agents/
1. Clone the repository and copy the agent .md definitions into ~/.claude/agents (or .claude/agents inside a project).
2. Start a new Claude Code session to load the agents.
3. Delegate work to them with the Task/Agent tool or by name.

24 items in this repository

ad-attackerSubagent

>-

Install
api-securitySubagent

Delegates to this agent when the user asks about API security testing, REST API attacks, GraphQL exploitation, OAuth/OIDC vulnerabilities, JWT attacks, API enumeration, or web service penetration testing methodology.

Install

>-

Install

>-

Install
bug-bountySubagent

>-

Install
c2-operatorSubagent

Delegates to this agent when the user asks about command-and-control framework operations, Sliver/Mythic/Havoc/Cobalt Strike configuration, listener and beacon tuning, malleable C2 profiles, sleep and jitter strategy, redirector and CDN fronting infrastructure, or operating an established foothold during authorized red team engagements.

Install
cicd-redteamSubagent

>-

Install

Delegates to this agent when the user asks about cloud security testing, AWS/Azure/GCP penetration testing, cloud misconfiguration analysis, IAM privilege escalation, container security, Kubernetes attacks, serverless security, or cloud-native attack paths.

Install

Delegates to this agent when the user asks about container escape, Docker breakout, Kubernetes pod escape, runc/containerd CVE exploitation, capability abuse, privileged container hunting, kubelet API attacks, service account token abuse, or any technique that pivots from inside a container to the host or cluster control plane during authorized testing.

Install

>-

Install
ctf-solverSubagent

Delegates to this agent when the user is working on CTF challenges, capture the flag competitions, HackTheBox machines, TryHackMe rooms, or needs help with CTF methodology including web exploitation, binary exploitation, cryptography, forensics, reverse engineering, or privilege escalation challenges.

Install

Delegates to this agent when the user asks about detection rules, SIEM queries, threat hunting, indicator analysis, log analysis, blue team detection for specific attack techniques, or creating detection engineering content.

Install

Delegates to this agent when the user needs to plan a penetration test, define attack methodology, scope an engagement, map techniques to MITRE ATT&CK, or create a rules of engagement template.

Install

>-

Install

Delegates to this agent when the user asks about exploitation techniques, attack methodologies, tool configurations for authorized testing, post-exploitation activities, or specific vulnerability exploitation paths.

Install

Delegates to this agent when the user asks about digital forensics, incident response, evidence acquisition, memory forensics, disk forensics, network forensics, timeline analysis, or chain of custody

Install
llm-redteamSubagent

Delegates to this agent when the user asks about LLM and AI system red teaming, prompt injection (direct and indirect), jailbreak techniques, RAG poisoning, model exfiltration, training data extraction, agent and tool-use abuse, MCP server exploitation, AI guardrail bypass, or red teaming a deployed Claude/GPT/Gemini/open-weight application during authorized testing.

Install

Delegates to this agent when the user asks about malware analysis, reverse engineering, binary analysis, disassembly, debugging, sandbox analysis, static analysis, dynamic analysis, or suspicious file triage

Install

Delegates to this agent when the user asks about mobile application security testing, Android pentesting, iOS pentesting, APK analysis, IPA analysis, mobile API testing, certificate pinning bypass, or mobile reverse engineering

Install

Delegates to this agent when the user asks about operator-side identity hygiene, source IP separation, traffic anonymization for authorized red team work, Tor and proxy chains, burner infrastructure provisioning, attribution avoidance, or pre-engagement opsec posture before tools are run against scope.

Install

Delegates to this agent when the user asks about OSINT, reconnaissance, information gathering, target profiling, email harvesting, subdomain enumeration, social media recon, breach data, open source intelligence, or building a target dossier for authorized engagements.

Install

Delegates to this agent when the user asks about generating offensive payloads, building shellcode, working with msfvenom, packing or encoding payloads, building reverse shells, creating EDR-test binaries, or producing initial-access artifacts during authorized red team engagements.

Install

Delegates to this agent when the user asks about setting up phishing infrastructure, configuring Evilginx3 or GoPhish, adversary-in-the-middle credential capture, MFA token relay, domain lookalike detection with dnstwist, or building phishing landing pages for authorized red team engagements.

Install

>-

Install
Use cases

Subagents overview

README preview not available. Visit the repo on GitHub for full documentation.
ai-agentsai-securitybug-bountyclaude-codectfcybersecurityethical-hackinginfoseckali-linuxmitre-attackoffensive-securityoscppenetration-testingpentestpentestingred-teamsecurity-automationsecurity-tools

What people ask about pentest-ai-agents

What is 0xSteph/pentest-ai-agents?

+

0xSteph/pentest-ai-agents is subagents for the Claude AI ecosystem. Turn Claude Code into your offensive security research assistant. Specialized AI subagents for authorized penetration testing plan engagements, analyze recon, research exploits, build detections, audit STIGs, and write reports. It has 2k GitHub stars and was last updated 1mo ago.

How do I install pentest-ai-agents?

+

You can install pentest-ai-agents by cloning the repository (https://github.com/0xSteph/pentest-ai-agents) or following the README instructions on GitHub. ClaudeWave also provides quick install blocks on this page.

Is 0xSteph/pentest-ai-agents safe to use?

+

Our security agent has analyzed 0xSteph/pentest-ai-agents and assigned a Trust Score of 92/100 (tier: Verified). See the full breakdown of passed checks and flags on this page.

Who maintains 0xSteph/pentest-ai-agents?

+

0xSteph/pentest-ai-agents is maintained by 0xSteph. The last recorded GitHub activity is from 1mo ago, with 3 open issues.

Are there alternatives to pentest-ai-agents?

+

Yes. On ClaudeWave you can browse similar subagents at /categories/agents, sorted by popularity or recent activity.

Deploy pentest-ai-agents to your cloud

Ship this repo to production in minutes. Each platform spins up its own environment with editable env vars.

Maintain this repo? Add a badge to your README

Drop the badge into your GitHub README to show it's tracked on ClaudeWave. Each badge links back to this page and reflects the live Trust Score.

Featured on ClaudeWave: 0xSteph/pentest-ai-agents
[![Featured on ClaudeWave](https://claudewave.com/api/badge/0xsteph-pentest-ai-agents)](https://claudewave.com/repo/0xsteph-pentest-ai-agents)
<a href="https://claudewave.com/repo/0xsteph-pentest-ai-agents"><img src="https://claudewave.com/api/badge/0xsteph-pentest-ai-agents" alt="Featured on ClaudeWave: 0xSteph/pentest-ai-agents" width="320" height="64" /></a>

More Subagents