Research · curated 29 Sep 2026
PentestChain: A Cost-Aware, MCP-Orchestrated Framework for Automated Penetration Testing with Free-Tier LLMs
First reported arxiv.org
Coverage timeline
Single-source research — first reported, latest, and curated coincide.
Why it matters
PentestChain lowers the cost barrier to autonomous LLM-driven offensive operations while documenting the real MCP supply-chain and tool-poisoning risks defenders must anticipate as agentic pentest engines proliferate.
PentestChain is a research framework for cost-aware automated penetration testing that cascades free-tier and local LLMs (qwen2.5-7b via Ollama, OpenRouter, Cerebras) behind a deterministic exploit map and exposes an eleven-tool Model Context Protocol (MCP) server. The paper also analyzes the attack surface an MCP-exposed offensive engine introduces, grounding a threat model in 2025 MCP incidents including CVE-2025-6514 (RCE in mcp-remote), the postmark-mcp supply-chain backdoor, and tool-poisoning/rug-pull/line-jumping classes, and proposes four mitigations.