☠ Pentest Copilot — The Machine That Hunts For You ☠ 3 hours ago
#1
```
☠ What Lurks Inside
An open-source, AI-driven penetration testing agent that connects to a Kali attack box, runs tools autonomously, analyzes results, and iterates without a hand on the wheel. You describe the target. It hunts.
☠ Its Capabilities
☠ It Answers to No Single Master
Bring your own model: OpenAI, Anthropic, Google, Mistral, or any compatible endpoint. It can even ride on an authenticated Claude Code or Codex CLI subscription for inference while keeping its own tool and consent loop.
☠ Proof of the Kill
Demonstrated performing a live auth bypass against OWASP Juice Shop, agent-driven from start to finish.
☠ Requirements to Summon It
☠ A Word of Warning
The project's own disclaimer: intended for authorized testing only, and explicit permission is required before touching any system. The MCP token exposes local admin-level control over the exploit box, Burp, browser automation, and VPN, so guard it like a key to something that bites back.
☠ PENTEST COPILOT — THE MACHINE THAT HUNTS FOR YOU ☠
It doesn't sleep. It doesn't hesitate. Point it at a target, and it does the rest.
☠ What Lurks Inside
An open-source, AI-driven penetration testing agent that connects to a Kali attack box, runs tools autonomously, analyzes results, and iterates without a hand on the wheel. You describe the target. It hunts.
☠ Its Capabilities
- Agentic execution: runs commands directly on the attack box, reads the output, decides the next move, loops up to 25 times per turn unattended
- 16 agent tools: bash, Python, tool installation, shell management, Google search, subagent spawning, full Burp Suite control, browser automation
- 100+ curated tools spanning network, reverse engineering, pwn, crypto, forensics, and steganography
- Burp Suite fully wired in: Repeater, Intruder, Collaborator, proxy history, all agent-accessible
- Browser agent that drives real browsers through login flows and JS-heavy apps, with an optional Burp proxy chain
- VPN profile management with simultaneous connections
- Subagent parallelism, so multiple attacks run at once in the shadows
☠ It Answers to No Single Master
Bring your own model: OpenAI, Anthropic, Google, Mistral, or any compatible endpoint. It can even ride on an authenticated Claude Code or Codex CLI subscription for inference while keeping its own tool and consent loop.
☠ Proof of the Kill
Demonstrated performing a live auth bypass against OWASP Juice Shop, agent-driven from start to finish.
☠ Requirements to Summon It
- 8GB RAM minimum (+2GB for the built-in Kali container)
- 20GB disk
- Docker v20+ with Compose v2+
☠ A Word of Warning
The project's own disclaimer: intended for authorized testing only, and explicit permission is required before touching any system. The MCP token exposes local admin-level control over the exploit box, Burp, browser automation, and VPN, so guard it like a key to something that bites back.
☠ SUMMON THE REPO ☠
1.3k stars. 255 forks. MIT licensed. It's already watching.
```
(This post was last modified: 3 hours ago by The High Roller.)




![[+]](https://sinister.ly/images/modern/collapse_collapsed.png)