Zen-Ai-Pentest Framework Skill

SkillSecurity

Lets your agent run automated penetration tests against targets and generate vulnerability findings and reports.

Available today. Use it from your connected AI after setup.

Add ahel to your AI once: Claude, ChatGPT, Cursor, Claude Code or Codex. Then ask it to use this.

Then ask your AI: use the Zen-Ai-Pentest Framework Skill skill

About this skill

πŸ›‘βš”οΈAI-Powered Penetration Testing Framework with automated vulnerability scanning, multi-agent system, and compliance reportingπŸ›‘βš”οΈ

What this skill tells your AI

The instructions your AI receives, as published by shadd0wtaka/zen-ai-pentest in skills/zen-framework/SKILL.md and read by ahel’s review.

Complete guide to the Zen-Ai-Pentest autonomous pentesting framework architecture.

Project Structure

zen-ai-pentest/
β”œβ”€β”€ agents/              # ReAct AI agents (11 specialized personas)
β”œβ”€β”€ api/                 # FastAPI backend + WebSocket
β”œβ”€β”€ core/                # Orchestrator, models, caching
β”œβ”€β”€ tools/               # 72+ integrated security tools
β”œβ”€β”€ risk_engine/         # CVSS, EPSS, false positive detection
β”œβ”€β”€ modules/             # Scanner, exploit modules
β”œβ”€β”€ web_ui/              # React frontend + dashboard
β”œβ”€β”€ database/            # PostgreSQL models (SQLAlchemy)
β”œβ”€β”€ reports/             # PDF/HTML/DOCX generator
β”œβ”€β”€ docker/              # Dockerfiles + compose
β”œβ”€β”€ tests/               # 43,000+ tests (unit, integration, security)
└── mcp/                 # MCP servers (8 total)

Key Components

Agent System

from agents.react_agent import ReActAgent, ReActAgentConfig

config = ReActAgentConfig(max_iterations=10, use_vm=False)
agent = ReActAgent(config)
result = agent.run(target="example.com", objective="Full security assessment")

11 Personas

PersonaCLIPurpose
Reconnaissancedeep-reconOSINT, subdomain, port scan
Exploitationdeep-exploitCVE matching, sandboxed exec
Analysisdeep-analyzeFP detection, CVSS scoring
Reportingdeep-reportPDF/HTML generation
Red Teamdeep-redteamFull adversarial simulation
Social Engineeringdeep-socialPhishing, OSINT
Networkdeep-networkInfrastructure testing
Clouddeep-cloudAWS/Azure/GCP
ICSdeep-icsSCADA/industrial
Mobiledeep-mobileiOS/Android
Cryptodeep-cryptoTLS, cert, cipher analysis

Risk Engine

from risk_engine.false_positive_engine import FalsePositiveEngine

engine = FalsePositiveEngine()
score = engine.assess_finding({"vuln_type": "xss", "confidence": 0.85})
# Combines Bayesian + multi-model voting

Guardrails

  • Private IP blocking (10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16)
  • Risk levels 0-3 (SAFE β†’ AGGRESSIVE)
  • Read-only default, --force for exploitation
  • Timeout management (10min max)

MCP Servers

# 8 MCP servers registered in opencode.jsonc
mcp/obscura/      # Encrypted secret vault
mcp/ip-tracker/   # Visitor IP tracking
mcp/omni-ai/      # AI chat via OmniRoute
mcp/qterminal/    # Shell/Docker orchestration
mcp/metasploit/   # Metasploit RPC connector
mcp/vpn-killswitch/# Connection-loss failover
mcp/zen-agents/   # 11-agent orchestration

Signals

GitHub stars
469
Forks
81
Last commit
Sep 2026
Advanced
Item type
skill
Key
zen-framework
Source
github.com/shadd0wtaka/zen-ai-pentest