vibe-pentest-ai-security-testing
Skill by ara.so — Security Skills collection.
Vibe Pentest is an AI Agent-based automated penetration testing tool that uses a multi-agent parallel execution architecture to perform comprehensive black-box penetration testing (including business logic vulnerability assessment) on web applications, APIs, and admin backends. It outputs stable and reliable security reports with actionable remediation recommendations.
Overview
Vibe Pentest orchestrates multiple AI agents to:
- Fingerprint web technologies and frameworks
- Crawl and map attack surfaces
- Execute parallel vulnerability testing across multiple categories
- Identify business logic flaws
- Generate comprehensive security reports in HTML and DOCX formats
Version: v1.0.7
License: AGPL-3.0
Primary Language: Python
Installation
Prerequisites
- Git (required for auto-update mechanism):
- Python 3.10+ and dependencies:
- Katana Crawler (included for Windows, download for other OS):
- Windows version included in
tools/katana - For other OS, see
tools/katana_downloads.jsonfor download links
- Windows version included in
Automated Installation
You can also ask your AI coding agent to install everything:
Project Structure
Core Testing Workflow
Vibe Pentest follows a 7-phase workflow:
Phase 0: Fingerprinting
Identify web technologies, frameworks, and server information.
Phase 0.5: Backend Entry Scanning
Scan for admin panels and sensitive endpoints.
Phase 1: Authorization Confirmation
Verify written authorization before proceeding.
Phase 2: Browser Login & Credential Extraction
Launch browser for manual login, extract session cookies/tokens.
Phase 3: Katana Crawling
Use Katana crawler to discover all endpoints and parameters.
Phase 4: Data Cleaning
Process crawler output, deduplicate URLs, extract parameters.
Phase 4.5: Attack Surface Mapping
Map discovered endpoints to vulnerability test categories.
Phase 5: Multi-Agent Parallel Testing
Distribute testing across 6 specialized agents using prepared skeleton files.
Phase 5.5: Attack Chain Analysis
Identify cross-agent attack chains and compound vulnerabilities.
Phase 5.6: Evidence Verification
Re-verify confirmed vulnerabilities with HTTP evidence.
Phase 6: Report Generation
Generate comprehensive reports in multiple formats.
Configuration
Environment Variables
Testing Principles
Critical Rules:
- All sub-agents MUST actively investigate, not wait for prompts
- If Katana runs >20 minutes, terminate and collect results
- Test ALL discovered functionality, not just entry points
- Attempt 2-3 bypass techniques on failed tests
- Iron Law: May modify/delete own test data; NEVER modify production data
Common Usage Patterns
Standard Authorized Testing
Multi-Account Privilege Escalation Testing
Report-Only Generation
Troubleshooting
Katana Crawler Issues
Problem: Crawler returns empty results or finishes in <20 seconds
Problem: Crawler times out or hangs
Multi-Agent Coordination
Problem: Agents not finding vulnerabilities
Problem: Agents marking everything as "Potential" without confirmation
Report Generation Failures
Problem: Report missing sections or malformed
Session Extraction Issues
Problem: Browser doesn't launch or session not captured
Best Practices
- Always use separate workspaces for different targets to avoid cross-contamination
- Verify authorization documentation before starting any test
- Test on staging/UAT environments when possible, not production
- Review findings manually before delivering reports to clients
- Keep vibe-pentest updated using
git pullto get latest detection techniques - Use multiple accounts to thoroughly test authorization controls
- Document custom test data created during testing for cleanup
Additional Resources
- 3-minute tutorial video: bilibili.com/video/BV1RiGX6rESQ/
- Sub-agent setup guide: See
sub_agent.mdin repository - Katana documentation: github.com/projectdiscovery/katana


