xalgorix
Autonomous AI penetration testing with exploit-verified security findings
All Skills in This Repository (150)
Pure Emerald Level Indicatorssupabase
Detect misconfigurations and vulnerabilities in Supabase deployments.
firebase-firestore
Identify and remediate Firebase security misconfigurations in Firestore, Realtime Database, and Cloud Functions.
root-agent
Coordinate specialized agents for end-to-end security assessments with unified reporting.
azure-security
Test Azure security weaknesses across Blob storage, IMDS, Azure AD tokens, and Function App SSRF.
kubernetes-security
Audit Kubernetes deployments for misconfigurations and insecure access vectors.
quick
Automate time-boxed vulnerability assessments for web and API targets.
deep
Discover chained vulnerabilities across applications and infrastructure during penetration tests.
standard
Automate multi-phase security assessments across application attack surfaces.
express
Test Express.js apps for prototype pollution, body-parser quirks, and path traversal.
fastapi
Assess security weaknesses in FastAPI applications across DI, middleware, and auth.
nextjs
Identify authorization, caching, and runtime vulnerabilities in Next.js applications.
nestjs
Identify authentication, validation, and module boundary weaknesses in NestJS applications.
Frequently Asked Questions
FAQPage SchemaHow to install Xalgorix?โผ
Run `npx skills add xalgord/xalgorix --all -g -y` in your terminal to install the full skill suite globally.
What does Xalgorix do differently from a vulnerability scanner?โผ
It runs an autonomous AI agent through a full pentest methodology, then an independent verifier re-exploits each finding so you only get proven vulnerabilities, not a list of maybes.
Which security areas do the Xalgorix skills cover?โผ
The skills cover incident response, AI/LLM security testing, compliance (ISO 27001, PCI DSS, GDPR, NIST CSF), deception technology, firmware analysis, and OT/ICS industrial security.
Does Xalgorix send my data to the cloud?โผ
No. It is self-hosted and bring-your-own-LLM, so scan data, API keys, and target information never leave your infrastructure.
Can I use Xalgorix on any target?โผ
Only on systems you own or have explicit written permission to test, since it performs real exploitation to verify findings.
Related Repositories in Software Engineering
View All in Software Engineeringโopenclaw
Run a personal AI assistant across your devices and chat apps
superpowers
Gives coding agents a disciplined workflow from idea to merged code
react
AI agent skills for building, testing, and porting React core