ok-helloworld/vibe-pentest

Vibe Pentest 是一款模拟人类安全专家思维挖掘漏洞的 AI 渗透测试工具,采用多 Agent 并行执行架构,能够对 Web 应用、API、管理后台等进行全面的渗透测试(包括业务逻辑漏洞评估),输出稳定可靠的安全报告,并提供可落地的整改建议。

What it solves

Vibe Pentest is an AI-driven penetration testing tool designed to simulate the thinking process of human security experts. It automates the discovery of vulnerabilities in Web applications, APIs, and administrative backends, reducing the manual effort required for black-box security assessments and business logic vulnerability evaluations.

How it works

The tool employs a multi-agent parallel execution architecture where specialized AI agents are assigned different security testing roles. The process follows a structured pipeline:

  1. Reconnaissance: Performs fingerprinting, backend entry scanning, and API pre-scanning.
  2. Discovery: Uses GoSpider for crawling and data cleaning to map the attack surface.
  3. Execution: Deploys specific agents (e.g., injection-agent, poc-agent, api-agent, auth-agent, file-agent, business-agent) to hunt for vulnerabilities in parallel.
  4. Reporting: Analyzes attack chains, verifies evidence, and generates professional reports in HTML and Word formats.

It integrates with AI agent software (like Qoder or Claude Code) to orchestrate these tasks and can use Playwright for browser-based credential extraction.

Who it’s for

It is primarily built for security service companies and individual white-hat hackers who need a scalable, automated way to conduct authorized security audits.

Highlights

  • Multi-Agent Architecture: Uses specialized agents for different vulnerability types (SQLi, XSS, BOLA/BFLA, business logic, etc.) to increase coverage.
  • Flexible Penetration Modes: Offers a "Low Impact High Reward" mode for batch testing and a "Standard Mode" for deep-dive analysis of single sites.
  • Fingerprint-POC Linkage: Automatically matches identified technology stacks to relevant POCs to optimize testing efficiency.
  • Ethical Constraints: Built-in white-hat professional ethics constraints to ensure minimal impact on target systems.

相關

  • 專案
  • 專案
  • 專案
  • 專案