PentestMCP: A Toolkit for Agentic Penetration Testing
Ezetta, Zachary, Feng, Wu-chang
–arXiv.org Artificial Intelligence
Agentic AI is transforming security by automating many tasks being performed manually. While initial agentic approaches employed a monolithic architecture, the Model-Context-Protocol has now enabled a remote-procedure call (RPC) paradigm to agen-tic applications, allowing for the flexible construction and composition of multi-function agents. This paper describes PentestMCP, a library of MCP server implementations that support agentic penetration testing. By supporting common penetration testing tasks such as network scanning, resource enumeration, service fingerprinting, vulnerability scanning, exploitation, and post-exploitation, PentestMCP allows a developer to customize multi-agent workflows for performing penetration tests.
arXiv.org Artificial Intelligence
Oct-7-2025
- Genre:
- Research Report (0.64)
- Workflow (0.49)
- Industry:
- Information Technology > Security & Privacy (1.00)
- Technology: