PentestMCP: A Toolkit for Agentic Penetration Testing
Fuente:
arXiv
Saved in:
| Main Authors: | , |
|---|---|
| Format: | Preprint |
| Published: |
2025
|
| Subjects: | |
| Online Access: | |
| Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
| _version_ | 1866909823876988928 |
|---|---|
| author | Ezetta, Zachary Feng, Wu-chang |
| author_facet | Ezetta, Zachary Feng, Wu-chang |
| contents | Agentic AI is transforming security by automating many tasks being performed manually. While initial agentic approaches employed a monolithic architecture, the Model-Context-Protocol has now enabled a remote-procedure call (RPC) paradigm to agentic applications, allowing for the flexible construction and composition of multi-function agents. This paper describes PentestMCP, a library of MCP server implementations that support agentic penetration testing. By supporting common penetration testing tasks such as network scanning, resource enumeration, service fingerprinting, vulnerability scanning, exploitation, and post-exploitation, PentestMCP allows a developer to customize multi-agent workflows for performing penetration tests. |
| format | Preprint |
| id |
arxiv_https___arxiv_org_abs_2510_03610 |
| institution | arXiv |
| publishDate | 2025 |
| record_format | arxiv |
| spellingShingle | PentestMCP: A Toolkit for Agentic Penetration Testing Ezetta, Zachary Feng, Wu-chang Cryptography and Security Artificial Intelligence Agentic AI is transforming security by automating many tasks being performed manually. While initial agentic approaches employed a monolithic architecture, the Model-Context-Protocol has now enabled a remote-procedure call (RPC) paradigm to agentic applications, allowing for the flexible construction and composition of multi-function agents. This paper describes PentestMCP, a library of MCP server implementations that support agentic penetration testing. By supporting common penetration testing tasks such as network scanning, resource enumeration, service fingerprinting, vulnerability scanning, exploitation, and post-exploitation, PentestMCP allows a developer to customize multi-agent workflows for performing penetration tests. |
| title | PentestMCP: A Toolkit for Agentic Penetration Testing |
| topic | Cryptography and Security Artificial Intelligence |
| url | https://arxiv.org/abs/2510.03610 |