- Reasoning the way each vendor expects it — adaptive thinking, effort levels, thinking budgets, and a real "off" are sent in each model family's native form. Combinations a vendor would reject are…
- Three new providers — MiniMax, Mistral, and xAI, for 13 provider types in total. Any other OpenAI-compatible endpoint works through the custom provider, which now also calls Azure OpenAI…
- Tested, not just listed — every built-in provider, plus example configurations for OpenRouter, DeepInfra, Ollama Cloud, self-hosted vLLM, and others, ships with a ctester report in examples/tests/…
- Current catalogues — GPT-6, Claude Opus 5.x and Fable 5.x, Gemini 3.x, Qwen 3.8, GLM 5.3, DeepSeek V4, and Grok 4.7, with prices checked against vendor pages. Agent chains are compacted to the…
- Provider failover — LLMFALLBACKPROVIDER repeats a failed model call on a second configured provider and records the switch in the trace.
- Anthropic without a long-lived key — Workload Identity Federation exchanges a Kubernetes, GitHub Actions, or other OIDC token for a short-lived Claude token.
PentAGI by VXControl
Overview
A self-hosted multi-agent system that carries out penetration testing tasks in a sandboxed environment, written in Go and React and working with several model providers.
The GitHub repository has 25.3K stars, 3,018 of them added in the last 30 days. The latest stable release is 2.2.0, published Oct 5, 2026; there were 1 stable releases in the past 30 days.
PentAGI usage and attention over time
Download the raw daily series: pentagi.csv
Install PentAGI
| Docker | docker pull vxcontrol/pentagi |
|---|
These commands use the packages tracked on this page. The vendor may recommend a different installer; see the official documentation.
Key facts
| Maker | VXControl |
|---|---|
| Type | Open-source autonomous penetration testing agent |
| First released | January 2025 |
| License | MIT |
| Main language | Go |
| Open issues and PRs | 19 |
| Docker Hub pulls | 350,038 |
Pricing
Free and open source (MIT), self-hosted; users pay their own model costs.
Source: official pricing page, checked Oct 6, 2026. Prices change often; confirm before you buy.
Pulse Score breakdown
Each component is scored 0 to 100 from public signals; a dash means no data for it. Methodology.
PentAGI news and signals
-
101 agents added to AgentGid
DeepSeek Harness, CopilotKit, Orca, eve, ARTEMIS, Jasper, Harvey, Paradox, Eightfold AI Interviewer, TesterArmy e2e, Copy.ai, Consensus and 89 more
-
PentAGI 2.2.0 released
Reasoning the way each vendor expects it — adaptive thinking, effort levels, thinking budgets, and a real "off" are sent in each model family's native form. Combinations a vendor would reject are…; Three new providers — MiniMax, Mistral, and xAI, for 13…
What changed: recent PentAGI releases
1 stable releases in the last 90 days · Full changelog
- User Resources — a persistent, per-user file library with MD5-deduplicated storage and a virtual path filesystem. Full REST and GraphQL CRUD (upload, mkdir, move, copy, delete, download),…
- Flow files — per-flow workspace files that sync into worker containers at /work/uploads and /work/resources. Files can be pulled back out of a running container and promoted into the user library.…
- File Manager UI — a reusable tree component with multi-select, keyboard navigation, drag-and-drop, sortable columns, bulk actions, and an overwrite workflow. Used by both the new /resources page…
- Limits and hardening — enforced on both ends: 300 MB per file, 1000 files per request, 2 GB total, 255-byte names. Upload paths are protected against directory traversal and symlink escapes.
- GraphQL/REST CRUD plus semantic search over the knowledge store, with admin/user scoping, per-user document ownership, re-embedding on update, and real-time subscriptions.
- A new /knowledges interface with list and detail pages, a TipTap markdown editor, partial updates, inline rename/delete, and a collapsible semantic-search input (hotkey-accessible).
- Token usage and cost breakdown per flow and per agent type (primary, pentester, coder, installer, searcher, adviser, etc.)
- Cache hit rates and cache read/write cost separation for Anthropic and Gemini providers
- Tool call frequency and execution time metrics per flow and subtask
- Per-model cost detail, useful when running multiple provider configurations simultaneously
- AGENTPLANNINGSTEPENABLED=true — enables a planning step before each specialist agent starts work, where a planner generates a 3–7 step execution plan to scope the subtask and prevent drift.
- EXECUTIONMONITORENABLED=true — enables automatic detection of unproductive agent behavior: consecutive identical tool calls (EXECUTIONMONITORSAMETOOLLIMIT, default 5) and excessive exploration…
- Gemini 2.5/3.0 family with thinking tokens support
- Anthropic Claude Sonnet 4+ with extended reasoning
- DeepSeek R1 and Kimi K2.5 in reasoning mode
- OpenAI o-series models with signature thoughts
- OpenRouter and OpenAI-compatible endpoints with reasoning content preservation
- Native caching support for Anthropic (ephemeral cache controls) and Gemini (pre-created content caching)
- Fixed Gemini provider compatibility issues preventing proper LiteLLM integration
- All providers now support LiteLLM passthrough mode with standardized endpoints
- Anthropic
- Tested and verified with LiteLLM v1.80.11-stable.1
- Enhanced Gemini provider with custom HTTP transport for API key injection and URL rewriting
- Changed file mounting scheme in PentAGI container to resolve Windows path format issues
- Added stop reason to error messages when LLM fails to generate tool calls
- If stop reason is length, increase maxtokens parameter for the affected agent in provider settings
- Improves troubleshooting and configuration optimization
- Migrated to new DuckDuckGo API with HTML response parsing
- Added comprehensive test coverage with real-world search scenarios
- Significantly improved reliability and result quality
PentAGI alternatives
| # | Agent | Pulse | Downloads 7d | 7d | 30d | VS Code installs | Stars | Latest release | Price | Last 90 days | |
|---|---|---|---|---|---|---|---|---|---|---|---|
| 156 |
StrixStrix |
24 | 8,244 | up 9.7% | down 57.0% | — | 66.8K+197/day | 1.7.0yesterday | Free + $29/mo | ||
| 185 |
NodeZeroHorizon3.ai |
18 | — | — | — | — | — | — | Custom | — | |
| 209 |
XBOWXBOW |
11 | — | — | — | — | — | — | Usage-based | ||
| 210 |
CAI (Cybersecurity AI)Alias Robotics |
10 | 686 | up 58.8% | down 46.7% | — | 9,847+2/day | — | Free | ||
| 227 |
Dropzone AIDropzone AI |
0 | — | — | — | — | — | — | Custom | — | |
| 250 |
Microsoft Security Copilot agentsMicrosoft |
— | — | — | — | — | — | — | Usage-based | — | |
| No agents match that filter. | |||||||||||
Head to head: PentAGI vs Strix · PentAGI vs NodeZero · PentAGI vs XBOW · PentAGI vs CAI (Cybersecurity AI)
PentAGI FAQ
How much does PentAGI cost?
Free and open source (MIT), self-hosted; users pay their own model costs.
Is PentAGI open source?
Yes. PentAGI is open source, released under the MIT license.
How popular is PentAGI?
The GitHub repository has 25.3K stars, 3,018 of them added in the last 30 days. The latest stable release is 2.2.0, published Oct 5, 2026; there were 1 stable releases in the past 30 days.
What is the latest version of PentAGI?
The latest stable release we track is 2.2.0, published on Oct 5, 2026.
What are the alternatives to PentAGI?
The closest alternatives in the same category by Pulse Score are Strix, NodeZero, XBOW, CAI (Cybersecurity AI).
Where these numbers come from
GitHub: vxcontrol/pentagi. Site rank: pentagi.com on the Tranco list. See data sources for how each one is collected.
Product facts and pricing were checked against: github.com, hub.docker.com.
