Full-chain pentest
automation for OpenCode.
From recon to report — 15 phases of automated exploitation with AI-powered intelligence. No API keys. No external services.
Built for real exploitation
Not another scanner. gitest executes payloads, chains attacks, and simulates what a real competitor would do.
Full-Chain Exploitation
15 phases from recon to persistence — real exploitation with payloads, not just scanning.
250+ Attack Playbooks
Web, API, mobile, AD, cloud, CTF, forensics — categorized and ready to execute.
AI-Native Intelligence
18 JSON intel files for attack chaining, CVE correlation, pattern matching, and WAF bypass.
Multi-Vector Approach
OSINT, source code analysis, supply chain, API abuse, business logic, and cloud attacks.
Competitor Simulation
Report generation with CVSS scoring, simulating what a real competitor would do.
Zero External Dependencies
Runs on OpenCode's built-in model. No API keys, no external services needed.
15 phases. End to end.
From environment setup to final report — every phase is automated with real exploitation, not just scanning.
Intel loading & tool verification
Subdomain, port, service enumeration
Git dump, backup files, JS secrets
People, email, GitHub recon
SQLi, XSS, directory fuzzing
CDN, dependency confusion
Full site crawling
JWT, GraphQL, IDOR, rate limit
Brute, spray, default creds
Race conditions, workflow flaws
Subdomain takeover, S3 buckets
PII, financial data, credentials
Admin creation, webshell
SSO, OAuth, webhook security
CVSS scoring, competitor simulation
AI-native intelligence stack
18 JSON databases powering attack chaining, pattern matching, WAF bypass, and CVE correlation.
Install in 2 commands
Clone, install, and run. No API keys, no config.
Start your first full-chain pentest
Clone the repo, run the command, and watch gitest execute 15 phases of automated exploitation.