Show HN: An agent harness for long-running pentests and code audits (github.com)

🤖 AI Summary
Vigil has emerged as a pioneering framework for automating long-running penetration tests and code audits, integrating AI-driven methodologies to enhance security engagements through a command-line interface (CLI). This tool combines a phased workflow that leverages large language models (LLMs) like Claude Code and Codex to orchestrate operations within a shared Kali Linux environment, recording every aspect of the engagement—from target data to attack chains—into a robust database. Vigil supports five operational modes: red-teaming for web applications, white-box code analysis, Android app evaluation, and blue team incident response, making it a versatile addition to security professionals' arsenals. The significance of Vigil lies in its potential to streamline and enhance the efficiency of security assessments while maintaining rigorous documentation and command auditing. The integration of durable state management ensures continuity across sessions, while the use of advanced AI models provides adaptability and increased efficacy in threat detection and response. With built-in features for real attack tooling and automated responses, Vigil not only empowers independent researchers and authorized entities but also addresses the need for reliability and verification in security operations. As AI access becomes more regulated, Vigil's upcoming support for alternative models like GLM 5.3 may further democratize access to advanced security tools, fostering broader participation in authorized security research.
Loading comments...
loading comments...