Open-source AI pentesting with independently verified findings

- supporters
Xalgorix is an open-source AI penetration-testing agent built to do more than produce a list of possible vulnerabilities. It works through a structured 22-phase methodology covering reconnaissance, authentication, injection, SSRF, access control, APIs, file uploads, deserialization, business logic, cloud infrastructure, exploit verification, and reporting.
The primary agent uses browser automation and terminal tools against targets you are authorized to test. Candidate findings are passed to a separate verifier that attempts to reproduce the exploit. Confirmed results retain supporting evidence and severity context, helping teams reduce false positives and prioritize real risks.
You can self-host Xalgorix from GitHub or use its managed SaaS dashboard for scans, scheduling, centralized findings, reports, and team workflows.
Open source: https://github.com/xalgorix/xalgorix Website: https://www.xalgorix.com/
Featured Today

tiun
Payments backend for indie hackers
All-in-one: Auth, payments & DB
Single command: MCP, Skills
Built for developers.
Merchant of Record. Better fees.
The Weekly Top 10 in your inbox
Best launches + founder deals.