SkillAtlasSkill 详情

ioa

AI-driven single-binary pentest agent with a built-in multi-engine arsenal, ready to go

审核状态:已审核Quality 80Security 92

复制安装命令

用 Codex 或 Claude 安装复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它先审查 Skill 页面再帮你安装。

复制前请先查看来源、License 和安全提示。

项目 README

来源文件:README.md

抓取于 2026年9月4日

aiscan logo

aiscan

AI-driven single-binary pentest agent with a built-in multi-engine arsenal, ready to go

Release CI Downloads AGPL-3.0 Stars

中文文档


aiscan combines LLM agents with traditional security scanning engines. Three modes: Scan (deterministic pipeline, optional AI assist), Agent (natural-language autonomous assessment), IOA (multi-agent distributed collaboration).

Use only on explicitly authorized targets. Unauthorized use is illegal.

Quick Start

# No LLM needed — one-line scan
aiscan scan -i 192.168.1.0/24

# With LLM — one-line agent
aiscan agent --base-url "https://api.deepseek.com" --api-key "sk-..." --model deepseek-chat \
  -p "scan targets and check for high-risk vulnerabilities" -i 192.168.1.0/24

Install

Download Binary

From GitHub Releases:

EditionDescription
aiscanStandard — scan/agent/gogo/spray/zombie/neutron/proton/arsenal
aiscan-fullFull — adds Web, playwright, passive recon, and katana
OSArchStandardFull
Linuxamd64 / arm64aiscan_linux_<arch>.zipaiscan-full_linux_<arch>.zip
macOSIntel / Apple Siliconaiscan_darwin_<arch>.zipaiscan-full_darwin_<arch>.zip
Windowsamd64 / arm64aiscan_windows_<arch>.zipaiscan-full_windows_amd64.zip
# Linux
curl -LO https://github.com/chainreactors/aiscan/releases/latest/download/aiscan_linux_amd64.zip
unzip aiscan_linux_amd64.zip
chmod +x aiscan && sudo mv aiscan /usr/local/bin/

# macOS Apple Silicon
curl -LO https://github.com/chainreactors/aiscan/releases/latest/download/aiscan_darwin_arm64.zip
unzip aiscan_darwin_arm64.zip
chmod +x aiscan && sudo mv aiscan /usr/local/bin/

# Windows (PowerShell)
Invoke-WebRequest "https://github.com/chainreactors/aiscan/releases/latest/download/aiscan_windows_amd64.zip" -OutFile aiscan.zip
Expand-Archive .\aiscan.zip -DestinationPath .
.\aiscan.exe --version

Web Console (Full Edition)

The Web console is included in aiscan-full. It starts the browser UI and an embedded local agent by default. Open http://127.0.0.1:8080 and enter the access key printed at startup:

aiscan-full web

To listen on the network with a fixed access key:

aiscan-full web --addr 0.0.0.0:8080 --token change-me

Run the Web console as a hub without an embedded agent, then connect agents from this or other hosts:

# Hub
aiscan-full web --addr 0.0.0.0:8080 --token change-me --no-agent

# Remote node
aiscan agent --server-url http://change-me@server.example:8080 --node-name worker-01

The Web console stores sessions, scans, assets, findings, and configuration in aiscan-web.db by default. Use --db <path> to select another SQLite file.

Build from Source

git clone https://github.com/chainreactors/aiscan.git && cd aiscan

make                                                       # standard edition
make runner                                                # tag-free remote tool runner
make full                                                  # frontend + full edition

The standalone agent executable is no longer a maintained build or release target. Reference wiring remains in examples/agent and can be run manually with go run ./examples/agent --help. make full requires Node.js/npm and a working CGO toolchain; it builds the frontend first so the latest web/static assets are embedded into the binary. The native record tool is not included in the default full build; SDK and tool developers can build it explicitly with make record, as described in docs/record.md.

make web WEB_ADDR=127.0.0.1:18081 WEB_TOKEN=local-dev    # full build + Web UI

On Windows amd64, make and make full use the bundled static RE2 backend and statically link the MinGW runtime, producing a single executable without RE2, Abseil, libstdc++, libgcc, or winpthread DLLs.


Features

Design

  • Single-file distribution — bundled engines need no separate runtime install; OS graphics and system libraries still apply
  • Minimal agent core — composable ~160-line loop; tools, retries, evaluation are plugged in, not hardcoded
  • Plugin architecture — adding a new tool is one file; heavy dependencies (playwright, katana) are compile-time optional
  • Embedded skills — each tool carries its own usage docs and tactical guidance, loaded by the agent on demand
  • Scan + Agent unified — the same engines drive both the deterministic pipeline and the autonomous agent

Scan — Deterministic Pipeline

  • Multi-stage auto-chaining: port discovery → web probing → weak credentials → POC detection — no LLM required
  • Optional AI-driven result verification, public CVE correlation, and dynamic testing
  • Quick mode for fast exposure mapping, full mode for deep crawl and extended coverage

Agent — Autonomous Security Assessment

  • Natural language tasks — the agent plans, scans, analyzes, and reports autonomously
  • Goal evaluation — an independent evaluator judges task completion and drives automatic retry
  • Interactive REPL with direct command execution
  • Multiple provider profiles with explicit manual switching

IOA — Multi-Agent Collaboration

  • Shared message spaces for distributed agent coordination
  • Worker mode for persistent task listening
  • Built-in IOA server with token authentication
  • See: Design | CLI | Extension

Built-in Toolset

Scanners

  • gogo — port, service, and banner discovery
  • spray — web probing, fingerprinting, path fuzzing
  • zombie — credential testing
  • neutron — template-based POC execution
  • proton — sensitive information scanning (API keys, tokens, credentials, secrets)
  • cyberhub — fingerprint and POC association query

Browser & Recon (full edition)

  • playwright — headless Chromium sessions, screenshots, network capture
  • katana — web crawler with standard/headless/hybrid engines
  • passive — cyberspace search (FOFA, Hunter, Shodan)

Optional SDK tools

  • record — native desktop/window screenshots and H.264/MP4 recording (Windows and Linux X11)

Utilities

  • tmux — background task sessions with incremental output delivery
  • arsenal — security tool package manager (crtm), one-command install
  • proxy — multi-protocol proxy chain (trojan/vless/anytls/hy2/ss)
  • web_search / fetch — CVE search and URL fetching

Usage

Scan Mode

aiscan scan -i 192.168.1.0/24                                    # quick scan
aiscan scan -i 192.168.1.0/24 --mode full                        # full scan
aiscan scan -i http://target.example --verify=high --sniper       # AI-enhanced
aiscan scan -i http://target.example --mode full --deep --report  # full + deep + report

Agent Mode

# One-shot task
aiscan agent -p "scan and find web vulnerabilities" -i 192.168.1.0/24

# With goal evaluation
aiscan agent -p "full scan" -i http://target.example -e "find all open ports with service fingerprints"

# Interactive REPL
aiscan agent

IOA Mode

# Start IOA server
aiscan ioa serve --ioa-url http://0.0.0.0:8765

# Start IOA worker
aiscan agent --ioa-url http://127.0.0.1:8765 --space pentest-project \
  -p "scan assigned targets and report findings"

LLM Configuration

# Environment variable
export OPENAI_API_KEY="sk-..."

# CLI arguments
aiscan agent --provider openai --base-url https://api.deepseek.com/v1 --api-key sk-... --model deepseek-chat

Config file aiscan.yaml:

llm:
  provider: openai
  api_key: sk-...
  model: gpt-4o
  context_window: 128000   # Set explicitly for custom model IDs
  max_tokens: 16384        # Maximum output per response

context_window is a literal token count: use 128000, not 128K. Values below 8192 are accepted, but the Web UI warns that they may be too small. The request output limit is dynamically clamped to the remaining context: min(max_tokens, context_window - current_context - 4096). If no output space remains, AIScan returns a clear error instead of sending a one-token request. Automatic compaction starts as the context approaches the configured window.


Documentation

DocDescription
Scan ModePipeline, AI enhancements, output formats
Agent ModeToolset, Goal Evaluation, REPL
IOAMulti-agent architecture, Space/Node/Message model
Record ToolDesktop/window capture, platform support, native builds
ReferenceConfiguration, providers, flags, scanner usage, FAQ
v1.0.0 GuideStable API baseline, removed pre-v1 interfaces, release profiles
ChangelogVersion history

Contributing

  1. Fork this repository
  2. Create a feature branch (git checkout -b feature/xxx)
  3. Commit your changes (git commit -m 'feat: add xxx')
  4. Push to the branch (git push origin feature/xxx)
  5. Create a Pull Request

Disclaimer

  1. This tool is intended for authorized security testing and research purposes only. If you need to test its capabilities, please set up your own lab environment.
  2. Before using this tool for any scanning, you must ensure compliance with local laws and regulations and obtain sufficient authorization. Do not scan unauthorized targets.
  3. If you engage in any illegal activity while using this tool, you shall bear all consequences yourself. We assume no legal or joint liability.
  4. Before installing and using this tool, please carefully read and fully understand all terms. Limitation and disclaimer clauses may be highlighted for your attention.
  5. Unless you have fully read, understood, and accepted all terms of this agreement, please do not install or use this tool. Your use or any other express or implied acceptance constitutes your agreement to be bound by these terms.

License

This project is licensed under the GNU Affero General Public License v3.0 (AGPL-3.0).

Links

  • chainreactors — Organization
  • IOA — Internet of Agents
  • gogo — Port & service discovery
  • spray — Web probing & fingerprinting
  • zombie — Credential testing
  • neutron — Template-based POC engine
  • fingers — Fingerprint rule engine
  • sdk — Scanner SDK (gogo/spray/zombie core)
  • proxyclient — Multi-protocol proxy client
  • crtm — Security tool package registry
  • utils — Shared utilities & PTY manager
  • parsers — Protocol & data parsers

Star History

Agent / MCP / Skill 创作

低风险

  • 来源需自行核对维护者身份。
  • 包含脚本或命令调用,安装前请复核。
  • 未检测到明显外部权限要求。
  • 未检测到高风险命令。
  • 扫描发现:0 条。

Codex — Git Clone 安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 克隆仓库:git clone https://github.com/chainreactors/cyber-harness.git
  3. 将 "skills/ioa" 文件夹复制到 Codex 的 skills 目录中。
  4. 重启 Codex 让新的 skill 生效。

Codex — 手动复制安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 从源仓库下载 SKILL.md 及相关文件。
  3. 在 Codex 的 skills 目录中创建新文件夹。
  4. 将所有 skill 文件复制到新文件夹中。
  5. 重启 Codex 让新的 skill 生效。

Claude Code — Git Clone 安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 克隆仓库:git clone https://github.com/chainreactors/cyber-harness.git
  3. 将 "skills/ioa" 文件夹复制到 Claude Code 的 skills 目录中。
  4. 重启 Claude Code 让新的 skill 生效。

Claude Code — 手动复制安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 从源仓库下载 SKILL.md 及相关文件。
  3. 在 Claude Code 的 skills 目录中创建新文件夹。
  4. 将所有 skill 文件复制到新文件夹中。
  5. 重启 Claude Code 让新的 skill 生效。

Cursor — Git Clone 安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 克隆仓库:git clone https://github.com/chainreactors/cyber-harness.git
  3. 将 "skills/ioa" 文件夹复制到 Cursor 的 skills 目录中。
  4. 重启 Cursor 让新的 skill 生效。

Cursor — 手动复制安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 从源仓库下载 SKILL.md 及相关文件。
  3. 在 Cursor 的 skills 目录中创建新文件夹。
  4. 将所有 skill 文件复制到新文件夹中。
  5. 重启 Cursor 让新的 skill 生效。

GitHub Copilot — Git Clone 安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 克隆仓库:git clone https://github.com/chainreactors/cyber-harness.git
  3. 将 "skills/ioa" 文件夹复制到 GitHub Copilot 的 skills 目录中。
  4. 重启 GitHub Copilot 让新的 skill 生效。

GitHub Copilot — 手动复制安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 从源仓库下载 SKILL.md 及相关文件。
  3. 在 GitHub Copilot 的 skills 目录中创建新文件夹。
  4. 将所有 skill 文件复制到新文件夹中。
  5. 重启 GitHub Copilot 让新的 skill 生效。

Windsurf — Git Clone 安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 克隆仓库:git clone https://github.com/chainreactors/cyber-harness.git
  3. 将 "skills/ioa" 文件夹复制到 Windsurf 的 skills 目录中。
  4. 重启 Windsurf 让新的 skill 生效。

Windsurf — 手动复制安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 从源仓库下载 SKILL.md 及相关文件。
  3. 在 Windsurf 的 skills 目录中创建新文件夹。
  4. 将所有 skill 文件复制到新文件夹中。
  5. 重启 Windsurf 让新的 skill 生效。
查看 SKILL.md 原文
name: ioa
description: Use this skill when coordinating with other agents through IOA shared message spaces — the ioa pseudo-command (space/send/read subcommands), message envelope, and protocol skills (checkpoint, handoff, swarm, team).
internal: true

IOA — Inter-Operator Async Collaboration

IOA provides shared message spaces for agent coordination through a single pseudo-command: ioa with space, send, and read subcommands.

Each aiscan instance binds to one space. After joining, all send/read operations automatically target that space — no space ID needed.

The wire protocol (message envelope, typed content formats) is defined by the chainreactors/ioa module. Its protocol skills are loaded as internal skills — read them for exact message formats:

  • ioa://skills/checkpoint/SKILL.md — human-in-the-loop review (content_type: "checkpoint")
  • ioa://skills/handoff/SKILL.md — fire-and-forget delegation (content_type: "handoff")
  • ioa://skills/swarm/SKILL.md — commander/node self-organization (content_type: "swarm")
  • ioa://skills/team/SKILL.md — named-group broadcast (content_type: "team")

1. Tool API

The command surface is the ioa module's CLI (github.com/chainreactors/ioa/client go-flags commands), with the current space auto-injected as --space on send/read.

ioa space

Join or create a space, and inspect spaces:

ioa space "case-target" "Your role" [--tag recon]   Join or create a space (sets it as current)
ioa space list                                      List available spaces
ioa space nodes                                     Show nodes in current space
ioa space topics                                    Show root messages (conversation starters)

After joining, the response includes member nodes (ID, name, description) and existing root messages.

ioa send

Send a message to the current space:

ioa send --content '{"content": "recon complete, 3 hosts found"}'                     Broadcast to all
ioa send --ref-nodes <node_id> --content '{"content": "scan 10.0.0.1 for web vulns"}' Send to a specific node
ioa send --ref-messages <message_id> --content '{"content": "confirmed, SQLi"}'       Reply to a message
ioa send checkpoint --kind verify --title "SQLi" --content "..." --target <url> --status confirmed

CRITICAL: The --content value must be a JSON object with a "content" key containing the message text. The swarm protocol parses "content" to route messages — any other key name (e.g. "message", "text") will be silently dropped. Additional fields ("kind", "targets", etc.) are optional metadata.

Typed protocol sends (ioa send <protocol> [flags]) are registered by the ioa module — checkpoint supports --kind, --title, --content, --target, --status. Raw sends accept --content-type, --meta, and --content-schema.

ioa read

Read messages from the current space:

ioa read                                Messages addressed to this node
ioa read --all --limit 50               All messages in the space
ioa read --message <message_id>         Context (ancestors + descendants) of a message
ioa read --message <id> --direction upstream|downstream   Thread traversal
ioa read --after <message_id>           Messages after a cursor (pagination)
ioa read --listen                       Stream new messages (SSE)

Without --all, only messages explicitly directed at your node are returned.

Background Monitoring

Loop workers do not receive peer messages automatically unless heartbeat is enabled. For situational awareness, poll intentionally with ioa read --all --limit <N> before and after long work, or use ioa read --listen for a live stream. If the worker was started with --heartbeat, the runtime periodically loads recent IOA messages into the heartbeat prompt.

2. Message Format

The envelope carries content_type (raw text when unset, or a protocol type like checkpoint/handoff/swarm/team) plus a JSON content body. Every content body must have a "content" key with the text body — except typed protocol bodies, which follow their own schema (see the protocol skills above; each also has ioa://skills/<name>/schema.json).

Refs

  • reply --to <msg_id>: reference a prior message (reply, follow-up)
  • to --node <node_id>: address a specific node. Omit to broadcast to all space members.

3. Coordination Rules

  1. Read before write — always ioa read all before starting work. A peer may have already claimed your target.
  2. Claim before work — announce your scope before any significant operation.
  3. Share as you go — emit loots immediately, not in a final batch. Peers need your data to make decisions now.
  4. No noise — the space is shared memory, not chat. No "ok", "thanks", or thinking-out-loud.
  5. Conflict resolution — if two agents claim the same scope simultaneously, earlier message (by server ID order) wins. The later agent adapts.

When coordinating workers from a heartbeat/coordinator role:

  • Workers are single-task — they cannot respond to messages while busy. Do NOT send status checks; wait for the completion message.
  • Dispatch once, wait for completion — send one task per worker, wait for their result before sending the next.
  • Do NOT scan targets yourself — the coordinator only uses ioa send/ioa read; react to results and dispatch follow-ups.

4. Multi-Agent Swarm

For the full commander/node self-organization protocol (objective broadcast, squad formation, convergence), read ioa://skills/swarm/SKILL.md.

发现问题?提交给管理员复核

评分:

评论 (0)

暂无评论,成为第一个评论者吧!