Original Summary

Hey everyone, I’m building Violin, an MIT-licensed project for supervised, authorised penetration testing using Hermes Agent. Repo: github.com/Strategic-Automation/violin The focus is on making an agent’s work traceable: what it tested, why it ran a command, and what evidence supports a finding. Violin structures the engagement from scoping and recon through exploit validation and reporting. It includes: - 35 playbooks covering web apps, authentication, APIs, business logic, LLM security, and misconfigurations. - Scope and task checks before target commands execute. - Persistent engagement state so command history, hypotheses, and evidence survive context compression. - Reproducible proof requirements for validated findings. It uses the model/provider configured in Hermes, with human supervision and an approved scope built into the workflow. I’d love feedback from people building agents or working in security. Which part would you test hardest: scope enforcement, keeping track of an engagement, or the evidence behind the final report? Issues, testing feedback, and contributions are welcome.   submitted by   /u/WarmAd6505 [link]   [comments]

中文概览

中文标题: 我构建了 Violin——一个带范围检查和可复现发现的开源 AI 渗透测试工作流

作者介绍 MIT 许可的 Violin 项目,使用 Hermes Agent 进行受监督、获授权的渗透测试。它让代理工作可追溯:测试了什么、为何运行命令、有何证据支持发现。流程覆盖范围界定、侦察、漏洞验证和报告,包含 35 个操作手册、执行前范围与任务检查、持久化项目状态和可复现证明要求。作者征求反馈,并询问最想测试哪部分:范围强制、项目跟踪或报告证据。


  • 情报分类:开源项目与落地
  • 分类依据:开源AI渗透测试项目,含仓库、许可证与贡献邀请。
  • 信息来源:Reddit · SideProject
  • 发布时间:2026/9/17 05:16:16