Autonomous AI pentesting agents for real-time reconnaissance, vulnerability detection, and exploitation

You’ve been there. Your scanner finishes, and you’re staring at 400 “potential” issues. Half are false positives, a quarter are noise, and you’ll spend the next three days working out which ones matter. A new open-source project called Xalgorix wants to end that misery. It has already collected over 1,100 GitHub stars.

The Scanner That Refuses to Guess

Xalgorix’s pitch is blunt: most scanners detect, Xalgorix proves. It is an autonomous AI pentesting agent built in Go and TypeScript. An LLM-driven agent works through a full testing methodology, and then a separate, independent verifier tries to re-exploit every finding before it lands in your report.

Findings it can’t reproduce are flagged for review. They are never dressed up as confirmed. You get evidence, not a pile of maybes.

22 Phases of Digital Mayhem (Authorized Only)

The agent doesn’t run a fixed template list. It follows a 22-phase methodology covering:

  • Reconnaissance and directory discovery
  • Authentication and session testing
  • Injection, SSRF, and IDOR/broken access control
  • API and GraphQL testing
  • Race conditions and business logic flaws
  • Subdomain takeover, cloud and infrastructure checks
  • Exploit verification, then a “novel vulnerability discovery” phase

That reasoning-heavy approach is what lets it chase business logic bugs and chained exploits that signature-based tools tend to miss.

Installation: Under a Minute

There are four ways to get running.

Option 1: One-line install (Linux or macOS, amd64/arm64)

bash
curl -sSL https://www.xalgorix.com/install | bash
xalgorix --setup

The setup wizard asks for your LLM provider, model, and API key. It stores the key privately in ~/.xalgorix.env with restricted permissions. Local Ollama needs no key at all.

Option 2: Docker (batteries included)

bash
docker run --rm -p 9137:9137 \
  --privileged \
  -v xalgorix-data:/data \
  xalgord/xalgorix:latest

The image ships with nmap, nuclei, httpx, subfinder, katana, ffuf, sqlmap, masscan, and more. If you don’t set credentials, a random admin password is printed to the container logs on first run. Prefer Compose? Download the project’s docker-compose.yml and run docker compose up -d.

Option 3: Build from source (needs Go 1.26+ and Node.js)

bash
git clone https://github.com/xalgorix/xalgorix.git
cd xalgorix
make build
sudo install -m 755 build/xalgorix /usr/local/bin/xalgorix

Option 4: Kubernetes. A Helm chart lives in deploy/chart in the repo.

Bring Your Own Brain

Xalgorix doesn’t lock you into one AI vendor. It works with OpenAI, Anthropic, DeepSeek, Gemini, Groq, Ollama, and MiniMax. It also works with any OpenAI-compatible gateway such as LiteLLM, which opens the door to OpenRouter, Azure, and local models. A minimal config looks like this:

bash
XALGORIX_LLM=openai/gpt-5.6
XALGORIX_API_KEY=your_api_key

A current frontier model with strong reasoning and reliable tool calling gives the best results. Smaller local models work but may need more babysitting on long scans.

Usage: From Zero to Report

The dashboard route. Launch the web UI:

bash
xalgorix --web

Open http://127.0.0.1:9137, then:

  1. Confirm your LLM settings under Settings.
  2. Click New Scan and pick a mode: single target, wildcard/multi-target, or DAST for browser-assisted testing.
  3. Optionally select specific methodology phases for a focused run.
  4. Watch tool calls, findings, and agent reasoning stream in live over WebSockets.
  5. Download a branded PDF report with CVSS scores, proof-of-concept, and remediation advice.
The command-line route:
bash
xalgorix --target https://app.example.com \
  --instruction "Focus on SQL injection, IDOR, and auth bypass. Avoid destructive tests."

Scan your source code, no live target needed:

bash
xalgorix --source ./my-app --code-scan review

review mode traces user input from entry point to dangerous sink. provision mode builds and runs the app on a loopback port, then pentests it.

Run it as a service. sudo xalgorix --start installs it as a system service. You can then push alerts to Discord or Telegram as findings arrive.

Self-Hosted or Cloud?

The engine is free under Apache-2.0, and your data stays on your infrastructure. If you’d rather skip API keys and surprise token bills, there’s a hosted version at xalgorix.com that runs the same engine.

The Fine Print (Read This Part)

Xalgorix is an offensive-security tool. Only point it at systems you own or have explicit written permission to test. The container runs privileged and as root by design, so treat it as a disposable sandbox. Never expose the dashboard publicly without authentication. The tool refuses external binding without auth, and by default it also refuses to scan localhost and private ranges.

Verdict

Xalgorix isn’t a magic wand. LLM costs and model quality will shape your results, and you should still review findings like any professional. But the verify-before-reporting approach directly targets the biggest pain in vulnerability scanning: the triage grind. For bug bounty hunters, red teamers, and small security teams, it’s worth an afternoon of experimenting.

Repo: https://github.com/xalgorix/xalgorix