pentagi vs reverse-skill
Self-hosted autonomous pentesting: multi-agent system in sandboxed Docker with 20+ tools, supervised agent hierarchies, Langfuse observability and a Graphiti knowledge graph. 10+ LLM providers. — versus — Reverse-engineering and pentest skill router for coding agents: routes APK/ELF/JS/PCAP/CTF tasks to the right playbook, bootstraps jadx/Frida/IDA-class toolchains, evolves a knowledge base. CN/EN.
Same domain, opposite philosophy: reverse-skill routes YOUR agent through pentest methodology; PentAGI ships its own autonomous agent system end to end.
| pentagi | reverse-skill | |
|---|---|---|
| Stars | 22k | 19k |
| Forks | 2.9k | 2.7k |
| Language | Go | PowerShell |
| License | MIT | MIT |
| Last activity | 3 days ago | 3 days ago |
| Topics | security, agents | security, skills |
| Curated connections | 3 | 2 |
pentagi — the curator's take
The most complete self-hosted offensive-AI platform in the open: agent supervision, isolated execution, observability and long-term memory are all first-class, not bolted on — this is infrastructure, not a script. When NOT: it's a serious deployment (Docker stack, Postgres, optional Langfuse/Graphiti services) for serious authorized work — a quick web-app scan doesn't need an AGI acronym; and autonomous exploitation tooling makes your legal scope YOUR problem, doubly so.
reverse-skill — the curator's take
The router is the substance: agents don't know whether a task wants jadx, Frida or Burp, and this encodes that judgment — plus scope and authorization contracts BEFORE any target is touched, which most offensive-skill packs skip. When NOT: it's methodology, not tools — you still install the toolchain and hold the authorization it assumes; PowerShell-first heritage shows off-Windows; and the star count partly rides the CN security community wave.