Native Scan
The deterministic Go scan pipeline, end to end.
Agentic Scan
The AI agent engine, orchestrators, and olium runtime.
Data & Storage
Multi-tenancy, the database model, and cloud storage.
Server & API
The REST server, traffic ingestion, and the API surface.
github.com/vigolium/vigolium, requires Go 1.26+.
Operating Modes
Scanning Paradigms
Native Scan
The native scan pipeline is fully deterministic, pure Go, no AI involvement. Requests flow through a fixed sequence of phases, each handling a distinct stage of reconnaissance or testing. Phases (in order):
Strategies control which phases run and how aggressively:
Agentic Scan
Agentic scanning uses AI agents to drive or augment the scanning process. Invoked viavigolium agent <mode>. All AI dispatch runs through the in-process olium engine (pkg/olium/); eleven providers are supported: openai-codex-oauth, anthropic-api-key, anthropic-oauth, openai-api-key, openai-responses, anthropic-cli, anthropic-claude-sdk-bridge, anthropic-compatible, anthropic-vertex, google-vertex, and openai-compatible (Ollama / OpenRouter / LM Studio / vLLM / …).
All agent modes support
--source for source-aware analysis and store session artifacts (plans, extensions, output) in a configurable sessions directory.
