++++
Vigolium
Vigolium
v1.0.0-alpha
// An agent-agnostic vulnerability scanner

High-fidelity vulnerability scanner fusing agentic AI with native speed, modularity, and precision.

Try open-source on your machine
$ curl -fsSL /install.sh | bash
Vigolium Dashboard
Vigolium Main Workbench
// Features

Core Components

01

Native Scan

Deterministic, multi-phase scanning with active and passive modules. Content discovery, browser spidering, SPA crawling, SAST, and audit — all in one pipeline.

02

Agentic Scan

AI agents autonomously plan attacks, select modules, generate custom payloads, and triage results. Powered by Claude, Codex, Gemini, or OpenCode.

03

Native Speed

Core engine written in Go. Configurable worker pools with per-host rate limiting and hybrid in-memory/disk/Redis queues.

04

Dynamic Extensions

Agents write custom checks on the fly via an embedded JS engine. Discover and load sessions during scans with session-aware HTTP APIs and multi-step auth flows.

// Process

How It Works

+

Ingest

Feed targets via URLs, OpenAPI specs, Postman collections, Burp exports, cURL commands, or live proxy traffic.

+

Scan

Run native scans with strategy presets, or let AI agents autonomously discover endpoints and orchestrate attacks.

+

Report

Get findings with full request/response evidence, confidence scoring, and exportable HTML reports.

// Capabilities

What We Detect

Injection

XSS (reflected, DOM, SSR), SQLi, NoSQL, SSTI, command injection, XXE, prototype pollution

01

Access Control

CSRF, IDOR, authorization bypass, mass assignment, HTTP method tampering

02

API & Protocol

GraphQL introspection, SSRF, open redirect, request smuggling, JWT flaws, race conditions

03

Framework-Specific

Spring Boot, Django, Laravel, Rails, Express, Next.js, Nuxt, ASP.NET, Flask, FastAPI

04

Cloud & Infra

Firebase, cloud storage takeover, default credentials, web cache poisoning, CORS misconfiguration

05

Adaptive Learning

Agents continuously learn from scan results, refining detection strategies and adapting to new attack surfaces

06
// Metrics

By The Numbers

0

Scanner modules — active and passive

0

Native scan phases

0

Agentic scan phases

0

Frameworks with dedicated scanners

0

Agent learning capacity — always evolving

// Ecosystem

Integrations

+

CI/CD Pipelines

GitHub Actions, GitLab CI, Jenkins

+

Burp Suite

Import/export Burp XML traffic

+

API Server

REST API with Swagger UI and traffic ingestion

+

OpenAPI / Swagger

Auto-ingest API specifications

+

AI Backends

Claude, Codex, Gemini, OpenCode, Cursor via Agent SDK

// Cloud

Vigolium Cloud

Coming Soon

Managed scanning infrastructure, team collaboration, and continuous monitoring — all without self-hosting.