Score breakdown
Popularity is tracked separately. Support, ads, sponsorships, and tips never affect these signals.
Why it matters
Useful for authorized penetration testers, bug-bounty hunters, and red-team operators who need an LLM-coordinated orchestrator that wraps 200+ security tools behind a single MCP server: a single subscription to Claude Code / Cursor / Codex drives the workflow; for security teams who need a documented 'authorized testing only' workflow with an explicit AUP and per-engagement consent flow (`PENTEST_
Who should use it
Who should skip it
Avoid running 0xSteph/pentest-ai in production until you have reviewed its permissions, data-access scope, and failure modes in a sandbox.
About this signal
0xSteph/pentest-ai is tracked by RepoRadar as a autonomous pentest orchestrator in the MIT Python autonomous pentest orchestrator wrapp section. It was first seen on 2026-06-25 and last updated on 2026-06-25. The current verdict is 'try now' with a Silver tier and review needed setup difficulty. Across RepoRadar's eight signals, 0xSteph/pentest-ai is strongest on novelty (10.0) and momentum (10.0) and weakest on setup ease (6.5) — a profile worth weighing against your own priorities. This page summarizes the evidence RepoRadar has captured from captured source metadata. The score, tier, risk label, and verdict on this page are never influenced by sponsorship, ads, or tips — they reflect only the usefulness, popularity, novelty, momentum, maturity, and evidence signals described in the RepoRadar methodology.
How this item is evaluated
RepoRadar assigned 0xSteph/pentest-ai a composite score of 7.9 out of 10, placing it in the Silver tier. This score combines weighted sub-signals: usefulness (35%), novelty (18%), momentum (14%), maturity (10%), open-source/build quality (7%), evidence quality (6%), workflow potential (6%), and setup ease (4%). Popularity is tracked separately at 895.0 and never affects the composite score or tier. The risk label of 'high' reflects inherent user-impacting hazards, not generic novelty. Items with no risk flag may still require normal code review before production use.
Risk explanation
High risk: do not use without strong containment, approvals, and hands-on review.