Skip to content
Agents tracked: 258 Downloads (7d): 219M up 9.4% GitHub stars: 5.5M VS Code installs: 148M Releases (7d): 282 Agent pull requests (last week): 940K Updated Oct 6, 2026

PentAGI by VXControl

AI security agents #133 overall#1 in categoryOpen source · MIT
Pulse Score
30 / 100
Rank #133 of 258
GitHub stars
25.3K
about +31 a day
Latest release
2.2.0
yesterday · 1 in 30 days
Price
Free (OSS)
checked Oct 6, 2026

Overview

A self-hosted multi-agent system that carries out penetration testing tasks in a sandboxed environment, written in Go and React and working with several model providers.

The GitHub repository has 25.3K stars, 3,018 of them added in the last 30 days. The latest stable release is 2.2.0, published Oct 5, 2026; there were 1 stable releases in the past 30 days.

PentAGI usage and attention over time

GitHub starsrunning total 25.3K

Download the raw daily series: pentagi.csv

Install PentAGI

Dockerdocker pull vxcontrol/pentagi

These commands use the packages tracked on this page. The vendor may recommend a different installer; see the official documentation.

Key facts

MakerVXControl
TypeOpen-source autonomous penetration testing agent
First releasedJanuary 2025
LicenseMIT
Main languageGo
Open issues and PRs19
Docker Hub pulls350,038

Pricing

Free and open source (MIT), self-hosted; users pay their own model costs.

Source: official pricing page, checked Oct 6, 2026. Prices change often; confirm before you buy.

Pulse Score breakdown

Adoption15
Community58
Attention—
Momentum57

Each component is scored 0 to 100 from public signals; a dash means no data for it. Methodology.

PentAGI news and signals

All AI agent news

  1. New on AgentGid AgentGid

    101 agents added to AgentGid

    DeepSeek Harness, CopilotKit, Orca, eve, ARTEMIS, Jasper, Harvey, Paradox, Eightfold AI Interviewer, TesterArmy e2e, Copy.ai, Consensus and 89 more

  2. Release GitHub Releases

    PentAGI 2.2.0 released

    Reasoning the way each vendor expects it — adaptive thinking, effort levels, thinking budgets, and a real "off" are sent in each model family's native form. Combinations a vendor would reject are…; Three new providers — MiniMax, Mistral, and xAI, for 13…

What changed: recent PentAGI releases

1 stable releases in the last 90 days · Full changelog

2.2.0
  • Reasoning the way each vendor expects it — adaptive thinking, effort levels, thinking budgets, and a real "off" are sent in each model family's native form. Combinations a vendor would reject are…
  • Three new providers — MiniMax, Mistral, and xAI, for 13 provider types in total. Any other OpenAI-compatible endpoint works through the custom provider, which now also calls Azure OpenAI…
  • Tested, not just listed — every built-in provider, plus example configurations for OpenRouter, DeepInfra, Ollama Cloud, self-hosted vLLM, and others, ships with a ctester report in examples/tests/…
  • Current catalogues — GPT-6, Claude Opus 5.x and Fable 5.x, Gemini 3.x, Qwen 3.8, GLM 5.3, DeepSeek V4, and Grok 4.7, with prices checked against vendor pages. Agent chains are compacted to the…
  • Provider failover — LLMFALLBACKPROVIDER repeats a failed model call on a second configured provider and records the switch in the trace.
  • Anthropic without a long-lived key — Workload Identity Federation exchanges a Kubernetes, GitHub Actions, or other OIDC token for a short-lived Claude token.
2.1.0
  • User Resources — a persistent, per-user file library with MD5-deduplicated storage and a virtual path filesystem. Full REST and GraphQL CRUD (upload, mkdir, move, copy, delete, download),…
  • Flow files — per-flow workspace files that sync into worker containers at /work/uploads and /work/resources. Files can be pulled back out of a running container and promoted into the user library.…
  • File Manager UI — a reusable tree component with multi-select, keyboard navigation, drag-and-drop, sortable columns, bulk actions, and an overwrite workflow. Used by both the new /resources page…
  • Limits and hardening — enforced on both ends: 300 MB per file, 1000 files per request, 2 GB total, 255-byte names. Upload paths are protected against directory traversal and symlink escapes.
  • GraphQL/REST CRUD plus semantic search over the knowledge store, with admin/user scoping, per-user document ownership, re-embedding on update, and real-time subscriptions.
  • A new /knowledges interface with list and detail pages, a TipTap markdown editor, partial updates, inline rename/delete, and a collapsible semantic-search input (hotkey-accessible).
2.0.0
  • Token usage and cost breakdown per flow and per agent type (primary, pentester, coder, installer, searcher, adviser, etc.)
  • Cache hit rates and cache read/write cost separation for Anthropic and Gemini providers
  • Tool call frequency and execution time metrics per flow and subtask
  • Per-model cost detail, useful when running multiple provider configurations simultaneously
  • AGENTPLANNINGSTEPENABLED=true — enables a planning step before each specialist agent starts work, where a planner generates a 3–7 step execution plan to scope the subtask and prevent drift.
  • EXECUTIONMONITORENABLED=true — enables automatic detection of unproductive agent behavior: consecutive identical tool calls (EXECUTIONMONITORSAMETOOLLIMIT, default 5) and excessive exploration…
1.2.0
  • Gemini 2.5/3.0 family with thinking tokens support
  • Anthropic Claude Sonnet 4+ with extended reasoning
  • DeepSeek R1 and Kimi K2.5 in reasoning mode
  • OpenAI o-series models with signature thoughts
  • OpenRouter and OpenAI-compatible endpoints with reasoning content preservation
  • Native caching support for Anthropic (ephemeral cache controls) and Gemini (pre-created content caching)
1.1.0
  • Fixed Gemini provider compatibility issues preventing proper LiteLLM integration
  • All providers now support LiteLLM passthrough mode with standardized endpoints
  • Anthropic
  • Tested and verified with LiteLLM v1.80.11-stable.1
  • Enhanced Gemini provider with custom HTTP transport for API key injection and URL rewriting
  • Changed file mounting scheme in PentAGI container to resolve Windows path format issues
1.0.1
  • Added stop reason to error messages when LLM fails to generate tool calls
  • If stop reason is length, increase maxtokens parameter for the affected agent in provider settings
  • Improves troubleshooting and configuration optimization
  • Migrated to new DuckDuckGo API with HTML response parsing
  • Added comprehensive test coverage with real-world search scenarios
  • Significantly improved reliability and result quality

PentAGI alternatives

All AI security agents

# Agent Pulse Downloads 7d 7d 30d VS Code installs Stars Latest release Price Last 90 days
156
StrixStrix
24 8,244 up 9.7% down 57.0% — 66.8K+197/day 1.7.0yesterday Free + $29/mo
185
NodeZeroHorizon3.ai
18 — — — — — — Custom —
209
XBOWXBOW
11 — — — — — — Usage-based
210 10 686 up 58.8% down 46.7% — 9,847+2/day — Free
227
Dropzone AIDropzone AI
0 — — — — — — Custom —
250 — — — — — — — Usage-based —

Head to head: PentAGI vs Strix · PentAGI vs NodeZero · PentAGI vs XBOW · PentAGI vs CAI (Cybersecurity AI)

PentAGI FAQ

How much does PentAGI cost?

Free and open source (MIT), self-hosted; users pay their own model costs.

Is PentAGI open source?

Yes. PentAGI is open source, released under the MIT license.

How popular is PentAGI?

The GitHub repository has 25.3K stars, 3,018 of them added in the last 30 days. The latest stable release is 2.2.0, published Oct 5, 2026; there were 1 stable releases in the past 30 days.

What is the latest version of PentAGI?

The latest stable release we track is 2.2.0, published on Oct 5, 2026.

What are the alternatives to PentAGI?

The closest alternatives in the same category by Pulse Score are Strix, NodeZero, XBOW, CAI (Cybersecurity AI).

Where these numbers come from

GitHub: vxcontrol/pentagi. Site rank: pentagi.com on the Tranco list. See data sources for how each one is collected.

Product facts and pricing were checked against: github.com, hub.docker.com.