{"schema_version":1,"workflow_uuid":"cf2f4bfe-7f9c-5fcb-b801-c8f8ef64d83a","workflow_title":"PentestAgent — MCP-Ready AI Pentesting Agent","page_url":"","raw_url":"https://tokrepo.com/raw/cf2f4bfe-7f9c-5fcb-b801-c8f8ef64d83a","metadata_url":"https://tokrepo.com/metadata/cf2f4bfe-7f9c-5fcb-b801-c8f8ef64d83a.json","install_plan_url":"https://api.tokrepo.com/api/v1/tokenboard/workflows/install-plan?uuid=cf2f4bfe-7f9c-5fcb-b801-c8f8ef64d83a&target=codex","recommended_install":{"schema_version":1,"status":"stage","policy":"stage_only","install_mode":"stage_only","target":"codex","command":"npx -y tokrepo@latest install cf2f4bfe-7f9c-5fcb-b801-c8f8ef64d83a --target codex","dry_run_command":"npx -y tokrepo@latest install cf2f4bfe-7f9c-5fcb-b801-c8f8ef64d83a --target codex --dry-run --json","runtime_commands":{"codex":"npx -y tokrepo@latest install cf2f4bfe-7f9c-5fcb-b801-c8f8ef64d83a --target codex","gemini":"npx -y tokrepo@latest install cf2f4bfe-7f9c-5fcb-b801-c8f8ef64d83a --target gemini","project":"npx -y tokrepo@latest install cf2f4bfe-7f9c-5fcb-b801-c8f8ef64d83a"},"prompt":"Install and make this TokRepo asset usable: \"PentestAgent — MCP-Ready AI Pentesting Agent\".\n\nPage: \nUUID: cf2f4bfe-7f9c-5fcb-b801-c8f8ef64d83a\nTarget adapter: codex\nPolicy/mode: stage_only / stage_only\n\nRead these machine-facing entry points first:\n- metadata: https://tokrepo.com/metadata/cf2f4bfe-7f9c-5fcb-b801-c8f8ef64d83a.json\n- install contract: https://tokrepo.com/install-contract/cf2f4bfe-7f9c-5fcb-b801-c8f8ef64d83a.json\n- install plan: https://api.tokrepo.com/api/v1/tokenboard/workflows/install-plan?uuid=cf2f4bfe-7f9c-5fcb-b801-c8f8ef64d83a&target=codex\n- raw content: https://tokrepo.com/raw/cf2f4bfe-7f9c-5fcb-b801-c8f8ef64d83a\n\nCommands:\n- choose the current runtime; do not use unsupported CLI targets.\n- Codex: npx -y tokrepo@latest install cf2f4bfe-7f9c-5fcb-b801-c8f8ef64d83a --target codex\n- Gemini CLI: npx -y tokrepo@latest install cf2f4bfe-7f9c-5fcb-b801-c8f8ef64d83a --target gemini\n- Claude Code / project agent: run npx -y tokrepo@latest install cf2f4bfe-7f9c-5fcb-b801-c8f8ef64d83a from the project root; add `--dry-run --json` first to inspect the plan.\n- add `--dry-run --json` to the chosen command first; after the plan allows it, run the chosen command.\n\nExecution rules:\n1. Run the install command to stage the asset safely.\n2. Read the staged README, install-plan, and entrypoint files.\n3. Activate scripts, MCP config, or global config only after user confirmation.\n4. Verify usability with the install-plan post_verify checks and the asset README.\n\nReport back with changed files, verification result, and how to use the asset next.","next_steps":["Run the install command to stage the asset safely.","Read the staged README, install-plan, and entrypoint files.","Activate scripts, MCP config, or global config only after user confirmation.","Verify usability with the install-plan post_verify checks and the asset README."],"success_check":["The asset is safely staged.","The agent can give clear activation steps from the staged content."]},"agent_metadata":{"asset_kind":"mcp_config","target_tools":["codex"],"install_mode":"stage_only","entrypoint":"Asset","risk_profile":{"executes_code":false,"modifies_global_config":true,"requires_secrets":[],"uses_absolute_paths":false,"network_access":false},"dependencies":{"npm":[],"pip":[],"brew":[],"system":[]},"content_hash":"42bcbdee62afb68d440a81f017cf5ea82be5a4a2bd9342567cf0fbd9b61cdc8c","verification":{"commands":[],"expected_files":["Asset"]}},"agent_fit":{"target":"codex","score":17,"status":"stage_only","policy":"stage_only","why":["target_tools includes codex","asset_kind mcp_config","install_mode stage_only","policy stage_only","asset_kind mcp_config is not activated directly for Codex","install_mode is stage_only","risk_profile.modifies_global_config is true","trust established"],"asset_kind":"mcp_config","install_mode":"stage_only"},"trust":{"author_trust_level":"established","verified_publisher":false,"asset_signed_hash":"42bcbdee62afb68d440a81f017cf5ea82be5a4a2bd9342567cf0fbd9b61cdc8c","signature_status":"hash_only","install_count":0,"report_count":0,"dangerous_capability_badges":["mcp_config","modifies_global_config","stage_only"],"review_status":"unreviewed","signals":["author has published assets","content hash available"]},"provenance":{"owner_uuid":"8a910281-3180-11f1-9bc6-00163e2b0d79","owner_name":"MCP Hub","source_url":"https://tokrepo.com/en/workflows/pentestagent-mcp-ready-ai-pentesting-agent","content_hash":"42bcbdee62afb68d440a81f017cf5ea82be5a4a2bd9342567cf0fbd9b61cdc8c","visibility":1,"created_at":"2026-05-13 13:21:36","updated_at":"2026-05-28 21:42:55"},"target_adapter":{"target":"codex","adapter":"skill-directory","root":"~/.codex/skills","entrypoint":"SKILL.md","manifest_path":"~/.codex/tokrepo/install-manifest.json","staging_root":"~/.codex/tokrepo/staged/cf2f4bfe-7f9c-5fcb-b801-c8f8ef64d83a","install_modes":["single","bundle","split","stage_only"],"activates_files":true},"install_plan":{"schema_version":2,"target":"codex","asset_uuid":"cf2f4bfe-7f9c-5fcb-b801-c8f8ef64d83a","asset_title":"PentestAgent — MCP-Ready AI Pentesting Agent","source_url":"https://tokrepo.com/en/workflows/pentestagent-mcp-ready-ai-pentesting-agent","install_mode":"stage_only","entrypoint":"Asset","preconditions":[{"type":"target_supported","status":"pass","message":"codex install target is supported"},{"type":"install_root","status":"pass","message":"~/.codex/skills for activated skills; ~/.codex/tokrepo/staged for staged assets"},{"type":"target_tool_metadata","status":"pass","message":"metadata allows codex"},{"type":"content_hash","status":"pass","message":"asset metadata includes content_hash"},{"type":"trust_policy","status":"pass","message":"publisher trust level is established"},{"type":"policy_decision","status":"warn","message":"stage_only for cf2f4bfe-7f9c-5fcb-b801-c8f8ef64d83a (stage_only)"}],"actions":[{"type":"stage_file","path":"~/.codex/tokrepo/staged/cf2f4bfe-7f9c-5fcb-b801-c8f8ef64d83a/Asset.md","source_name":"Asset","sha256":"97bf9d4bdbcaf9f1af81d7076d19c2db4ebce0be36822952c78fa400243fbea2","bytes":4235,"risk":{"executes_code":false,"modifies_global_config":false,"requires_secrets":[],"uses_absolute_paths":false,"network_access":false},"if_exists":"overwrite"}],"policy_decision":{"decision":"stage_only","requires_confirmation":false,"reasons":["asset_kind mcp_config is not activated directly for Codex","install_mode is stage_only","risk_profile.modifies_global_config is true"]},"requires_confirmation":false,"rollback":[{"type":"remove_file","path":"~/.codex/tokrepo/staged/cf2f4bfe-7f9c-5fcb-b801-c8f8ef64d83a/Asset.md"}],"post_verify":[{"type":"file_sha256","path":"~/.codex/tokrepo/staged/cf2f4bfe-7f9c-5fcb-b801-c8f8ef64d83a/Asset.md","sha256":"97bf9d4bdbcaf9f1af81d7076d19c2db4ebce0be36822952c78fa400243fbea2"},{"type":"expected_file","path":"Asset.md"}],"metadata":{"asset_kind":"mcp_config","target_tools":["codex"],"install_mode":"stage_only","entrypoint":"Asset","risk_profile":{"executes_code":false,"modifies_global_config":true,"requires_secrets":[],"uses_absolute_paths":false,"network_access":false},"dependencies":{"npm":[],"pip":[],"brew":[],"system":[]},"content_hash":"42bcbdee62afb68d440a81f017cf5ea82be5a4a2bd9342567cf0fbd9b61cdc8c","verification":{"commands":[],"expected_files":["Asset"]}},"agent_fit":{"target":"codex","score":17,"status":"stage_only","policy":"stage_only","why":["target_tools includes codex","asset_kind mcp_config","install_mode stage_only","policy stage_only","asset_kind mcp_config is not activated directly for Codex","install_mode is stage_only","risk_profile.modifies_global_config is true","trust established"],"asset_kind":"mcp_config","install_mode":"stage_only"},"trust":{"author_trust_level":"established","verified_publisher":false,"asset_signed_hash":"42bcbdee62afb68d440a81f017cf5ea82be5a4a2bd9342567cf0fbd9b61cdc8c","signature_status":"hash_only","install_count":0,"report_count":0,"dangerous_capability_badges":["mcp_config","modifies_global_config","stage_only"],"review_status":"unreviewed","signals":["author has published assets","content hash available"]},"provenance":{"owner_uuid":"8a910281-3180-11f1-9bc6-00163e2b0d79","owner_name":"MCP Hub","source_url":"https://tokrepo.com/en/workflows/pentestagent-mcp-ready-ai-pentesting-agent","content_hash":"42bcbdee62afb68d440a81f017cf5ea82be5a4a2bd9342567cf0fbd9b61cdc8c","visibility":1,"created_at":"2026-05-13 13:21:36","updated_at":"2026-05-28 21:42:55"},"target_adapter":{"target":"codex","adapter":"skill-directory","root":"~/.codex/skills","entrypoint":"SKILL.md","manifest_path":"~/.codex/tokrepo/install-manifest.json","staging_root":"~/.codex/tokrepo/staged/cf2f4bfe-7f9c-5fcb-b801-c8f8ef64d83a","install_modes":["single","bundle","split","stage_only"],"activates_files":true},"evidence_bundle":{"acceptance_gate":{"recommended_action":"stage_or_request_confirmation","rule":"Agents should only activate an asset after evidence_bundle.integrity, policy_compatibility, rollback, and post_verify have been inspected.","status":"caution"},"asset_title":"PentestAgent — MCP-Ready AI Pentesting Agent","asset_uuid":"cf2f4bfe-7f9c-5fcb-b801-c8f8ef64d83a","eval_evidence":["https://tokrepo.com/evals/install-safety.json","https://tokrepo.com/evals/trust-evidence-coverage.json","https://tokrepo.com/evals/handoff-quality.json"],"generated_at":"2026-05-28T13:42:56Z","integrity":{"content_hash":"7e2701a9cfc729722e24361cde12e73edab5c5b6a4986bcfe2cf4e5c5929ef92","declared_content_hash":"42bcbdee62afb68d440a81f017cf5ea82be5a4a2bd9342567cf0fbd9b61cdc8c","file_count":1,"hash_algorithm":"sha256","install_plan_hash":"3ab186d68bdcbbf27776da05400839ca3964ada3228594509a2d0a8b1f4ead0e"},"policy_compatibility":{"permission_envelope":{"destructive":false,"executes_code":false,"file_count":1,"filesystem_write":["~/.codex/tokrepo/staged"],"global_config_write":true,"network":false,"requires_secrets":[],"uses_absolute_paths":false},"policy_decision":{"decision":"stage_only","requires_confirmation":false,"reasons":["asset_kind mcp_config is not activated directly for Codex","install_mode is stage_only","risk_profile.modifies_global_config is true"]},"requires_confirmation":false,"target":"codex","trust_score_v2":{"recommended_action":"stage_or_request_confirmation","status":"caution","trust_score":60}},"provenance":{"asset_kind":"mcp_config","asset_title":"PentestAgent — MCP-Ready AI Pentesting Agent","asset_uuid":"cf2f4bfe-7f9c-5fcb-b801-c8f8ef64d83a","computed_bundle_hash":"7e2701a9cfc729722e24361cde12e73edab5c5b6a4986bcfe2cf4e5c5929ef92","content_hash":"42bcbdee62afb68d440a81f017cf5ea82be5a4a2bd9342567cf0fbd9b61cdc8c","created_at":"2026-05-13 13:21:36","generated_at":"2026-05-28T13:42:56Z","install_plan_hash":"3ab186d68bdcbbf27776da05400839ca3964ada3228594509a2d0a8b1f4ead0e","owner_name":"MCP Hub","owner_uuid":"8a910281-3180-11f1-9bc6-00163e2b0d79","parent_uuid":"","schema_version":2,"source":"tokrepo_asset","source_url":"https://tokrepo.com/en/workflows/pentestagent-mcp-ready-ai-pentesting-agent","updated_at":"2026-05-28 21:42:55","visibility":1},"sbom":{"asset_kind":"mcp_config","asset_title":"PentestAgent — MCP-Ready AI Pentesting Agent","asset_uuid":"cf2f4bfe-7f9c-5fcb-b801-c8f8ef64d83a","capability_flags":{"destructive":false,"executes_code":false,"modifies_global_config":true,"network_access":false,"requires_secrets":[]},"content_hash":"7e2701a9cfc729722e24361cde12e73edab5c5b6a4986bcfe2cf4e5c5929ef92","dependencies":{"brew":[],"mcp":[],"npm":[],"pip":[],"system":[]},"files":[{"bytes":4235,"path":"~/.codex/tokrepo/staged/cf2f4bfe-7f9c-5fcb-b801-c8f8ef64d83a/Asset.md","role":"supporting_file","sha256":"97bf9d4bdbcaf9f1af81d7076d19c2db4ebce0be36822952c78fa400243fbea2","source_name":"Asset"}],"format":"SBOM-lite","install_mode":"stage_only","schema_version":1,"target":"codex"},"schema":"https://tokrepo.com/schemas/agent-evidence-bundle.schema.json","schema_version":1,"schemas":{"asset_verification":"https://tokrepo.com/schemas/asset-verification.schema.json","evidence_bundle":"https://tokrepo.com/schemas/agent-evidence-bundle.schema.json","install_plan":"https://tokrepo.com/schemas/install-plan.schema.json","provenance":"https://tokrepo.com/schemas/provenance.schema.json","sbom":"https://tokrepo.com/schemas/agent-evidence-bundle.schema.json#/properties/sbom"},"signature_evidence":{"content_hash":"7e2701a9cfc729722e24361cde12e73edab5c5b6a4986bcfe2cf4e5c5929ef92","hash_algorithm":"sha256","install_plan_hash":"3ab186d68bdcbbf27776da05400839ca3964ada3228594509a2d0a8b1f4ead0e","schema_version":1,"signed_hash":"42bcbdee62afb68d440a81f017cf5ea82be5a4a2bd9342567cf0fbd9b61cdc8c","status":"hash_only","verification_notes":["hash_only evidence proves content integrity but not publisher identity unless an external signature verifies it"]},"source_url":"https://tokrepo.com/en/workflows/pentestagent-mcp-ready-ai-pentesting-agent","target":"codex"},"sbom":{"asset_kind":"mcp_config","asset_title":"PentestAgent — MCP-Ready AI Pentesting Agent","asset_uuid":"cf2f4bfe-7f9c-5fcb-b801-c8f8ef64d83a","capability_flags":{"destructive":false,"executes_code":false,"modifies_global_config":true,"network_access":false,"requires_secrets":[]},"content_hash":"7e2701a9cfc729722e24361cde12e73edab5c5b6a4986bcfe2cf4e5c5929ef92","dependencies":{"brew":[],"mcp":[],"npm":[],"pip":[],"system":[]},"files":[{"bytes":4235,"path":"~/.codex/tokrepo/staged/cf2f4bfe-7f9c-5fcb-b801-c8f8ef64d83a/Asset.md","role":"supporting_file","sha256":"97bf9d4bdbcaf9f1af81d7076d19c2db4ebce0be36822952c78fa400243fbea2","source_name":"Asset"}],"format":"SBOM-lite","install_mode":"stage_only","schema_version":1,"target":"codex"},"signature_evidence":{"content_hash":"7e2701a9cfc729722e24361cde12e73edab5c5b6a4986bcfe2cf4e5c5929ef92","hash_algorithm":"sha256","install_plan_hash":"3ab186d68bdcbbf27776da05400839ca3964ada3228594509a2d0a8b1f4ead0e","schema_version":1,"signed_hash":"42bcbdee62afb68d440a81f017cf5ea82be5a4a2bd9342567cf0fbd9b61cdc8c","status":"hash_only","verification_notes":["hash_only evidence proves content integrity but not publisher identity unless an external signature verifies it"]},"provenance_v2":{"asset_kind":"mcp_config","asset_title":"PentestAgent — MCP-Ready AI Pentesting Agent","asset_uuid":"cf2f4bfe-7f9c-5fcb-b801-c8f8ef64d83a","computed_bundle_hash":"7e2701a9cfc729722e24361cde12e73edab5c5b6a4986bcfe2cf4e5c5929ef92","content_hash":"42bcbdee62afb68d440a81f017cf5ea82be5a4a2bd9342567cf0fbd9b61cdc8c","created_at":"2026-05-13 13:21:36","generated_at":"2026-05-28T13:42:56Z","install_plan_hash":"3ab186d68bdcbbf27776da05400839ca3964ada3228594509a2d0a8b1f4ead0e","owner_name":"MCP Hub","owner_uuid":"8a910281-3180-11f1-9bc6-00163e2b0d79","parent_uuid":"","schema_version":2,"source":"tokrepo_asset","source_url":"https://tokrepo.com/en/workflows/pentestagent-mcp-ready-ai-pentesting-agent","updated_at":"2026-05-28 21:42:55","visibility":1},"transitive_dependencies":null}}