head to head · open source
pentest-ai-agents vs pipelock
pentest-ai-agents has 2,248 GitHub stars, 429 forks, 1 open issues and last shipped 1 months ago. pipelock has 886 stars, 101 forks, 7 open issues and last shipped today. pentest-ai-agents leads on adoption by 154% (2,248 vs 886 stars). pentest-ai-agents is written in Shell under MIT; pipelock is written in Go under Apache-2.0. pentest-ai-agents has attracted 19% as many forks as stars, pipelock 11%. pipelock was the more recently maintained of the two, and both are self-hostable with no licence fee. The two share 2 topic tags (ai-agents, ai-security), so they are genuine substitutes rather than adjacent tools.
Two open source projects, one decision. Both are free and self-hostable — the differences are community size, license terms, language stack and release pace.
← all 20902 open source comparisons
Side by side
| pentest-ai-agents | pipelock | |
|---|---|---|
| GitHub stars | ★ 2.2K | ★ 886 |
| License | MIT | Apache-2.0 |
| Written in | Shell | Go |
| Last push | 2026-08-16 | 2026-09-20 |
| Forks | ⑂ 429 | ⑂ 101 |
| Self-hosting | Yes | Yes |
| Data ownership | Your server | Your server |
pick pentest-ai-agents if
- You weight community size — 2.2K stars and counting
- You want the MIT license terms
- Your stack matches Shell
- You value the larger contributor base for long-term maintenance
pick pipelock if
- You want the pipelock feature set and don't need the biggest community
- You prefer the Apache-2.0 license terms
- Your stack matches Go
- You evaluated both and pipelock fits your workflow better
About pentest-ai-agents
pentest ai agents: 50 Claude Code subagents for authorized offensive security research. Lives in Claude Code ecosystem. Agents carry domain knowledge for recon, web, Active Directory, cloud, mobile, wireless, social engineering, payload crafting, reverse engineering, exploit chaining, detection engineering, forensics.
read the full pentest-ai-agents overview →
About pipelock
Pipelock is an open source AI agent firewall written in Go and licensed Apache 2.0 that sits between AI agents and the network, inspecting mediated HTTP, WebSocket, MCP, and A2A traffic for secret exfiltration, prompt injection, SSRF, tool poisoning, and risky tool call chains, and emitting mediator signed action receipts so a reviewer can verify what the boundary decided from outside the agent runtime.
read the full pipelock overview →
More in AI & Machine Learning
Related comparisons
More AI Security & Privacy projects
Compare either of these against the rest of the AI Security & Privacy field.
Frequently asked questions
Is pentest-ai-agents or pipelock more popular?
pentest-ai-agents has 2,248 GitHub stars and pipelock has 886. pentest-ai-agents has the larger community by that measure.
Are pentest-ai-agents and pipelock free?
Both are open source. pentest-ai-agents is licensed under MIT and pipelock under Apache-2.0. Neither carries a licence fee.
What is the difference between pentest-ai-agents and pipelock?
pentest-ai-agents is written in Shell and pipelock in Go. The practical differences are community size, licence terms, language stack and release cadence — all compared in the table above.
Which should I choose, pentest-ai-agents or pipelock?
Choose pentest-ai-agents if you want the larger community (2,248 stars) or its MIT licence terms. Choose pipelock if its feature set, stack or Apache-2.0 licence fits better. Both are self-hostable.