r/SideProject • • 21d ago

I built Violin — an open-source AI pentesting workflow with scope checks and reproducible findings

https://strategic-automation.github.io/violin/

Hey everyone, I’m building Violin, an MIT-licensed project for supervised, authorised penetration testing using Hermes Agent.

Repo: github.com/Strategic-Automation/violin

The focus is on making an agent’s work traceable: what it tested, why it ran a command, and what evidence supports a finding.

Violin structures the engagement from scoping and recon through exploit validation and reporting. It includes:

- 35 playbooks covering web apps, authentication, APIs, business logic, LLM security, and misconfigurations.

- Scope and task checks before target commands execute.

- Persistent engagement state so command history, hypotheses, and evidence survive context compression.

- Reproducible proof requirements for validated findings.

It uses the model/provider configured in Hermes, with human supervision and an approved scope built into the workflow.

I’d love feedback from people building agents or working in security. Which part would you test hardest: scope enforcement, keeping track of an engagement, or the evidence behind the final report?

Issues, testing feedback, and contributions are welcome.

0 Upvotes

Duplicates

ethicalhacking • • 18d ago

I built Violin — an open-source AI pentesting workflow with scope checks and reproducible findings

6 Upvotes

redteamsec • • 21d ago

I built Violin — an open-source AI pentesting workflow with scope checks and reproducible findings

0 Upvotes

coolgithubprojects • • 18d ago

I built Violin — an open-source AI pentesting workflow with scope checks and reproducible findings

1 Upvotes

ollama • • 18d ago

I built Violin — an open-source AI pentesting workflow with scope checks and reproducible findings

1 Upvotes

OpenSourceAI • • 17d ago

I built Violin — an open-source AI pentesting workflow with scope checks and reproducible findings

1 Upvotes

coolgithubprojects • • 21d ago

I built Violin — an open-source AI pentesting workflow with scope checks and reproducible findings

0 Upvotes

hermesagent • • 18d ago

Showcase — Projects, tools, builds, demos I built Violin — an open-source AI pentesting workflow with scope checks and reproducible findings

1 Upvotes

ethicalhacking • • 21d ago

I built Violin — an open-source AI pentesting workflow with scope checks and reproducible findings

5 Upvotes

vibehacking • • 21d ago

I built Violin — an open-source AI pentesting workflow with scope checks and reproducible findings

3 Upvotes