What is Pentagi? An AI-Driven Penetration Testing Automation Platform

Pentagi is an open-source, AI-driven penetration testing platform that automates security assessments through a multi-agent LLM system, eliminating the manual overhead and human error inherent in traditional pentesting workflows.

Pentagi is an open-source, AI-driven platform developed by vxcontrol that transforms the traditionally manual process of penetration testing into an autonomous, repeatable workflow. Hosted in the vxcontrol/pentagi repository, this tool combines a multi-agent LLM system with a scalable micro-services architecture to address the critical shortage of efficient, repeatable, and intelligent automation for security assessments.

The Problem Pentagi Solves: Automating Security Assessments

Traditional penetration testing requires highly skilled engineers to manually orchestrate tools, research vulnerabilities, and compile reports. This approach is prone to human error, limited by individual analyst knowledge and available time, and lacks a unified knowledge base that can be reused across engagements.

Limitations of Manual Penetration Testing

  • Manual orchestration: Security professionals must manually execute and correlate results from dozens of disparate tools like Nmap, Metasploit, and SQLMap.
  • Knowledge fragmentation: Successful exploitation techniques and research findings are typically stored in unstructured notes or individual memory, preventing organizational learning.
  • Reporting overhead: Compiling comprehensive vulnerability reports with exploitation guides consumes significant time that could be spent on actual testing.
  • Context constraints: Human analysts work with limited access to real-time threat intelligence and historical campaign data during active engagements.

How Pentagi Automates Penetration Testing

Pentagi solves these challenges through a containerized, AI-driven architecture that combines specialized LLM agents with professional security utilities. The platform stores all artifacts in a PostgreSQL database with pgvector extension, maintains long-term memory of successful techniques, and isolates all execution within Docker containers to ensure operational security.

Multi-Agent Architecture and Tool Orchestration

At the core of Pentagi is a multi-agent system implemented in backend/pkg/agents/ and managed through backend/pkg/queue/. Specialist AI agents automatically invoke a built-in suite of 20+ sandboxed security tools—including Nmap, Metasploit, and SQLMap—eliminating the need for manual orchestration. The entry point at backend/cmd/pentagi/main.go initializes this system, loading configurations and launching the agent orchestration engine.

Persistent Knowledge and Memory

Pentagi addresses the knowledge fragmentation problem through long-term vector memory that stores research results and successful exploitation techniques. The platform integrates with Graphiti (Neo4j) through backend/pkg/graphiti/ to maintain a knowledge graph of vulnerabilities and attack paths. All data persists in PostgreSQL with pgvector, enabling semantic search across historical engagements and allowing the system to recall and apply prior knowledge to new targets.

Secure Execution Environment

Operational security is ensured through isolated Docker containers that execute all actions. This architecture guarantees that the target environment never touches the host system, preventing cross-contamination and ensuring that potentially malicious payloads or vulnerable tools run in sandboxed environments. The containerization strategy is defined in docker-compose.yml, which orchestrates all core services including the API, databases, and monitoring stacks.

Observability and Monitoring

Pentagi provides comprehensive visibility into agent behavior through a full OpenTelemetry stack including Grafana, Loki, Jaeger, and VictoriaMetrics. Configuration resides in observability/otel/config.yml. Additionally, Langfuse analytics integration offers real-time monitoring of LLM interactions and tool execution, enabling debugging of agent decision-making processes and performance optimization of the multi-agent workflow.

Getting Started with Pentagi

Deploying Pentagi requires Docker and access to LLM API keys. The platform supports multiple model providers including OpenAI, and exposes both GraphQL and REST interfaces for integration.

To run Pentagi locally using Docker Compose:


# Clone the repository

git clone https://github.com/vxcontrol/pentagi.git
cd pentagi

# Copy example environment configuration

curl -o .env https://raw.githubusercontent.com/vxcontrol/pentagi/master/.env.example

# Start all services

docker compose up -d

Once running, create a new penetration testing flow using the GraphQL API defined in backend/pkg/graph/schema.graphqls:

mutation CreateFlow {
  createFlow(
    modelProvider: "openai"
    input: "Test the security of https://example.com"
  ) {
    id
    title
    status
    createdAt
  }
}

For programmatic access, query existing flows via REST:

curl https://your-pentagi-instance:8443/api/v1/flows \
  -H "Authorization: Bearer YOUR_API_TOKEN" | jq '.flows[] | {id, title, status}'

Key Components and Architecture

The Pentagi codebase in vxcontrol/pentagi is organized into distinct layers:

Component Important File(s) Purpose
Entry point backend/cmd/pentagi/main.go Initializes the API server, loads configuration, and launches the agent system.
GraphQL API backend/pkg/graph/schema.graphqls Defines the public schema used by the React frontend and external clients.
Agent system backend/pkg/queue/ and backend/pkg/agents/ Implements async task processing and multi-agent workflow orchestration.
Frontend frontend/src/app.tsx React entry point providing the web console, flow management, and monitoring dashboards.
Infrastructure docker-compose.yml Orchestrates core services including API, PostgreSQL, Neo4j, and observability stacks.
Observability observability/otel/config.yml Configures OpenTelemetry exporters for metrics, traces, and logs.
Knowledge graph backend/pkg/graphiti/ Handles Neo4j integration for attack path visualization and context retention.
Configuration .env.example Documents required variables for LLM providers, search APIs, and authentication.

Summary

Pentagi transforms penetration testing from a manual, expertise-intensive process into an automated, reproducible workflow. Key advantages include:

  • Autonomous multi-agent orchestration of 20+ security tools through specialized LLM agents
  • Persistent knowledge storage via PostgreSQL/pgvector and Neo4j graph databases that retain techniques across engagements
  • Isolated execution environment using Docker containers to maintain operational security
  • Comprehensive observability through OpenTelemetry, Grafana, and Langfuse for real-time debugging of AI decision-making
  • Flexible APIs supporting both GraphQL and REST for integration into existing security pipelines

Frequently Asked Questions

What is Pentagi used for?

Pentagi is used to automate penetration testing and security assessment workflows. Organizations deploy it to continuously evaluate application security, simulate attack scenarios, and generate detailed vulnerability reports without requiring constant manual oversight from senior security engineers.

Is Pentagi suitable for production environments?

Yes, Pentagi is designed for production deployment through its micro-services architecture and Docker containerization. The platform includes production-ready features such as isolated execution environments, comprehensive observability through OpenTelemetry and Grafana, and secure database backends using PostgreSQL and Neo4j.

How does Pentagi differ from traditional pentesting tools?

Unlike traditional tools that require manual operation and interpretation, Pentagi operates as an autonomous system that orchestrates multiple security tools through AI agents. It maintains long-term memory of successful techniques, integrates real-time threat intelligence through web search APIs, and generates structured reports automatically rather than requiring manual compilation.

What LLM providers does Pentagi support?

Pentagi supports multiple model providers including OpenAI, with configuration managed through environment variables defined in .env.example. The GraphQL API accepts a modelProvider parameter when creating flows, allowing teams to select appropriate models for different testing scenarios based on capability requirements and cost considerations.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →