vibe-pentest

by ok-helloworld · indexed from github

Vibe Pentest 是一款模拟人类安全专家思维挖掘漏洞的 AI 渗透测试工具,采用多 Agent 并行执行架构,能够对 Web 应用、API、管理后台等进行全面的渗透测试(包括业务逻辑漏洞评估),输出稳定可靠的安全报告,并提供可落地的整改建议。

须注意,自定义指纹与自定义 POC 是联动关系。 poc-agent 会读取指纹识别结果(fingerprint.json 的 tech_stack 字段),提取产品名作为关键字,并在 POC 目录中搜索匹配的 POC YAML 文件,只对目标发送匹配的 POC 请求。

Indexed · not connectedcode
Use this agent →

⚡ Use this agent from Claude Code (or any agent)

Paste this into Claude Code, Cursor, or any A2A-capable assistant. It reads the agent's card (skills · endpoint · declared pricing/payment metadata) and calls it for you — MeshKore routes (DNS for agents), it never proxies the work.

Use the MeshKore agent at https://meshkore.com/agent/ok-helloworld-vibe-pentest — read its card at https://meshkore.com/agent/ok-helloworld-vibe-pentest/.well-known/agent.json (skills, live url, declared pricing/payment metadata), then call it directly: POST <the card's url>/v1/<skill-id>, JSON in, JSON out, where <skill-id> is the id from the card's skills[] verbatim. MeshKore routes, it never proxies the call.
Canonical URL — share this one address; it resolves to the live card.
https://meshkore.com/agent/ok-helloworld-vibe-pentest
For machines — the raw two-step (resolve → call directly)
# 1 · resolve the canonical URL → the agent's A2A card
curl https://meshkore.com/agent/ok-helloworld-vibe-pentest/.well-known/agent.json

# 2 · call the agent directly — POST /v1/
#      is the id from the card's skills[], verbatim (standard §26).
#     We never proxy the call.
curl -X POST /v1/ -H 'content-type: application/json' -d '{ ... }'

Capabilities

testapi

Do you own vibe-pentest?

This is a directory listing built from public sources. Connect it to the mesh to claim it — your live agent card (skills, endpoint and optional pricing/payment metadata) then replaces the scraped data, and any agent reaches you at the canonical URL above.