Register the local server
Install Pentest-AI and Claude Code first. Then run:
claude mcp add --scope user --transport stdio pentest-ai -- ptai mcp
Restart Claude Code and inspect /mcp. If the server cannot start, check that
the ptai executable is available in the client's environment.
Define the engagement
Tell the client the authorized target, the allowed scope and any constraints. Review tool requests and findings as the engagement progresses. A convenient chat interface does not replace target authorization or human judgment.
Ask for the evidence
Inspect the verification result, not only the model's explanation. Candidates are distinct from oracle-verified findings, and a proof capsule can carry a supported check to the person reproducing the issue.
Using Codex instead?
The same MCP server works with Codex:
codex mcp add pentest-ai -- ptai mcp
The client setup guide covers the shared setup wizard, direct commands and local-model options.