AutoPentest is an automated Web application penetration testing server based on the MCP protocol, integrating the OWASP WSTG and PortSwigger attack technique guides. It realizes a seven - stage automated testing through role - based agents (scout, analyst, exploiter, reporter), including 109 tests, 31 attack techniques, 27 security tools, and the ability to bypass WAF adaptively, ensuring zero false positives and evidence - driven vulnerability discovery.