
vigolium v0.3.6
Vigolium - High-fidelity vulnerability scanner fusing agentic AI with native speed, modularity, and precision
Vigolium - High-fidelity vulnerability scanner fusing agentic AI with native speed, modularity, and precision
Vigolium provides two complementary scanning modes:
-
Native Scan (
vigolium scan): Fast, powerful, and flexible. Deterministic, multi-phase scanning with 317 modules across content discovery, browser/SPA spidering, and active/passive audit, covering injection, access control, file/path, API/protocol, framework-specific, cloud/infra, and out-of-band (OAST) vulnerability classes. -
Agentic Scan (
vigolium agent): Thoroughly audits your codebase. AI-driven scanning that autonomously plans attacks, selects modules, generates custom extensions, and triages results, combining deep source-code audit with autonomous and targeted vulnerability scanning.
Installation
Quick Install (Recommended)
curl -fsSL https://vigolium.com/install.sh | bash
npm
npm install -g @vigolium/vigolium
Windows
The npm install above works on Windows. Alternatively, download
vigolium_<version>_windows_amd64.zip from the
releases page, extract it, and
put vigolium.exe somewhere on your PATH.
Windows ships as x64 only; on Windows ARM it runs under emulation. The shell installer above is POSIX-only, so
vigolium updateis not available on Windows — re-run the npm install or download the newer zip to upgrade.
Other method like Docker or Build from source
Docker
docker pull j3ssie/vigolium:latest
docker run --rm j3ssie/vigolium:latest scan -h
Build from Source
git clone https://github.com/vigolium/vigolium.git
cd vigolium
make build # build and install to $GOPATH/bin
Requires Go 1.27+ and bun 1.3.11+. See HACKING.md for prerequisites and build details.
| UI Dashboard | Traffic Dashboard |
|---|---|
![]() | ![]() |
| Static Reports | Static Reports |
|---|---|
![]() | ![]() |
| Native scan | Agentic Scan |
|---|---|
![]() | ![]() |
Sponsor
Thank you to Daytona for sponsoring the sandbox infrastructure
Key Features
Native Scan
- 324 scanner modules: 208 active (fuzzing) + 117 passive (pattern matching), covering OWASP Top 10 and beyond
- Out-of-band testing (OAST): blind XSS/SSRF/command injection via interactsh callbacks with automatic payload correlation
- Value-aware mutation: classifies parameters by semantic type (integer, UUID, JWT, email) and mutates per intent
- Multi-phase pipeline: external harvesting, content discovery (Deparos), browser/SPA spidering (Spitolas), and audit, controlled by strategy presets and scanning profiles
- Flexible inputs: URLs, OpenAPI/Swagger, Postman, Burp Suite, cURL, Nuclei JSONL
- Multi-session authentication: inline sessions, session files, or full auth configs with login flows, token extraction, and IDOR/BOLA testing
- JavaScript extensions: custom modules and hooks via embedded JS engine with session-aware HTTP APIs
- Scalable & reportable: concurrent worker pool with per-host rate limiting, hybrid in-memory/disk/Redis queue, and self-contained HTML reports
Agentic Scan
- In-process olium runtime: every agent mode runs on the native Go
pkg/oliumengine: turn-based loop, built-in tool registry, skills support, and pluggable provider drivers (no subprocess SDK pools) - Autopilot: agent autonomously discovers endpoints, runs scans, and triages findings, with optional multi-specialist pipeline and session resume
- Swarm: master agent selects modules, generates custom JS attack extensions, runs code audit + SAST, executes scans, and triages results; targeted or full-scope (
--discover), with--diff/--last-commitsfor change-focused runs - Source-audit drivers:
audit,piolium, and the unifiedauditdispatcher run foreground source-code audits sharing one finding schema and DB tagging - Query mode: single-shot prompts for code review, endpoint discovery, and secret detection
- Pluggable providers:
openai-compatible(default),openai-codex-oauth,openai-api-key,openai-responses,anthropic-api-key,anthropic-oauth,anthropic-cli,anthropic-compatible,anthropic-vertex,google-vertex. Same modes exposed over the REST API with SSE streaming and an OpenAI-compatible chat endpoint
Quick Start: Native Scan
# Scan a single target (default: balanced strategy)
vigolium scan -t https://example.com
# Scan with a strategy preset
vigolium scan -t https://example.com --strategy deep
# Scan specific modules only
vigolium scan -t https://example.com -m xss-reflected,sqli-error
# Scan from an OpenAPI spec
vigolium scan -T openapi.yaml -I openapi
# Pipe URLs from stdin
cat urls.txt | vigolium scan
# Run a single phase directly
vigolium run discovery -t https://example.com
# Generate an HTML report
vigolium scan -t https://example.com --only discovery --format html -o report.html
See the architecture overview for the full pipeline and the strategies guide for strategies, profiles, and pace configuration. For a quick command reference, see docs.vigolium.com/getting-started/cheat-sheet.
Server Mode
# Start API server with authentication
vigolium server -k my-secret-key





