Atlas / MCP servers / ibrahimsaleem / Pentest Thinking

Pentest ThinkingSAFE

mcp/ibrahimsaleem/pentest-thinking

A systematic, AI-powered penetration testing reasoning engine (MCP server) for attack path planning, CTF/HTB solving, and automated pentest workflows. Features Beam Search, MCTS, attack step scoring, and tool recommendations.

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
2 2r · 0w · 0d
Transport
stdio
License
MIT
Stars
38
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

A main and foundational implementation of the research paper:

LIMA: Leveraging Large Language Models and MCP Servers for Initial Machine Access

This project serves as the primary and naive system described in the paper, providing a practical framework for orchestrating automated initial-access reconnaissance, enumeration, and exploitation using large language models (LLMs) with Model Context Protocol (MCP) servers.

Research Context

This repository is the main codebase referenced in the paper LIMA: Leveraging Large Language Models and MCP Servers for Initial Machine Access. The research introduces LIMA, a modular system that pairs off-the-shelf LLMs with MCP servers to automate penetration testing tasks such as reconnaissance, enumeration, vulnerability assessment, and exploitation. The project demonstrates how LLMs can autonomously reason about attack paths, generate exploits, and complete initial access challenges with minimal human input, as benchmarked on public HackTheBox machines and custom environments.

Key highlights from the research:

  • LIMA achieves up to 2x faster completion than expert testers for certain tasks, including autonomous CAPTCHA solving and attack chain execution.
  • The system provides the first quantitative baseline for AI-augmented penetration testing at the initial-access phase.
  • The modular design allows other LLMs to be integrated easily for future research and development.

For more details, see the full paper or the summary in this repository.

What is PentestThinkingMCP?

PentestThinkingMCP is an advanced Model Context Protocol (MCP) server designed to empower both human and AI pentesters. It provides:

  • Automated attack path planning using Beam Search and Monte Carlo Tree Search (MCTS)
  • Step-by-step reasoning for CTFs, Hack The Box (HTB), and real-world pentests
  • Attack step scoring and prioritization
  • Tool recommendations for each step (e.g., nmap, metasploit, linpeas)
  • Critic
Read from source at commit 7e72960c019aOBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add pentestthinking -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "pentestthinking": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ]
    }
  }
}
03

Exposed tools (2)

2 read · 0 write · 0 destructive.

ToolRiskDescription
pentestthinkingreadA pentest reasoning engine that helps break down and analyze attack paths step by step
pentestthinkingMCPreadAdvanced reasoning tool with multiple strategies including Beam Search and Monte Carlo Tree Search
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
none-observed
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (2)

LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, chalk, uuid, @smithery/cli, @types/jest, @types/node, @types/uuid, @typescript-eslint/eslint-plugin
Why it matters. 16 dependency range(s) float
Fix. pin exact versions or ship a lockfile
INFOInventory / provenance · inv.oversize · CWE-1104
.smithery/index.cjs
.smithery/index.cjs
Why it matters. 10493393 bytes not read

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 7e72960c019afull audit observations/trust-audit/mcp-server/ibrahimsaleem__pentest-thinking.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-087e72960c019aSAFEB89first audit
06

Questions

What is the Pentest Thinking MCP server?

A systematic, AI-powered penetration testing reasoning engine (MCP server) for attack path planning, CTF/HTB solving, and automated pentest workflows. Features Beam Search, MCTS, attack step scoring, and tool recommendations.

What tools does Pentest Thinking expose?

2 in total: 2 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Pentest Thinking safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does Pentest Thinking need?

No credential environment variables were found in its source, so it appears to need none.

How does Pentest Thinking run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as pentestthinking at 1.0.0.

How current is this page?

The grade is for one exact copy of the source (7e72960c019a), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement