PentestChain keeps a 7B local model off the critical path behind a deterministic exploit map and runs an eleven-tool MCP pentest pipeline at zero paid-API cost
The framework's architecture choice is the transferable part: a curated deterministic exploit backbone does the work that must be correct, and a cost-aware AI cascade (local Ollama qwen2.5-7b first, then free-tier OpenRouter and Cerebras, then a rule-based fallback that always produces output) handles the rest, so the cheapest model never sits on the critical path. The authors treat US-dollar cost per engagement as a first-class measured metric and sustain end-to-end operation at zero measured paid-API cost. They also ground a four-position threat model for an MCP-exposed offensive engine in the 2025 incident record, naming CVE-2025-6514 in mcp-remote, the postmark-mcp supply-chain backdoor, and the tool-poisoning / rug-pull / line-jumping class, and contribute four mitigations. Reported results so far cover legacy targets only (26 services detected, 34 CVEs enriched), so treat the pentest numbers as preliminary and the cascade design as the takeaway.
↳ Follow the thread