Pentest ThinkingSAFE
A systematic, AI-powered penetration testing reasoning engine (MCP server) for attack path planning, CTF/HTB solving, and automated pentest workflows. Features Beam Search, MCTS, attack step scoring, and tool recommendations.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
A main and foundational implementation of the research paper:
LIMA: Leveraging Large Language Models and MCP Servers for Initial Machine Access
This project serves as the primary and naive system described in the paper, providing a practical framework for orchestrating automated initial-access reconnaissance, enumeration, and exploitation using large language models (LLMs) with Model Context Protocol (MCP) servers.
Research Context
This repository is the main codebase referenced in the paper LIMA: Leveraging Large Language Models and MCP Servers for Initial Machine Access. The research introduces LIMA, a modular system that pairs off-the-shelf LLMs with MCP servers to automate penetration testing tasks such as reconnaissance, enumeration, vulnerability assessment, and exploitation. The project demonstrates how LLMs can autonomously reason about attack paths, generate exploits, and complete initial access challenges with minimal human input, as benchmarked on public HackTheBox machines and custom environments.
Key highlights from the research:
- LIMA achieves up to 2x faster completion than expert testers for certain tasks, including autonomous CAPTCHA solving and attack chain execution.
- The system provides the first quantitative baseline for AI-augmented penetration testing at the initial-access phase.
- The modular design allows other LLMs to be integrated easily for future research and development.
For more details, see the full paper or the summary in this repository.
What is PentestThinkingMCP?
PentestThinkingMCP is an advanced Model Context Protocol (MCP) server designed to empower both human and AI pentesters. It provides:
- Automated attack path planning using Beam Search and Monte Carlo Tree Search (MCTS)
- Step-by-step reasoning for CTFs, Hack The Box (HTB), and real-world pentests
- Attack step scoring and prioritization
- Tool recommendations for each step (e.g., nmap, metasploit, linpeas)
- Critic
7e72960c019aOBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add pentestthinking -- npx -y [email protected]
{
"mcpServers": {
"pentestthinking": {
"command": "npx",
"args": [
"-y",
"[email protected]"
]
}
}
}Exposed tools (2)
2 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
pentestthinking | read | A pentest reasoning engine that helps break down and analyze attack paths step by step |
pentestthinkingMCP | read | Advanced reasoning tool with multiple strategies including Beam Search and Monte Carlo Tree Search |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (2)
@modelcontextprotocol/sdk, chalk, uuid, @smithery/cli, @types/jest, @types/node, @types/uuid, @typescript-eslint/eslint-plugin
.smithery/index.cjs
Gates applied: no_behavioural_pass.
7e72960c019afull audit observations/trust-audit/mcp-server/ibrahimsaleem__pentest-thinking.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 7e72960c019a | SAFE | B | 89 | first audit |
Questions
What is the Pentest Thinking MCP server?
A systematic, AI-powered penetration testing reasoning engine (MCP server) for attack path planning, CTF/HTB solving, and automated pentest workflows. Features Beam Search, MCTS, attack step scoring, and tool recommendations.
What tools does Pentest Thinking expose?
2 in total: 2 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Pentest Thinking safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does Pentest Thinking need?
No credential environment variables were found in its source, so it appears to need none.
How does Pentest Thinking run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as pentestthinking at 1.0.0.
How current is this page?
The grade is for one exact copy of the source (7e72960c019a), read on 2026-10-08. The repository is watched and re-audited when it changes.