Vigolium - High-fidelity vulnerability scanner fusing agentic AI with native speed, modularity, and precision
Vigolium - High-fidelity vulnerability scanner fusing agentic AI with native speed, modularity, and precision
Vigolium provides two complementary scanning modes:
Native Scan (vigolium scan): Fast, powerful, and flexible. Deterministic, multi-phase scanning with 317 modules across content discovery, browser/SPA spidering, and active/passive audit, covering injection, access control, file/path, API/protocol, framework-specific, cloud/infra, and out-of-band (OAST) vulnerability classes.
Agentic Scan (vigolium agent): Thoroughly audits your codebase. AI-driven scanning that autonomously plans attacks, selects modules, generates custom extensions, and triages results, combining deep source-code audit with autonomous and targeted vulnerability scanning.
curl -fsSL https://vigolium.com/install.sh | bash
npm install -g @vigolium/vigolium
The npm install above works on Windows. Alternatively, download
vigolium_<version>_windows_amd64.zip from the
releases page, extract it, and
put vigolium.exe somewhere on your PATH.
Windows ships as x64 only; on Windows ARM it runs under emulation. The shell installer above is POSIX-only, so
vigolium updateis not available on Windows — re-run the npm install or download the newer zip to upgrade.
docker pull j3ssie/vigolium:latest
docker run --rm j3ssie/vigolium:latest scan -h
git clone https://github.com/vigolium/vigolium.git
cd vigolium
make build # build and install to $GOPATH/bin
Requires Go 1.27+ and bun 1.3.11+. See HACKING.md for prerequisites and build details.
| UI Dashboard | Traffic Dashboard |
|---|---|
![]() | ![]() |
| Static Reports | Static Reports |
|---|---|
![]() | ![]() |
| Native scan | Agentic Scan |
|---|---|
![]() | ![]() |
Thank you to Daytona for sponsoring the sandbox infrastructure
pkg/olium engine: turn-based loop, built-in tool registry, skills support, and pluggable provider drivers (no subprocess SDK pools)--discover), with --diff/--last-commits for change-focused runsaudit, piolium, and the unified audit dispatcher run foreground source-code audits sharing one finding schema and DB taggingopenai-compatible (default), openai-codex-oauth, openai-api-key, openai-responses, anthropic-api-key, anthropic-oauth, anthropic-cli, anthropic-compatible, anthropic-vertex, google-vertex. Same modes exposed over the REST API with SSE streaming and an OpenAI-compatible chat endpoint# Scan a single target (default: balanced strategy)
vigolium scan -t https://example.com
# Scan with a strategy preset
vigolium scan -t https://example.com --strategy deep
# Scan specific modules only
vigolium scan -t https://example.com -m xss-reflected,sqli-error
# Scan from an OpenAPI spec
vigolium scan -T openapi.yaml -I openapi
# Pipe URLs from stdin
cat urls.txt | vigolium scan
# Run a single phase directly
vigolium run discovery -t https://example.com
# Generate an HTML report
vigolium scan -t https://example.com --only discovery --format html -o report.html
See the architecture overview for the full pipeline and the strategies guide for strategies, profiles, and pace configuration. For a quick command reference, see docs.vigolium.com/getting-started/cheat-sheet.
# Start API server with authentication
vigolium server -k my-secret-key