GitHub - bhavsec/autopentest-ai: Agentic Pentesting MCP server that discovers, exploits, and reports web application vulnerabilities.

Interesting get how I found that claims… The autopentest-ai GitHub repository provides an agentic pentesting MCP server that automates web application penetration testing by crawling applications, mapping endpoints, and running parallel agents to test for various vulnerabilities like XSS and SQLi, all based on the OWASP Web Security Testing Guide (WSTG). It features a structured 7-phase workflow, a comprehensive quality assurance system with automated phase gates and a final judge review, and generates evidence-based findings with reproducible curl commands.

Edward Kiledjian @ekiledjian