# start_engagement

Start a new pentest engagement against a target. AUTHORIZED TARGETS ONLY. This initiates reconnaissance and begins the automated assessment. All findings are stored and correlated in the findings database. Poll get_engagement_status(eng_id) for phase progress. The caller (LLM agent and the human operator behind it) MUST have written authorization to test the target. See pentestai.xyz/aup. Pass auth_profile to log into the target before scanning. Use the secure credential-resolver path (pentest-ai auth profile add) so secrets never enter the MCP/LLM payload. Without it, auth-gated bug classes (race conditions, mass assignment, type confusion, authenticated SQLi/XXE/IDOR) cannot be reached. Pass respect_rate_limits=True to honor HTTP 429 / Retry-After responses with exponential backoff (capped at 30s, 3 retries). Recommended for real bug-bounty targets behind WAFs; default off preserves today's behavior. Pass strict_scope=True to refuse any request whose host is outside the engagement target's host. Also disables redirect- following in primitives so a 302 to attacker.com cannot pull the scan off-target. Bug-bounty programs care a lot about scope discipline; default off preserves today's wide-open behavior.

Agent View of the PolicyLayer registry record for `start_engagement`. HTML page: https://policylayer.com/tools/0xsteph-pentest-ai/start-engagement

## Facts

- Tool: `start_engagement`
- Server: Pentest Ai (`0xsteph/pentest-ai`) — https://policylayer.com/tools/0xsteph-pentest-ai.md
- Homepage: https://github.com/0xSteph/pentest-ai
- Risk category: Execute (High risk)
- Registry record: grade F, identity unverified
- Server rate-limited: no
- Parameters: 0
- Recommended policy verdict: Rate-limited

## Example call (MCP tools/call, JSON-RPC 2.0)

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "start_engagement",
    "arguments": {}
  }
}
```

## Why start_engagement is rated High

This tool executes external security operations (reconnaissance, scanning) against specified targets with real-world consequences. While it includes an authorization gate ('AUTHORIZED TARGETS ONLY'), the tool itself performs active operations that can trigger alerts, disrupt services, or generate significant logs depending on target configuration.

From the tool's own definition: "'Start a new pentest engagement against a target' and 'initiates reconnaissance and begins the automated assessment' — the tool executes real penetration testing operations against network targets, triggering security scanning and data collection whose…"

## Use case

AI agents invoke start_engagement to trigger actions in Pentest Ai. What it does depends on the arguments the agent supplies, and its effects often reach beyond the immediate call: builds kicked off, notifications sent, workflows started.

## Recommended policy (PolicyLayer)

Verdict: **Rate-limited**. Enforced by the PolicyLayer MCP gateway (https://policylayer.com/mcp-gateway) before a call reaches Pentest Ai:

```json
{
  "version": "1",
  "default": "deny",
  "tools": {
    "start_engagement": {
      "limits": [
        {
          "counter": "start_engagement_rate",
          "window": "minute",
          "max": 10,
          "scope": "grant"
        }
      ]
    }
  }
}
```

## Other tools on Pentest Ai (50)

- `kill_process` — Destructive — https://policylayer.com/tools/0xsteph-pentest-ai/kill-process.md
- `authenticated_scan` — Execute — https://policylayer.com/tools/0xsteph-pentest-ai/authenticated-scan.md
- `builtin_scan` — Execute — https://policylayer.com/tools/0xsteph-pentest-ai/builtin-scan.md
- `ensure_tools_installed` — Execute — https://policylayer.com/tools/0xsteph-pentest-ai/ensure-tools-installed.md
- `http_request` — Execute — https://policylayer.com/tools/0xsteph-pentest-ai/http-request.md
- `plan_tools` — Execute — https://policylayer.com/tools/0xsteph-pentest-ai/plan-tools.md
- `resume_engagement` — Execute — https://policylayer.com/tools/0xsteph-pentest-ai/resume-engagement.md
- `run_probe` — Execute — https://policylayer.com/tools/0xsteph-pentest-ai/run-probe.md
- `run_recon` — Execute — https://policylayer.com/tools/0xsteph-pentest-ai/run-recon.md
- `run_tool` — Execute — https://policylayer.com/tools/0xsteph-pentest-ai/run-tool.md
- `scan_dns_builtin` — Execute — https://policylayer.com/tools/0xsteph-pentest-ai/scan-dns-builtin.md
- `scan_ports_builtin` — Execute — https://policylayer.com/tools/0xsteph-pentest-ai/scan-ports-builtin.md
- `select_agent` — Execute — https://policylayer.com/tools/0xsteph-pentest-ai/select-agent.md
- `start_campaign` — Execute — https://policylayer.com/tools/0xsteph-pentest-ai/start-campaign.md
- `test_active_directory` — Execute — https://policylayer.com/tools/0xsteph-pentest-ai/test-active-directory.md
- `test_api_security` — Execute — https://policylayer.com/tools/0xsteph-pentest-ai/test-api-security.md
- `test_cloud` — Execute — https://policylayer.com/tools/0xsteph-pentest-ai/test-cloud.md
- `test_credentials` — Execute — https://policylayer.com/tools/0xsteph-pentest-ai/test-credentials.md
- `test_mobile` — Execute — https://policylayer.com/tools/0xsteph-pentest-ai/test-mobile.md
- `test_privesc` — Execute — https://policylayer.com/tools/0xsteph-pentest-ai/test-privesc.md
- `test_social_engineering` — Execute — https://policylayer.com/tools/0xsteph-pentest-ai/test-social-engineering.md
- `test_vulnerabilities` — Execute — https://policylayer.com/tools/0xsteph-pentest-ai/test-vulnerabilities.md
- `test_web_app` — Execute — https://policylayer.com/tools/0xsteph-pentest-ai/test-web-app.md
- `test_wireless` — Execute — https://policylayer.com/tools/0xsteph-pentest-ai/test-wireless.md
- `validate_finding` — Execute — https://policylayer.com/tools/0xsteph-pentest-ai/validate-finding.md
- `browser_inspect` — Read — https://policylayer.com/tools/0xsteph-pentest-ai/browser-inspect.md
- `discover_attack_chains` — Read — https://policylayer.com/tools/0xsteph-pentest-ai/discover-attack-chains.md
- `get_attack_chains` — Read — https://policylayer.com/tools/0xsteph-pentest-ai/get-attack-chains.md
- `get_campaign_summary` — Read — https://policylayer.com/tools/0xsteph-pentest-ai/get-campaign-summary.md
- `get_config` — Read — https://policylayer.com/tools/0xsteph-pentest-ai/get-config.md
- …and 20 more: https://policylayer.com/tools/0xsteph-pentest-ai.md

## For agents

This record is a snapshot. Live verdicts and the full registry:

- Check every server in your MCP config at once: `npx -y policylayer stack`
- Vet a server before you add it: install the mcp-precheck skill — `npx skills add https://policylayer.com` (skill text: https://policylayer.com/skill.md)
- Query the registry over MCP: endpoint `https://api.policylayer.com/mcp` — tools `check_mcp_server`, `check_mcp_stack`, `check_tool`, `search_registry`, `get_change_events`

---

Source: the PolicyLayer MCP registry — one continuously verified record per MCP server. Full record: https://policylayer.com/registry?q=0xsteph-pentest-ai · API: https://policylayer.com/registry/api · Policy library: https://policylayer.com/policies/0xsteph-pentest-ai
