Scanners-Box 每日 AI 工具推荐 Scanners-Box Daily AI Tool Picks

AI 自主网络安全智能体 AI Autonomous Cybersecurity Agents

共 5 个工具 · 专栏每天 14:00(北京)更新一期 5 tools · one new issue daily at 14:00 GMT+8

LuaN1ao LuaN1ao LuaN1ao GitHub stars 第 009 期 · 2026.9.29 No. 9 · Sep 29, 2026

把每条渗透结论钉回证据链:P-E-O 三角色 + 三图分离 + Evidence→Hypothesis→Vulnerability→Exploit 因果链 Pinning every pentest finding to evidence: Planner-Executor-Observer roles + three graph separations + an enforced Evidence → Hypothesis → Vulnerability → Exploit chain

TypeScript + Pi SDK 重写的 v2 自主渗透 Agent:证据引用是 schema 层面的硬约束(没有 evidence 引用就写不进 Vulnerability / Exploit 节点)。Docker 出网收口在内核态,scope 校验确定性拒绝臆造网段。短板:AGPL-3.0、Node.js 25+、v2 benchmark 还没发、高危动作没有审批闸门。 v2 autonomous pentest agent rewritten in TypeScript on the Pi SDK — evidence references are an enforced schema constraint (no Vulnerability / Exploit node without evidence). Docker-based egress gating at the kernel layer, and deterministic scope checks reject any fabricated CIDR. Caveats: AGPL-3.0, Node.js 25+ required, no v2 benchmark published yet, and no human approval gate on high-risk actions.
https://github.com/SanMuzZzZz/LuaN1aoAgent
PentAGI PentAGI PentAGI GitHub stars 第 004 期 · 2026.9.21 No. 4 · Sep 21, 2026

全自主渗透平台:Docker 沙箱里跑 20+ 工具,13 个 agent 角色分工,四道闸门防止跑飞 A fully autonomous pentesting platform: 20+ tools in a Docker sandbox, 13 specialized agent roles, and four supervision gates to stop runaway runs

Go 写的全自主渗透平台,五层结构(核心 / 知识图谱 / 监控 / 沙箱工具 / 分析),13 个 agent 角色由四道闸门(调用上限 / Reflector / 执行监控 / 任务规划)监管。官方维护 vLLM + Qwen3.5-27B-FP8 气隙部署指南。 Autonomous pentesting platform in Go with five layers (core / knowledge graph / monitoring / sandbox tools / analytics), 13 agent roles supervised by four gates (call caps / Reflector / execution monitoring / task planning). Ships an official vLLM + Qwen3.5-27B-FP8 air-gapped deployment guide.
https://github.com/vxcontrol/pentagi
Cairn Cairn Cairn GitHub stars 第 003 期 · 2026.9.20 No. 3 · Sep 20, 2026

通用状态空间搜索引擎:不定义角色与工作流,给起点和终点,让 Agent 在黑板上自己搜路 A general state-space search engine: no roles, no workflows — hand it an origin and a goal and let agents find the path on a shared blackboard

黑板架构 + 事实/意图图,只有 Fact / Intent / Hint 三个原语;Worker 跑 OODA 循环,靠 Stigmergy 间接协作,角色在运行时涌现而非写死。腾讯云黑客松 AI 渗透挑战赛 610 队里唯一 AK(54/54)。 State-space search engine built on a blackboard + fact-intent graph with three primitives (Fact, Intent, Hint). Workers run OODA loops and coordinate via stigmergy; roles emerge at runtime. The only team to AK (54/54) at the Tencent Cloud AI Pentesting Hackathon out of 610.
https://github.com/oritera/Cairn
Shannon Shannon Shannon GitHub stars 第 002 期 · 2026.9.19 No. 2 · Sep 19, 2026

AI 渗透测试 Agent:读源码找攻击面,再真打一遍验证,只有跑通 PoC 的漏洞才进报告 An AI pentesting agent: read the source, map attack paths, then prove every finding with a real exploit — no PoC, no report.

六段流水线:侦察 + 代码分析双流候选 → 归并去重 → 利用 Agent 真打 → 打不穿就丢 → PDF/Markdown/SARIF 报告。原生接 GitHub Actions,只有 exploited 的发现才卡流水线。AGPL-3.0,会改目标状态,只打 staging。 Six-stage pipeline: recon and code analysis produce candidates, dedup, exploitation agents attack the live app, undemonstrated findings get discarded, and survivors become PDF / Markdown / SARIF. Native GitHub Actions; only exploited findings gate the pipeline. AGPL-3.0, staging only.
https://github.com/KeygraphHQ/shannon
CyberStrikeAI CyberStrikeAI CyberStrikeAI GitHub stars 第 001 期 · 2026.9.18 No. 1 · Sep 18, 2026

AI 原生的安全执行中枢:把自然语言意图转成受治理的行动,并把证据沉淀成可复用的运营记忆 An AI-native security execution hub: turns natural-language intent into governed action and bakes evidence into reusable operational memory.

Go + Eino 编排,100+ YAML 工具配方 + MCP,内置审批、调用前正则拦截、RBAC 与审计日志。它的差异不在能调多少工具,而在于敢不敢让 Agent 真的动手。 Go + Eino orchestration with 100+ YAML tool recipes plus MCP, plus first-class approval, pre-call regex intercept, RBAC and audit logs. Its edge isn't how many tools it can call — it's whether it dares to let the agent really act.
https://github.com/AIPentest/CyberStrikeAI

← 回专栏看全部期号 ← Back to all issues