Zen-Ai-Pentest Framework Skill
SkillSecurityLets your agent run automated penetration tests against targets and generate vulnerability findings and reports.
Available today. Use it from your connected AI after setup.
No other account needed.
Add ahel to your AI once: Claude, ChatGPT, Cursor, Claude Code or Codex. Then ask it to use this.
Then ask your AI: use the Zen-Ai-Pentest Framework Skill skill
About this skill
π‘βοΈAI-Powered Penetration Testing Framework with automated vulnerability scanning, multi-agent system, and compliance reportingπ‘βοΈ
What this skill tells your AI
The instructions your AI receives, as published by shadd0wtaka/zen-ai-pentest in skills/zen-framework/SKILL.md and read by ahelβs review.
Complete guide to the Zen-Ai-Pentest autonomous pentesting framework architecture.
Project Structure
zen-ai-pentest/
βββ agents/ # ReAct AI agents (11 specialized personas)
βββ api/ # FastAPI backend + WebSocket
βββ core/ # Orchestrator, models, caching
βββ tools/ # 72+ integrated security tools
βββ risk_engine/ # CVSS, EPSS, false positive detection
βββ modules/ # Scanner, exploit modules
βββ web_ui/ # React frontend + dashboard
βββ database/ # PostgreSQL models (SQLAlchemy)
βββ reports/ # PDF/HTML/DOCX generator
βββ docker/ # Dockerfiles + compose
βββ tests/ # 43,000+ tests (unit, integration, security)
βββ mcp/ # MCP servers (8 total)
Key Components
Agent System
from agents.react_agent import ReActAgent, ReActAgentConfig
config = ReActAgentConfig(max_iterations=10, use_vm=False)
agent = ReActAgent(config)
result = agent.run(target="example.com", objective="Full security assessment")
11 Personas
| Persona | CLI | Purpose |
|---|---|---|
| Reconnaissance | deep-recon | OSINT, subdomain, port scan |
| Exploitation | deep-exploit | CVE matching, sandboxed exec |
| Analysis | deep-analyze | FP detection, CVSS scoring |
| Reporting | deep-report | PDF/HTML generation |
| Red Team | deep-redteam | Full adversarial simulation |
| Social Engineering | deep-social | Phishing, OSINT |
| Network | deep-network | Infrastructure testing |
| Cloud | deep-cloud | AWS/Azure/GCP |
| ICS | deep-ics | SCADA/industrial |
| Mobile | deep-mobile | iOS/Android |
| Crypto | deep-crypto | TLS, cert, cipher analysis |
Risk Engine
from risk_engine.false_positive_engine import FalsePositiveEngine
engine = FalsePositiveEngine()
score = engine.assess_finding({"vuln_type": "xss", "confidence": 0.85})
# Combines Bayesian + multi-model voting
Guardrails
- Private IP blocking (10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16)
- Risk levels 0-3 (SAFE β AGGRESSIVE)
- Read-only default, --force for exploitation
- Timeout management (10min max)
MCP Servers
# 8 MCP servers registered in opencode.jsonc
mcp/obscura/ # Encrypted secret vault
mcp/ip-tracker/ # Visitor IP tracking
mcp/omni-ai/ # AI chat via OmniRoute
mcp/qterminal/ # Shell/Docker orchestration
mcp/metasploit/ # Metasploit RPC connector
mcp/vpn-killswitch/# Connection-loss failover
mcp/zen-agents/ # 11-agent orchestration
Signals
- GitHub stars
- 469
- Forks
- 81
- Last commit
- Sep 2026
Advanced
- Item type
- skill
- Key
zen-framework- Source
- github.com/shadd0wtaka/zen-ai-pentest