High-risk tools in Pentest Ai
29 of the 52 tools in Pentest Ai are classified as high risk. This page profiles those tools specifically, with recommended policy actions and the attack patterns that target them.
Every operation listed below is an action PolicyLayer recommends controlling at the transport layer. Open any tool to see the full profile, risk score, and YAML policy snippet.
Tools at high risk
-
authenticated_scanExecuteauthenticated_scan
-
browser_inspectExecuteInspect a URL with the headless browser.
-
builtin_scanExecutebuiltin_scan
-
ensure_tools_installedExecuteensure_tools_installed
-
http_requestExecutehttp_request
-
kill_processExecuteTerminate a running tool subprocess by PID.
-
plan_toolsExecuteplan_tools
-
poll_oobExecutepoll_oob
-
prove_attack_chainExecuteprove_attack_chain
-
resume_engagementExecuteresume_engagement
-
run_probeExecuterun_probe
-
run_reconExecuterun_recon
-
run_toolExecuteRun a specific security tool against a target.
-
scan_dns_builtinExecutePerform DNS enumeration (built-in).
-
scan_ports_builtinExecuteScan common ports on a target (built-in, no nmap required).
-
select_agentExecuteselect_agent
-
set_intensityExecuteChange scan intensity (stealth, normal, aggressive) mid-engagement.
-
start_campaignExecuteStart a multi-target campaign. Creates one engagement per target.
-
start_engagementExecutestart_engagement
-
test_active_directoryExecutetest_active_directory
-
test_api_securityExecuteRun API security testing (REST + GraphQL) following OWASP API Top 10.
-
test_cloudExecutetest_cloud
-
test_credentialsExecuteRun authentication testing (default creds, password spray, MFA bypass).
-
test_mobileExecuteRun mobile app security testing (Android or iOS).
-
test_privescExecuteRun privilege escalation enumeration on a compromised host.
-
test_social_engineeringExecuteRun a social engineering assessment (phishing simulation, OSINT, DMARC audit).
-
test_vulnerabilitiesExecuteRun vulnerability scanning (Nuclei + nikto; nuclei CVE templates are the primary known-CVE path).
-
test_web_appExecutetest_web_app
-
test_wirelessExecuteRun wireless security assessment (WiFi + Bluetooth). Returns
Attacks that target this class
High-risk tools in any server share these documented attack patterns. Each links to the full case and the defensive policy.