PentesterFlow: CLI agent for AI-assisted penetration testing

Tools2026-08-07, 13:16
PentesterFlow is an open-source CLI agent that follows a plan → act → observe → verify → report cycle. It supports local and hosted LLMs through Ollama, LM Studio, Gemini, Groq, and OpenAI-compatible APIs.
The agent can execute shell commands, send HTTP requests, work with files, ingest and analyze traffic captured in Burp Suite, and integrate external tools through MCP. Its built-in playbook skills cover recon, IDOR, SSRF, SSTI, JWT, GraphQL, race conditions, subdomain takeover, and insecure deserialization.
During an assessment, PentesterFlow tracks combinations that have already been tested — endpoint + parameter + vulnerability class, so that it does not repeat identical checks. Confirmed findings are saved as Markdown files containing requests, responses, impact, recommendations, and a reproducible curl command.
A key feature is operator control. Dangerous operations require an allow once decision, allow session or deny; a YOLO mode is also available, automatically approving actions that would normally require confirmation. These permission prompts should not be treated as a strict security boundary: the tool is intentionally capable of reaching internal and metadata addresses, reading files, and executing system commands when authorized by the operator. Since PentesterFlow can execute commands and modify files, it is best run in an isolated environment and used strictly within an explicitly authorized scope.
Vendors
Pentesterflow
Ollama
Lm Studio
Gemini
Groq
Openai
More
Products
Burp Suite
Curl
Gemini
Groq
Lm Studio
Mcp
More