# Pentest Ai MCP server

Agent View of the PolicyLayer registry record for Pentest Ai: identity, probed posture, risk grade, and all 51 tools classified. HTML page: https://policylayer.com/tools/0xsteph-pentest-ai

## Facts

- Server id: `0xsteph/pentest-ai`
- Homepage: https://github.com/0xSteph/pentest-ai
- Registry record: grade F, identity unverified
- Lifecycle: active
- Rate-limited: no
- Tools: 51
- Tool categories present: Execute, Read, Write
- Tags: 0xsteph pentest ai, automation
- Record last modified: 2026-06-10T22:13:45.684Z

## Tools (51)

| Tool | Category | Risk | Record |
| --- | --- | --- | --- |
| `kill_process` | Destructive | Critical | https://policylayer.com/tools/0xsteph-pentest-ai/kill-process.md |
| `authenticated_scan` | Execute | High | https://policylayer.com/tools/0xsteph-pentest-ai/authenticated-scan.md |
| `builtin_scan` | Execute | High | https://policylayer.com/tools/0xsteph-pentest-ai/builtin-scan.md |
| `ensure_tools_installed` | Execute | High | https://policylayer.com/tools/0xsteph-pentest-ai/ensure-tools-installed.md |
| `http_request` | Execute | High | https://policylayer.com/tools/0xsteph-pentest-ai/http-request.md |
| `plan_tools` | Execute | High | https://policylayer.com/tools/0xsteph-pentest-ai/plan-tools.md |
| `resume_engagement` | Execute | High | https://policylayer.com/tools/0xsteph-pentest-ai/resume-engagement.md |
| `run_probe` | Execute | High | https://policylayer.com/tools/0xsteph-pentest-ai/run-probe.md |
| `run_recon` | Execute | High | https://policylayer.com/tools/0xsteph-pentest-ai/run-recon.md |
| `run_tool` | Execute | High | https://policylayer.com/tools/0xsteph-pentest-ai/run-tool.md |
| `scan_dns_builtin` | Execute | High | https://policylayer.com/tools/0xsteph-pentest-ai/scan-dns-builtin.md |
| `scan_ports_builtin` | Execute | High | https://policylayer.com/tools/0xsteph-pentest-ai/scan-ports-builtin.md |
| `select_agent` | Execute | High | https://policylayer.com/tools/0xsteph-pentest-ai/select-agent.md |
| `start_campaign` | Execute | High | https://policylayer.com/tools/0xsteph-pentest-ai/start-campaign.md |
| `start_engagement` | Execute | High | https://policylayer.com/tools/0xsteph-pentest-ai/start-engagement.md |
| `test_active_directory` | Execute | High | https://policylayer.com/tools/0xsteph-pentest-ai/test-active-directory.md |
| `test_api_security` | Execute | High | https://policylayer.com/tools/0xsteph-pentest-ai/test-api-security.md |
| `test_cloud` | Execute | High | https://policylayer.com/tools/0xsteph-pentest-ai/test-cloud.md |
| `test_credentials` | Execute | High | https://policylayer.com/tools/0xsteph-pentest-ai/test-credentials.md |
| `test_mobile` | Execute | High | https://policylayer.com/tools/0xsteph-pentest-ai/test-mobile.md |
| `test_privesc` | Execute | High | https://policylayer.com/tools/0xsteph-pentest-ai/test-privesc.md |
| `test_social_engineering` | Execute | High | https://policylayer.com/tools/0xsteph-pentest-ai/test-social-engineering.md |
| `test_vulnerabilities` | Execute | High | https://policylayer.com/tools/0xsteph-pentest-ai/test-vulnerabilities.md |
| `test_web_app` | Execute | High | https://policylayer.com/tools/0xsteph-pentest-ai/test-web-app.md |
| `test_wireless` | Execute | High | https://policylayer.com/tools/0xsteph-pentest-ai/test-wireless.md |
| `validate_finding` | Execute | High | https://policylayer.com/tools/0xsteph-pentest-ai/validate-finding.md |
| `browser_inspect` | Read | Low | https://policylayer.com/tools/0xsteph-pentest-ai/browser-inspect.md |
| `discover_attack_chains` | Read | Low | https://policylayer.com/tools/0xsteph-pentest-ai/discover-attack-chains.md |
| `get_attack_chains` | Read | Low | https://policylayer.com/tools/0xsteph-pentest-ai/get-attack-chains.md |
| `get_campaign_summary` | Read | Low | https://policylayer.com/tools/0xsteph-pentest-ai/get-campaign-summary.md |
| `get_config` | Read | Low | https://policylayer.com/tools/0xsteph-pentest-ai/get-config.md |
| `get_engagement_status` | Read | Low | https://policylayer.com/tools/0xsteph-pentest-ai/get-engagement-status.md |
| `get_engagement_summary` | Read | Low | https://policylayer.com/tools/0xsteph-pentest-ai/get-engagement-summary.md |
| `get_evidence` | Read | Low | https://policylayer.com/tools/0xsteph-pentest-ai/get-evidence.md |
| `get_findings` | Read | Low | https://policylayer.com/tools/0xsteph-pentest-ai/get-findings.md |
| `health` | Read | Low | https://policylayer.com/tools/0xsteph-pentest-ai/health.md |
| `list_engagements` | Read | Low | https://policylayer.com/tools/0xsteph-pentest-ai/list-engagements.md |
| `list_plugins` | Read | Low | https://policylayer.com/tools/0xsteph-pentest-ai/list-plugins.md |
| `list_probes` | Read | Low | https://policylayer.com/tools/0xsteph-pentest-ai/list-probes.md |
| `list_processes` | Read | Low | https://policylayer.com/tools/0xsteph-pentest-ai/list-processes.md |
| `list_tools` | Read | Low | https://policylayer.com/tools/0xsteph-pentest-ai/list-tools.md |
| `poll_oob` | Read | Low | https://policylayer.com/tools/0xsteph-pentest-ai/poll-oob.md |
| `query_compliance` | Read | Low | https://policylayer.com/tools/0xsteph-pentest-ai/query-compliance.md |
| `scan_headers_builtin` | Read | Low | https://policylayer.com/tools/0xsteph-pentest-ai/scan-headers-builtin.md |
| `scan_paths_builtin` | Read | Low | https://policylayer.com/tools/0xsteph-pentest-ai/scan-paths-builtin.md |
| `scan_secrets_builtin` | Read | Low | https://policylayer.com/tools/0xsteph-pentest-ai/scan-secrets-builtin.md |
| `scan_ssl_builtin` | Read | Low | https://policylayer.com/tools/0xsteph-pentest-ai/scan-ssl-builtin.md |
| `close_engagement` | Write | Medium | https://policylayer.com/tools/0xsteph-pentest-ai/close-engagement.md |
| `generate_detection_rules` | Write | Medium | https://policylayer.com/tools/0xsteph-pentest-ai/generate-detection-rules.md |
| `generate_report` | Write | Medium | https://policylayer.com/tools/0xsteph-pentest-ai/generate-report.md |
| `set_intensity` | Write | Medium | https://policylayer.com/tools/0xsteph-pentest-ai/set-intensity.md |

## Tool descriptions

- `authenticated_scan` — Run a deterministic authenticated web scan (no LLM required). Logs in, crawls same-host pages, probes each parameterized endpoint with SQLi/XSS/command-injection payloads. Returns structured findings suitable for the findings database. R…
- `builtin_scan` — Run built-in security scans without requiring any external tools. Works immediately after install. Scan types: all, ports, headers, ssl, paths, dns, secrets. Includes: port scanning, HTTP header analysis, SSL/TLS checks, sensitive path d…
- `resume_engagement` — Resume an interrupted engagement from its last checkpoint. Returns immediately with status='running' and runs the resume in a background task — same async-task pattern as start_engagement (commit f2c58d3) so the MCP client doesn't time o…
- `run_recon` — Start a reconnaissance scan against a target. Returns immediately with an engagement_id while the recon agent runs asynchronously. Poll get_engagement_status(engagement_id) for status and get_findings(engagement_id=...) for results. Dept…
- `run_tool` — Run a specific security tool against a target. Returns structured results that are automatically stored in the findings database.
- `scan_dns_builtin` — Perform DNS enumeration (built-in).
- `scan_ports_builtin` — Scan common ports on a target (built-in, no nmap required).
- `start_campaign` — Start a multi-target campaign. Creates one engagement per target. Accepts a list of IPs, hostnames, or URLs.
- `start_engagement` — Start a new pentest engagement against a target. AUTHORIZED TARGETS ONLY. This initiates reconnaissance and begins the automated assessment. All findings are stored and correlated in the findings database. Poll get_engagement_status(eng_…
- `test_active_directory` — Run Active Directory security assessment. Includes: BloodHound enumeration, Kerberoasting, AS-REP roasting, privilege escalation paths, delegation attacks, and domain dominance. Recommended (secure): pass auth_profile = name of an ntlm p…
- `test_api_security` — Run API security testing (REST + GraphQL) following OWASP API Top 10. Tests for: BOLA/IDOR, JWT alg-confusion, OAuth callback validation, rate-limit bypass, mass assignment, GraphQL introspection. Returns immediately with engagement_id; …
- `test_cloud` — Run cloud security assessment. Providers: aws, azure, gcp Tests for: Misconfigurations, exposed secrets, overly permissive IAM, vulnerable services, and privilege escalation paths. Recommended (secure): pass auth_profile = name of a prof…
- `test_credentials` — Run authentication testing (default creds, password spray, MFA bypass). Lockout-aware. Prefers spraying over brute force on production targets. Returns immediately with engagement_id; agent runs asynchronously.
- `test_mobile` — Run mobile app security testing (Android or iOS). Static + dynamic analysis. OWASP Mobile Top 10 coverage. Returns immediately with engagement_id; agent runs asynchronously.
- `test_privesc` — Run privilege escalation enumeration on a compromised host. Platforms: linux, windows, container. Uses linpeas/winpeas/deepce plus kernel-exploit-suggester. Enumeration only by default. Returns immediately with engagement_id; agent runs …
- `test_social_engineering` — Run a social engineering assessment (phishing simulation, OSINT, DMARC audit). Returns immediately with engagement_id; agent runs asynchronously.
- `test_vulnerabilities` — Run vulnerability scanning (Nuclei + RouterSploit + nikto + dirb). De-duplicates against findings already in the engagement, filters false positives, scores by CVSS + EPSS exploit probability. Returns immediately with engagement_id; agen…
- `test_wireless` — Run wireless security assessment (WiFi + Bluetooth). Returns immediately with engagement_id; agent runs asynchronously.
- `validate_finding` — Validate a specific finding with a safe, non-destructive proof of concept. Confirms the vulnerability is real and exploitable without causing damage. Runs asynchronously (PoC execution can take 30-120s); returns immediately with status='…
- `browser_inspect` — Inspect a URL with the headless browser. Actions: headers (security headers), dom (forms+links+scripts), network (request log), forms, cookies, screenshot.
- `discover_attack_chains` — Discover attack chains from existing findings. Analyzes all findings for an engagement and identifies how they can be chained together to achieve full system compromise.
- `get_attack_chains` — Get discovered attack chains for an engagement. Shows how individual findings chain together into full compromise paths.
- `get_campaign_summary` — Get aggregated summary across all engagements in a campaign.
- `get_config` — Get current pentest-ai configuration (secrets masked).
- `get_engagement_status` — Get the current status of a pentest engagement.
- `get_engagement_summary` — Get a summary of an engagement including finding counts, chains, and rules.
- `get_evidence` — Retrieve evidence artifacts for an engagement or specific finding. Always returns the on-disk SHA-256 per artifact so callers can compare it against the hash stored in a finding's evidence_artifacts field to detect tampering. Args: inclu…
- `list_engagements` — List all pentest engagements, optionally filtered by status.
- `list_plugins` — List installed YAML plugins from ~/.pentest-ai/plugins/.
- `list_probes` — List every registered web probe with its metadata. Use this to discover what bug classes ptai can test for. The LLM driving an engagement picks probes by name and calls run_probe. Filters: - bug_class: only return probes for this bug cla…
- `list_processes` — List running tool subprocesses tracked by the engine. Each entry includes pid, tool, target, runtime_seconds, engagement_id, and cmd. Useful for monitoring long-running scans (nuclei, masscan, full-portscan nmap) and deciding whether to …
- `list_tools` — List all available security tools, optionally filtered by category. Categories: network, web, password, binary, cloud, osint
- `poll_oob` — Poll the OOB collaborator server for callbacks raised by recent probes; materialize confirmed findings. Call after firing probes that emit OOB payloads (blind SSRF / SQLi / XXE / RCE / stored XSS / SSTI / Log4Shell). The tool polls the c…
- `query_compliance` — Query compliance mapping for an engagement's findings. Frameworks: pci_dss, hipaa, soc2, owasp, all Returns findings grouped by compliance control.
- `scan_headers_builtin` — Analyze HTTP security headers (built-in).
- `scan_paths_builtin` — Scan for common sensitive paths (built-in).
- `scan_secrets_builtin` — Scan HTTP responses for leaked secrets and credentials (built-in).
- `scan_ssl_builtin` — Check SSL/TLS configuration (built-in).
- `close_engagement` — Close an engagement and mark it as completed.
- `generate_detection_rules` — Generate detection rules (Sigma, SPL, KQL) for all discovered attacks. Every offensive technique gets a corresponding detection rule for blue teams. Runs asynchronously; returns immediately with status='running'. Rules attach to findings…
- `generate_report` — Generate a professional pentest report (asynchronous). Formats: markdown, html, pdf, json Includes executive summary, technical findings, attack chains, proof of concepts, remediation guidance, and detection rules. Returns immediately wi…
- `set_intensity` — Change scan intensity (stealth, normal, aggressive) mid-engagement. Persists to DB. If the engagement is currently running, also updates the live rate limiter so subsequent phases respect the new pace immediately.

## Related servers

- UnClick (1658 tools) — https://policylayer.com/tools/io-github-malamutemayhem-unclick-mcp-server.md
- Nodebench (824 tools) — https://policylayer.com/tools/io-github-homenshum-nodebench.md
- Binance MCP Server (734 tools) — https://policylayer.com/tools/nirholas-binance-mcp.md
- Crawlora (728 tools) — https://policylayer.com/tools/crawlora-mcp.md
- Yaver (646 tools) — https://policylayer.com/tools/io-github-kivanccakmak-yaver.md
- MCP Framework Personal (643 tools) — https://policylayer.com/tools/inggerman-mcps.md
- Crow (587 tools) — https://policylayer.com/tools/kh0pper-crow.md
- Fortimanager (584 tools) — https://policylayer.com/tools/jmpijll-fortimanager-mcp.md

## For agents

This record is a snapshot. Live verdicts and the full registry:

- Check every server in your MCP config at once: `npx -y policylayer stack`
- Vet a server before you add it: install the mcp-precheck skill — `npx skills add https://policylayer.com` (skill text: https://policylayer.com/skill.md)
- Query the registry over MCP: endpoint `https://api.policylayer.com/mcp` — tools `check_mcp_server`, `check_mcp_stack`, `check_tool`, `search_registry`, `get_change_events`

---

Source: the PolicyLayer MCP registry — one continuously verified record per MCP server. Full record: https://policylayer.com/registry?q=0xsteph-pentest-ai · API: https://policylayer.com/registry/api · Recommended policies for every tool: https://policylayer.com/policies/0xsteph-pentest-ai
