This is an MCP server that exposes red team tools for active directory pentesting to LLMs
PentestMCP has severe definition quality issues across nearly all dimensions. Tools lack proper parameter descriptions, schemas are minimally documented, and error handling is absent. While tool names follow a reasonable verb_noun convention (save_, get_, check_, run_, generate_, enumerate_, bruteforce_, spray_, etc.), the descriptions are inconsistent in quality and many parameters are completely undescribed. The implementation shows command-line tool wrapping rather than agent-optimized interfaces. No tool provides structured output schemas, no pagination for list-returning tools, and no error guidance. This is a typical community pentesting tool that prioritizes CLI functionality over LLM usability.
Retrieve the Kerberos 5 AS-REP etype 23 hash of users without or with Kerberos pre-authentication required
The goal of Kerberoasting is to harvest TGS tickets for services that run on behalf of user accounts in the AD, not computer accounts. Thus, part of these TGS tickets is encrypted with keys derived from user passwords. As a consequence, their credentials could be cracked offline.
Bruteforce rid to enumerate users
used to check smb signgings of an ip address or some range of ip addresses with the needed options
enumerate users on an active directory domain, you can provide username or password if you have some
generate some password wordlist based on initial input of word(s), let this be the last resort if no other wordlist worked
Minimal parameter descriptions. Most tools declare parameters (ips, flags, username, password) with only 1-2 word descriptions like 'list of IP addresses' or 'optional password for authentication'. LLMs cannot infer context, valid ranges, formats, or constraints from such terse descriptions. Pattern:tool-description requires descriptions that answer WHAT, WHEN, and prerequisites.
No output schemas documented. Tools return raw command output (stdout/stderr from nmap, netexec, john) as free-text strings. LLMs must parse unstructured output, which is error-prone, wastes tokens, and prevents downstream tool chaining. Pattern:tool requires 'Document the output schema. LLMs need to know what fields to expect.'
Inferred effective spec: <=2025-11-25.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | F | 49 | <=2025-11-25 | v2 |
| 2026-03-09 | F | 22 | - | v1 |
check available john format before cracking a hash
read existing files from the project directory to see what findings and data have been saved
cracking hashes using john based on format and a wordlist
spray passwords on an account or several accounts
read a file
run an nmap scan on an ip or ip range (use the right nmap flags based on the first response)
save partial findings for later use (like open ports, used protocols, versions etc.) if finding data is too long or already exists in another file dont save it
enumerate smb shares having username and password credentials and dump them into ~/.nxc/modules/nxc_spider_plus/{ip}.json and you'll find the directory inside ~/.nxc/modules/nxc_spider_plus/{ip} that has the data so you could read that. read readable files after you check what files exists and pull valuable information like old versions , hard coded secrets , misconfigurations
No error handling or recovery guidance. run_command() returns a dict with success/failure flags and raw stderr, but provides no actionable next steps. When 'netexec' fails with 'Connection refused', the LLM gets a raw error message instead of 'Connection failed: target may be offline or port 445 blocked. Try running check_SMB_signing first to verify availability.' Pattern:recovery-guide requires 'Error responses must tell the LLM what to do next.'
Credentials exposed as tool parameters. 'enumerate_domain_users', 'ASREPRoast', 'Kerberoast', and 'spider_smb_shares' all accept username and password as string parameters. Agent traces log every parameter, credentials end up in logs and prompt history. Pattern:secret-injection requires 'Use server-side secret injection via environment variables or vault.'
No input validation or constraint documentation. Numeric parameters (flags in run_nmap_scan, list sizes in password_spray) have no min/max constraints. String parameters (usernames, passwords, filenames) have no format validation or length limits. Pattern:constrained-input requires declaring enums for known sets and documenting ranges for numerics.
Missing tool descriptions or generic descriptions. 'get_john_formats' has description 'check available john format before cracking a hash' (23 chars, below the 10-1024 char baseline). 'check_SMB_signing' description is 65 chars but does not explain WHEN to use it vs other SMB tools or what output to expect. Pattern:tool-description baseline is 194 chars average for A+ tools.
Tool composition issues. Multiple tools wrap raw CLI tools (nmap, netexec, john, impacket) without abstracting the complexity or enforcing idempotency. 'run_nmap_scan' and 'check_SMB_signing' both query SMB targets but return raw text requiring LLM parsing. No pagination for large result sets. Pattern:tool-chain requires 'Ensure tool A's output contains the IDs and references tool B needs.'
Ambiguous parameter naming. 'ips' parameter appears across 10+ tools but descriptions do not specify format: Does it accept '192.168.1.1', '192.168.1.0/24', 'scanme.nmap.org'? Which formats does each tool support? Pattern:tool-description requires 'Describe the expected format, range, and allowed values directly in the parameter description.'
No destructive operation safeguards. 'password_spray' and 'enumerate_domain_users' can trigger account lockouts or alert security systems if used incorrectly, but have no confirmation, rate-limiting, or dry-run mode. Pattern:confirmation-request requires 'Irreversible operations should support a dry-run or confirmation step.'
Undocumented dependencies between tools. Tools like 'ASREPRoast' and 'Kerberoast' both accept optional passwords and appear interdependent with 'enumerate_domain_users', but this is never stated. An LLM cannot plan the right sequence without explicit hints. Pattern:tool-description requires 'Include dependency hints: If you only have a name, call search_users() first.'