Vigolium
Official@vigolium
Vigolium - High-fidelity vulnerability scanner fusing agentic AI with native speed, modularity, and precision.
Agent Skills by Vigolium
Showing 34 vetted skills indexed across 2 GitHub repositories.
audit
Guides multi-phase repository security audits combining threat modeling, static analysis, and adversarial review.
command-injection-rce
Confirms OS command injection by proving remote code execution via OAST callbacks.
escalate-auth-bypass
Escalate suspected authentication bypasses into proven admin access, session takeover, or cross-tenant impact findings.
sqli-to-data-exfil
Escalates suspected SQL injection into verified data exfiltration with persisted findings.
audit
Identify and remediate security vulnerabilities in source code repositories.
vigolium-audit
Automate repository security audits with mode-based vulnerability analysis and JSON output.
security-threat-model
Generate repository-grounded AppSec threat models with trust boundaries and mitigations.
zeroize-audit
Detect missing or compiler-optimized-away zeroization of sensitive data in C/C++/Rust.
vuln-report
Draft a nine-section GitHub advisory report from one audit finding.
semgrep-rule-creator
Create Semgrep YAML rules with test-first development and validation.
semgrep
Run Semgrep static analysis with parallel execution and merged SARIF output.
differential-review
Analyze code diffs for security regressions and generate evidence-backed markdown reports.
insecure-defaults
Identify fail-open insecure defaults in production-reachable code and configuration.
sarif-parsing
Convert SARIF static analysis outputs into deduplicated findings for CI/CD gating.
last30days
Gather and synthesize community sentiment from Reddit, X, and the web over the last 30 days.
variant-analysis
Generalize an initial bug into broader Semgrep or CodeQL search patterns.
wooyun-legacy
Transform WooYun case methodology into repeatable web vulnerability testing workflows.
supply-chain-risk-auditor
Identify project dependencies with heightened exploitation or takeover risk.
codeql
Automates CodeQL security scanning with configurable precision modes and SARIF output.
fp-check
Verify suspected security bugs and issue evidence-backed TRUE POSITIVE or FALSE POSITIVE verdicts.
code-reviewer
Review local git diffs and remote Pull Requests with prioritized feedback.
spec-to-code-compliance
Extract Spec-IR and Code-IR to verify blockchain code against documentation.
agentic-actions-auditor
Audit GitHub Actions workflows for AI prompt-injection and execution risks.
sharp-edges
Identify error-prone security APIs and configuration designs during code review.
Frequently Asked Questions About Vigolium
FAQPage SchemaWhat specific security tasks does Vigolium enable?▼
Vigolium enables automated repository security audits, static analysis via Semgrep and CodeQL, threat modeling, and vulnerability triage. It supports deep inspection of authentication logic, supply chain risk assessment, and the validation of SSRF reachability or IDOR blast radius within complex enterprise environments.
Which engineering personas benefit most from these capabilities?▼
Application security engineers, penetration testers, and software developers benefit from these capabilities. The platform is designed for teams requiring high-fidelity vulnerability detection, regression testing during code reviews, and the ability to generate standardized advisory reports from scan findings.
What are the prerequisites for running Vigolium security scans?▼
Users require access to the target source code repository and a configured environment capable of executing static analysis patterns. Dependencies include standard repository access permissions and the ability to integrate SARIF-compliant outputs into existing security gating processes.