OWASP Penetration Testing Kit (PTK) is an open-source browser extension for testing web applications from the live browser session where they actually run.
PTK combines DAST, client-side SAST, in-browser IAST, SCA, traffic inspection, request replay, and JWT testing. It can test authenticated applications and single-page applications using the application state, traffic, and client-side code visible to the browser.
PTK provides its own extension interface. It does not use browser DevTools and does not require traffic to be routed through a separate desktop proxy for its normal testing workflows.
For interactive DAST, IAST, client-side SAST, SCA, traffic inspection, Request Builder, cookies, JWT testing and other manual pentesting workflows.
PTK complements full interception proxies, network scanners, and repository-level source-code analysis tools; it is not intended to replace all of them.
Its particular strength is testing what the browser can actually see and execute: authenticated workflows, browser-generated traffic, loaded client-side code, DOM behaviour, SPA navigation, and runtime application state.
The pentestkit npm package provides the CLI, framework integrations and browser runtime acquisition used for automation.
npm install -D pentestkit
npx ptk-agent --doctor-extension
Use the published PTK Action to run the same agent lifecycle in CI, retain scan artifacts and publish supported findings to code scanning.
For automated tests, CLI workflows, CI/CD pipelines and supported browser-testing providers. PTK Auto is controlled by an authorised automation client and is not a replacement for the interactive extension.Chrome Web Store.
Capture requests generated while using the application and run selected DAST attacks against specific requests, parameters, and request bodies. Findings include the request, payload, and evidence needed to review and reproduce the result.
Analyse JavaScript and HTML loaded by the browser for insecure patterns and client-side vulnerabilities. PTK can trace browser-controlled data from sources to dangerous sinks and report the relevant code and data flow.
Instrument selected browser behaviour while the application executes. PTK can identify security-relevant DOM operations, navigation, browser messaging, and other client-side behaviour that only becomes visible at runtime.
Identify client-side frameworks and libraries and report known vulnerable versions where matching vulnerability data is available.
Inspect and replay browser traffic, modify requests, import or export cURL commands, analyse and test JWTs, manage cookies and browser storage, and review security headers, application technologies, and discovered routes.
OWASP PTK is the interactive extension for tester-driven security testing. OWASP PTK Automation (PTK Auto) is the separate browser runtime used by PTK Agent for automated tests, CLI workflows, CI/CD pipelines, and supported browser-testing platforms.
PTK Agent supports Playwright, Puppeteer, Selenium, and Cypress, together with supported cloud-browser providers. PTK also integrates with ZAP so browser-side PTK analysis can be combined with broader ZAP testing.
Contributions, test cases, bug reports, and feature requests are welcome.
Use PTK only against systems where you have explicit authorisation. Active scanning, crawling, request modification, and token testing can generate load, modify application data, or trigger security monitoring. Confirm the permitted targets, test accounts, testing window, rate limits, and allowed test types before starting.
Many security tools begin outside the application and must reconstruct authentication, navigation, and application state. PTK starts from the browser session already being used by the tester. It can work with the authenticated user context, cookies, tokens, SPA routes, loaded JavaScript, DOM state, and browser-generated API traffic. This makes PTK particularly useful for testing authenticated workflows, single-page applications, and client-side behaviour.