EN
Back to the archive

The archive · Developer & Business Tools · Product decision · 2018–2026

VXControl's PentAGI bet: MIT 'autonomous red team' tops GitHub trending, 18.5k stars

VXControl bets AI agents can run penetration tests end-to-end, open-sourcing the 13-agent PentAGI under MIT — free where rivals charge $50k+/year.

VXControl

The betAI agents can run penetration tests end-to-end — recon, exploitation, reporting — so VXControl open-sourced its multi-agent system under MIT to prove autonomy wins.Live

What the business is

VXControl builds PentAGI, an open-source, self-hosted penetration-testing platform where 13+ specialized AI agents (orchestrator, searcher, coder, pentester, adviser, reflector and more) collaborate to scan, exploit and report on authorized targets, integrating 20+ security tools and 12+ LLM providers.

How it started

VXControl, founded in 2018 and based in Dubai per Runa Capital, started PentAGI in early 2025 as a GitHub security-tools organization betting that multi-agent AI could automate complex penetration tests. The open-source release took off in early 2026: a viral tweet — 'Someone just open-sourced a fully autonomous AI Red Team... Zero human input' — was shared thousands of times, and the repository climbed to the top of GitHub trending.

What happened

PentAGI's v1.2.0 shipped on 2026-02-25 with 13+ role-specialized agents, a Go backend, React UI, a Neo4j knowledge graph, Docker-sandboxed execution of Nmap, Metasploit, sqlmap and other tools, and support for 12+ LLM providers including local models. Runa Capital's Q1 2026 ROSS index listed it among the quarter's fastest-growing open-source startups, and the architecture drew both praise and skepticism — Ostorlab tests found configuration failures, and reviewers noted the 'zero human input' claim needs setup, API keys and defined targets.

How it ended up

Still running as of 2026-09-02: PentAGI reached 18.5k stars and release v2.1.0 (2026-05-29) by early July 2026 with active maintenance; the open question is whether an MIT tool with no support contracts can convert star momentum into the trust and compliance revenue that enterprise pentesting demands.

Background

VXControl, a security-tools company founded in 2018 and based in Dubai, launched PentAGI in early 2025 with a bet that AI agents could perform complex penetration tests end-to-end. Its architecture mirrors a real red team: more than thirteen specialized agents — orchestrator, searcher, coder, pentester, installer, adviser, reflector, enricher, generator — each with least-privilege access, coordinated by a Go backend with a React monitoring UI.

The project exploded when the open-source release went viral in early 2026. A widely shared tweet — 'Someone just open-sourced a fully autonomous AI Red Team... Zero human input' — accompanied a climb to the top of GitHub trending; PentAGI passed 12,500 stars and 1,600 forks around its 2026-02-25 v1.2.0 release, and Runa Capital's Q1 2026 ROSS index ranked it among the quarter's 20 fastest-growing open-source startups with 13.9x star growth.

Technically, PentAGI integrates more than twenty professional tools (Nmap, Metasploit, sqlmap, Nikto, Hydra) inside sandboxed Docker containers, keeps findings in PostgreSQL, pgvector and a Neo4j knowledge graph, and supports 12+ LLM providers via LiteLLM. High-risk actions — shell execution, exploit launches, privilege escalation — require human approval that fails closed after 300 seconds, and every prompt and tool call is audit-logged.

By 2026-07-03 the repo had grown to 18.5k stars with release v2.1.0 (2026-05-29), positioning it as the only fully free autonomous alternative to quote-based platforms like NodeZero.ai, Pentera and XBOW. Skeptics note Ostorlab found configuration failures, 'zero human input' still needs setup and scoping, and regulated clients may not accept AI-only testing — the commercialization question remains open.

What has to be true

  • Role-specialized agents with least-privilege tool access let PentAGI claim genuine autonomy rather than a chat wrapper around Nmap.
  • An MIT license made the category's most ambitious tool free, drawing attention and adoption that quote-based rivals could not match.
  • Human approval gates, Docker sandboxing and full audit logging gave security teams a defensible way to run an autonomous attacker.
  • The viral 'fully autonomous AI red team' framing turned a niche release into GitHub's trending list within weeks of launch.

What can be applied

Open-sourcing a category-defining tool works even in security: free shifts the fight to trust, sandboxing and evidence — while every copy multiplies the abuse surface a vendor must answer for.

Aftermath

As of 2026-09-02 PentAGI is live under active maintenance (last release v2.1.0 on 2026-05-29; 18.5k stars per DEV.co's 2026-07-03 snapshot). The project remains MIT and self-hosted, with Docker Compose installers for Linux, Windows and macOS. Its trajectory now depends on whether the community converts into enterprise deployments and whether autonomous AI pentesting gains acceptance with compliance and liability frameworks — regulators and insurers have not yet blessed AI-only assessments, and competitors keep bundling autonomy into supported SaaS.

Sources

spotted an error? The archive wants to know.

Your turn

You just read one. Describe what you are building, and see who is betting on the same thing.

Free account · 3 free questions · no card

Related cases