vxcontrol/pentagi

Source
GitHub
First trending
Category
Security
GitHub stars
24,606
Main language
Go
Website
pentagi.com (opens in a new tab)

This page introduces an external open-source repository. It is not an HDATF product.

vxcontrol/pentagi

What it does

An autonomous AI agent system that carries out penetration testing tasks. It works with several LLM providers and includes agent supervision, Langfuse integration and a Graphiti knowledge graph.

How it helps ATF

Its agent supervision and its way of giving agents Docker access without exposing the host could be a reference for oversight and sandboxing in Harness.

License

MIT Permissive. Commercial use and changes are allowed if the copyright notice is kept.

More in this category

  • promptfoo/promptfoo
    A CLI and library for evaluating and red-teaming LLM apps. It tests prompts, agents and RAG setups, compares models side by side, scans for vulnerabilities and runs checks in CI/CD from declarative configs.
  • QuipNetwork/hashsigs-rs
    A Rust workspace of hash-based post-quantum signature schemes, including WOTS+, SPHINCS+C and the hybrid SHRINCS signer and verifier. It also includes WebAssembly bindings and a verify-only Solana program.
  • NVIDIA/NemoClaw
    NemoClaw is an NVIDIA reference stack for running AI agents such as OpenClaw, Hermes and LangChain Deep Agents inside NVIDIA OpenShell sandboxes. Its CLI handles onboarding, managed inference, network policy, snapshots and lifecycle operations.
  • KeygraphHQ/shannon
    An AI agent that tests web applications and APIs for security flaws. It reads the source code, finds attack paths and runs real exploits, reporting only vulnerabilities it can prove, with CI/CD runs and SARIF output.
  • sherlock-project/sherlock
    Sherlock is a CLI tool that checks more than 400 social networks for accounts matching one or more usernames. Accounts found are saved to a text file for each username.

Only repositories in the ranked Trendshift lists are included, and the lists are used only to find candidates. We do not copy their ranks. Descriptions, licenses and star counts come from each GitHub repository. The notes are our own reading. We have not tested these projects, and a place on a trending list does not prove quality.

View on GitHub (opens in a new tab)