Back to list
High-Potential
Python

🛡️ RedAmon: AI-Driven Penetration Testing Framework

2,933 stars604 forksPython
agentic-aiaiai-pentestingattack-surface-managementautonomous-agentsbug-bountycybersecurityethical-hackingethical-hacking-toolsexploitationkali-linuxllm-agents
The direction here is clear: combining autonomous AI agents with penetration testing. RedAmon maps out an attack surface into a graph and attempts to exploit vulnerabilities from within a Kali Linux sandbox. The interesting part is that it does not run completely unchecked; it includes human approval gates for critical actions and can automatically open pull requests to fix the vulnerabilities it discovers. Its architecture takes full advantage of the Model Context Protocol (MCP) in both directions. You can plug any external MCP server into RedAmon as a tool, or you can drive RedAmon itself from Claude Code or a custom agent. This two-way integration makes it a highly flexible component for teams looking to bridge automated security testing with modern AI developer workflows.