loaditout.ai
SkillsPacksTrendingLeaderboardAPI DocsBlogSubmitRequestsCompareAgentsXPrivacyDisclaimer
{}loaditout.ai
Skills & MCPPacksBlog

pwnkit

MCP Tool

peaktwilight/pwnkit

Let autonomous AI agents hack you so the real ones can't. Attacks LLM endpoints, web apps, npm packages, and source code. Blind PoC verification to minimize false positives.

Install

$ npx loaditout add peaktwilight/pwnkit

Platform-specific configuration:

.claude/settings.json
{
  "mcpServers": {
    "pwnkit": {
      "command": "npx",
      "args": [
        "-y",
        "pwnkit"
      ]
    }
  }
}

Add the config above to .claude/settings.json under the mcpServers key.

About

<p align="center"> </p>

<h1 align="center">pwnkit</h1>

<p align="center"> <strong>Let autonomous AI agents hack you so the real ones can't.</strong><br/> <em>Fully autonomous agentic pentesting framework. Blind PoC verification to minimize false positives.</em> </p>

<p align="center"> <a href="https://www.npmjs.com/package/pwnkit-cli"></a> <a href="https://github.com/peaktwilight/pwnkit/blob/main/LICENSE"></a> <a href="https://github.com/peaktwilight/pwnkit/actions"></a> <a href="https://github.com/peaktwilight/pwnkit/stargazers"></a> <a href="https://pwnkit.com"></a> </p>

<p align="center"> </p>

<p align="center"> <a href="https://docs.pwnkit.com">Docs</a> &middot; <a href="https://pwnkit.com">Website</a> &middot; <a href="https://pwnkit.com/blog">Blog</a> &middot; <a href="#benchmark">Benchmark</a> </p>

---

Autonomous agents that discover, attack, and verify vulnerabilities across LLM endpoints, web apps, npm packages, and source code. Every finding is independently re-exploited by a blind verify agent to kill false positives.

npx pwnkit-cli
Quick Start
# Scan an LLM endpoint
npx pwnkit-cli scan --target https://your-app.com/api/chat

# Pentest a web app
npx pwnkit-cli scan --target https://example.com --mode web

# Audit an npm package
npx pwnkit-cli audit lodash

# Review source code
npx pwnkit

Tags

agenticaiai-agentsautonomous-pentestingbenchmarkclicode-reviewllm-securitymcpnpm-auditopen-sourceowasppentestingprompt-injectionred-teamsarifsecuritytypescriptvulnerability-scannerweb-security

Reviews

Loading reviews...

Quality Signals

8
Stars
0
Installs
Last updated9 days ago
Security: AREADME
New

Safety

Risk Levelmedium
Data Access
read
Network Accessnone

Details

Sourcegithub-crawl
Last commit4/4/2026
View on GitHub→

Embed Badge

[![Loaditout](https://loaditout.ai/api/badge/peaktwilight/pwnkit)](https://loaditout.ai/skills/peaktwilight/pwnkit)