You’ve been there. Your scanner finishes, and you’re staring at 400 “potential” issues. Half are false positives, a quarter are noise, and you’ll spend the next three days working out which ones matter. A new open-source project called Xalgorix wants to end that misery. It has already collected over 1,100 GitHub stars.
The Scanner That Refuses to Guess
Xalgorix’s pitch is blunt: most scanners detect, Xalgorix proves. It is an autonomous AI pentesting agent built in Go and TypeScript. An LLM-driven agent works through a full testing methodology, and then a separate, independent verifier tries to re-exploit every finding before it lands in your report.
Findings it can’t reproduce are flagged for review. They are never dressed up as confirmed. You get evidence, not a pile of maybes.
22 Phases of Digital Mayhem (Authorized Only)
The agent doesn’t run a fixed template list. It follows a 22-phase methodology covering:
- Reconnaissance and directory discovery
- Authentication and session testing
- Injection, SSRF, and IDOR/broken access control
- API and GraphQL testing
- Race conditions and business logic flaws
- Subdomain takeover, cloud and infrastructure checks
- Exploit verification, then a “novel vulnerability discovery” phase
That reasoning-heavy approach is what lets it chase business logic bugs and chained exploits that signature-based tools tend to miss.
Installation: Under a Minute
There are four ways to get running.
Option 1: One-line install (Linux or macOS, amd64/arm64)
curl -sSL https://www.xalgorix.com/install | bash
xalgorix --setup
The setup wizard asks for your LLM provider, model, and API key. It stores the key privately in ~/.xalgorix.env with restricted permissions. Local Ollama needs no key at all.
Option 2: Docker (batteries included)
docker run --rm -p 9137:9137 \
--privileged \
-v xalgorix-data:/data \
xalgord/xalgorix:latest
The image ships with nmap, nuclei, httpx, subfinder, katana, ffuf, sqlmap, masscan, and more. If you don’t set credentials, a random admin password is printed to the container logs on first run. Prefer Compose? Download the project’s docker-compose.yml and run docker compose up -d.
Option 3: Build from source (needs Go 1.26+ and Node.js)
git clone https://github.com/xalgorix/xalgorix.git
cd xalgorix
make build
sudo install -m 755 build/xalgorix /usr/local/bin/xalgorix
Option 4: Kubernetes. A Helm chart lives in deploy/chart in the repo.
Bring Your Own Brain
Xalgorix doesn’t lock you into one AI vendor. It works with OpenAI, Anthropic, DeepSeek, Gemini, Groq, Ollama, and MiniMax. It also works with any OpenAI-compatible gateway such as LiteLLM, which opens the door to OpenRouter, Azure, and local models. A minimal config looks like this:
XALGORIX_LLM=openai/gpt-5.6
XALGORIX_API_KEY=your_api_key
A current frontier model with strong reasoning and reliable tool calling gives the best results. Smaller local models work but may need more babysitting on long scans.
Usage: From Zero to Report
The dashboard route. Launch the web UI:
xalgorix --web
Open http://127.0.0.1:9137, then:
- Confirm your LLM settings under Settings.
- Click New Scan and pick a mode: single target, wildcard/multi-target, or DAST for browser-assisted testing.
- Optionally select specific methodology phases for a focused run.
- Watch tool calls, findings, and agent reasoning stream in live over WebSockets.
- Download a branded PDF report with CVSS scores, proof-of-concept, and remediation advice.

xalgorix --target https://app.example.com \
--instruction "Focus on SQL injection, IDOR, and auth bypass. Avoid destructive tests."
Scan your source code, no live target needed:
xalgorix --source ./my-app --code-scan review
review mode traces user input from entry point to dangerous sink. provision mode builds and runs the app on a loopback port, then pentests it.

sudo xalgorix --start installs it as a system service. You can then push alerts to Discord or Telegram as findings arrive.Self-Hosted or Cloud?
The engine is free under Apache-2.0, and your data stays on your infrastructure. If you’d rather skip API keys and surprise token bills, there’s a hosted version at xalgorix.com that runs the same engine.

The Fine Print (Read This Part)
Xalgorix is an offensive-security tool. Only point it at systems you own or have explicit written permission to test. The container runs privileged and as root by design, so treat it as a disposable sandbox. Never expose the dashboard publicly without authentication. The tool refuses external binding without auth, and by default it also refuses to scan localhost and private ranges.
Verdict
Xalgorix isn’t a magic wand. LLM costs and model quality will shape your results, and you should still review findings like any professional. But the verify-before-reporting approach directly targets the biggest pain in vulnerability scanning: the triage grind. For bug bounty hunters, red teamers, and small security teams, it’s worth an afternoon of experimenting.
Repo: https://github.com/xalgorix/xalgorix

Cyber Security Researcher. Information security specialist, currently working as risk infrastructure specialist & investigator. He is a cyber-security researcher with over 25 years of experience. He has served with the Intelligence Agency as a Senior Intelligence Officer. He has also worked with Google and Citrix in development of cyber security solutions. He has aided the government and many federal agencies in thwarting many cyber crimes. He has been writing for us in his free time since last 5 years.









