经 AI Skill Hub 精选评估,Vigolium 获评「强烈推荐」。这款Agent工作流在功能完整性、社区活跃度和易用性方面表现出色,AI 评分 8.0 分,适合有一定技术背景的用户使用。
Vigolium 是一套完整的 AI Agent 自动化工作流方案。通过可视化的节点编排,将复杂的多步骤任务拆解为清晰的自动化流程,实现全程无人值守的智能处理。支持与数百种外部服务和 API 无缝集成,适合构建数据处理管线、业务自动化和 AI 辅助决策系统。
Vigolium 是一套完整的 AI Agent 自动化工作流方案。通过可视化的节点编排,将复杂的多步骤任务拆解为清晰的自动化流程,实现全程无人值守的智能处理。支持与数百种外部服务和 API 无缝集成,适合构建数据处理管线、业务自动化和 AI 辅助决策系统。
# 方式一:go install(推荐) go install github.com/vigolium/vigolium@latest # 方式二:从源码编译 git clone https://github.com/vigolium/vigolium cd vigolium go build -o vigolium . # 方式三:下载预编译二进制 # 访问 Releases 页面下载对应平台二进制文件 # https://github.com/vigolium/vigolium/releases
# 查看帮助 vigolium --help # 基本运行 vigolium [options] <input> # 详细使用说明请查阅文档 # https://github.com/vigolium/vigolium
# vigolium 配置说明 # 查看配置选项 vigolium --config-example > config.yml # 常见配置项 # output_dir: ./output # log_level: info # workers: 4 # 环境变量(覆盖配置文件) export VIGOLIUM_CONFIG="/path/to/config.yml"
<p align="center"> <img alt="Vigolium" src="https://avatars.githubusercontent.com/u/266502139?s=200&v=4" height="140" /> <br /> <strong>Vigolium - High-fidelity vulnerability scanner fusing agentic AI with native speed, modularity, and precision</strong>
<p align="center"> <a href="https://console.vigolium.com/"><img src="https://img.shields.io/badge/Vigolium-Cloud-0078D4?style=flat&logo=google-cloud&logoColor=ffb86c&labelColor=black&color=black"></a> <a href="https://docs.vigolium.com/"><img src="https://img.shields.io/badge/Documentation-0078D4?style=flat&logo=GitBook&logoColor=8be9fd&labelColor=black&color=black"></a> <a href="https://twitter.com/Vigolium"><img src="https://img.shields.io/badge/Vigolium-0078D4?style=flat&logo=X&logoColor=f8f8f2&labelColor=black&color=black"></a> <a href="https://discord.gg/aHFypbAu6Y"><img src="https://img.shields.io/badge/Discord%20Server-0078D4?style=flat&logo=Discord&logoColor=bd93f9&labelColor=black&color=black"></a> <a href="https://www.linkedin.com/company/vigolium"><img src="https://custom-icon-badges.demolab.com/badge/LinkedIn-black?logo=linkedin-white&logoColor=39ff14"></a> <a href="https://www.linkedin.com/company/vigolium"><img src="https://img.shields.io/npm/v/@vigolium/vigolium.svg?style=flat&logo=npm&logoColor=50fa7b&labelColor=black&color=black"></a> </p> </p>
***
Vigolium provides two complementary scanning modes:
vigolium scan): Fast, powerful, and flexible. Deterministic, multi-phase scanning with 251 modules across content discovery, browser/SPA spidering, and active/passive audit, covering injection, access control, file/path, API/protocol, framework-specific, cloud/infra, and out-of-band (OAST) vulnerability classes.vigolium agent): Thoroughly audits your codebase. AI-driven scanning that autonomously plans attacks, selects modules, generates custom extensions, and triages results, combining deep source-code audit with autonomous and targeted vulnerability scanning.curl -fsSL https://vigolium.com/install.sh | bash
docker pull j3ssie/vigolium:latest
docker run --rm j3ssie/vigolium:latest scan -h
git clone https://github.com/vigolium/vigolium.git
cd vigolium
make build # build and install to $GOPATH/bin
Requires Go 1.26+ and bun 1.3.11+. See HACKING.md for prerequisites and build details.
| UI Dashboard | Traffic Dashboard |
|---|---|
|  |  |
| Static Reports | Static Reports |
|---|---|
|  |  |
| Native scan | Agentic Scan |
|---|---|
|  |  |
```bash
vigolium agent swarm -t https://example.com/api/users --vuln-type sqli vigolium agent swarm -t https://example.com --discover # full-scope vigolium agent swarm -t https://example.com --source ./src --discover # source-aware full-scope vigolium agent swarm --input "curl -X POST https://example.com/api/login -d '{\"user\":\"admin\"}'"
vigolium scan -t https://example.com --auth-config ./auth-config.yaml
vigolium scan -T openapi.yaml -I openapi
vigolium server -k my-secret-key
vigolium ingest -s http://localhost:9002 -i api.yaml -I openapi ```
See docs.vigolium.com/server-mode/running-the-server for server setup, docs.vigolium.com/server-mode/ingestion for ingestion workflows, and docs.vigolium.com/api-overview for the full REST API reference.
Burp Suite integration: forward live Burp Suite traffic to a running Vigolium server with the burp-vigolium extension.
vigolium scan -t https://example.com \ --session "admin:Cookie:session_id=abc123" \ --session "user:Cookie:session_id=xyz789"
vigolium scan -t https://example.com -m xss-reflected,sqli-error
vigolium ext ls # list loaded extensions vigolium ext docs --example # browse API with code examples vigolium ext preset # install starter scripts
The JS engine exposes session-aware HTTP APIs for authenticated testing:
javascript // Create a persistent session with shared cookie jar let session = vigolium.http.session(); session.post("https://app.example.com/login", { user: "admin", pass: "secret" }); session.get("https://app.example.com/dashboard"); // cookies auto-sent
// Automated login flow with token extraction let authed = vigolium.http.login({ url: "https://app.example.com/api/auth", method: "POST", body: JSON.stringify({ username: "admin", password: "pass" }), extract: [{ source: "json", path: "$.token", apply_as: "Authorization: Bearer {value}" }] });
// IDOR/BOLA testing across multiple sessions let results = vigolium.http.authTest({ sessions: { admin: adminSession, user: userSession }, requests: [{ method: "GET", url: "https://app.example.com/api/users/1" }] });
// Multi-step authentication sequences let result = vigolium.http.sequence([ { url: "/csrf", extract: [{ source: "cookie", name: "csrf_token", as: "token" }] }, { url: "/login", method: "POST", body: "csrf={token}&user=admin" } ]);
// Parallel request batching (race conditions, IDOR) let responses = vigolium.http.batch([req1, req2, req3], { concurrency: 10 });
// CSRF token extraction let csrf = vigolium.http.csrf("https://app.example.com/form");
// HTTP request replay with variations let varied = vigolium.http.replay(rawRequest, [ { headers: { "Authorization": "Bearer admin_token" } }, { headers: { "Authorization": "Bearer user_token" } } ]); ```
See docs.vigolium.com/customization/writing-extensions for the extension authoring guide and pkg/jsext/vigolium.d.ts for the full TypeScript API definitions.
高质量的安全审计工具,AI融合带来高效扫描
该工具使用 NOASSERTION 协议,商用场景请仔细阅读协议条款,必要时咨询法律意见。
AI Skill Hub 为第三方内容聚合平台,本页面信息基于公开数据整理,不对工具功能和质量作任何法律背书。
建议在沙箱或测试环境中充分验证后,再部署至生产环境,并做好必要的安全评估。
📄 NOASSERTION — 请查阅原始协议条款了解具体使用限制。
AI Skill Hub 点评:Vigolium 的核心功能完整,质量优秀。对于自动化工程师和运维人员来说,这是一个值得纳入个人工具库的选择。建议先在非生产环境试用,再逐步推广。
| 原始名称 | vigolium |
| Topics | 安全审计漏洞扫描AIGo |
| GitHub | https://github.com/vigolium/vigolium |
| License | NOASSERTION |
| 语言 | Go |
收录时间:2026-05-27 · 更新时间:2026-05-27 · License:NOASSERTION · AI Skill Hub 不对第三方内容的准确性作法律背书。
选择 Agent 类型,复制安装指令后粘贴到对应客户端