← pentestai.xyz

Blog

Notes from the team. How the agent loop works, what scanners miss, what we got wrong.

2026-05-19 · Architecture

Why we built pentest-ai as an MCP server, not just a CLI

The CLI works. The MCP server is what makes it actually useful. Here's the reasoning behind the split, and what changed when we let Claude Code drive.

2026-05-19 · Benchmark

The auth-protected bugs every web scanner misses

We pointed pentest-ai at OWASP Juice Shop. Unauthenticated, it found 58 issues. Authenticated, it found four exploit chains scanners typically can't reach. Here's what changed.

2026-05-19 · Tutorial

Driving a pentest from Claude Code in 5 minutes

Install ptai, register the MCP server, give Claude Code a scope. That's the whole setup. Walking through it with a real target and showing what the conversation looks like.