PentAGI is a self-hosted, fully autonomous AI penetration-testing platform from security engineering company VXControl.
A team of specialist agents plans and executes tests inside an isolated Docker sandbox using professional security tools, stores findings in long-term memory, and generates detailed vulnerability reports.
- 01
Autonomous multi-agent delegation for research, development and infrastructure tasks
- 02
Isolated Docker sandbox with 20+ tools including nmap, Metasploit and sqlmap
- 03
Long-term memory in PostgreSQL/pgvector plus optional Graphiti/Neo4j knowledge graph
- 04
Unified web search and built-in scraper browser for gathering current information
- 05
Web UI with REST and GraphQL APIs secured by Bearer tokens
- 06
Supports OpenAI, Anthropic, Gemini, AWS Bedrock, Ollama, DeepSeek and other OpenAI-compatible LLMs
- 07
Grafana/Prometheus monitoring and Docker Compose deployment
Open Source
The self-hosted platform is open source under the MIT license; you pay for your own LLM provider usage and infrastructure. An Enterprise Edition license is available via console.pentagi.com, where new users get one free license; Enterprise pricing is not published in the repository.
Best for
Security engineers and AppSec teams who want a self-hosted, autonomous pentesting agent they can run against their own systems with their choice of LLM.
Not ideal for
Teams looking for lightweight static code review or CI linting, or for breach-and-attack-simulation campaigns, which the project states it does not provide today.
One of the most complete open-source autonomous pentesting stacks, with a real tool suite, memory and monitoring; best suited to security teams comfortable operating a multi-service self-hosted deployment.
PentAGI 2.2 (v2.2.0, 2026-10-05) added tested configurations for current LLM generations, rebuilt sandbox isolation to close CVE-2026-14784, replaced seven search tools with one intent-driven web_search, and enabled multi-instance deployments sharing backing services.
As of
Is PentAGI free?+
Yes - PentAGI is Open Source. The self-hosted platform is open source under the MIT license; you pay for your own LLM provider usage and infrastructure. An Enterprise Edition license is available via console.pentagi.com, where new users get one free license; Enterprise pricing is not published in the repository.
Is PentAGI open source?+
Yes - PentAGI is open source. The self-hosted platform is open source under the MIT license; you pay for your own LLM provider usage and infrastructure. An Enterprise Edition license is available via console.pentagi.com, where new users get one free license; Enterprise pricing is not published in the repository.
Who is PentAGI best for?+
Security engineers and AppSec teams who want a self-hosted, autonomous pentesting agent they can run against their own systems with their choice of LLM.
Who is PentAGI not ideal for?+
Teams looking for lightweight static code review or CI linting, or for breach-and-attack-simulation campaigns, which the project states it does not provide today.
What are the best PentAGI alternatives?+
The closest PentAGI alternatives on ai.dosa.dev are CodeRabbit, Qodo, Snyk Code - all listed under AI Code Review & Security.
Who makes PentAGI?+
PentAGI is developed by VXControl. It is listed in the AI Code Review & Security category on ai.dosa.dev.
Favorite this tool to revisit it later, or Zap it to contribute to the public vote count.