Vigil – An agent harness for long-running pentests and code audits Vigil, an open-source agent harness released under the Apache License 2.0, drives authorized security engagements end to end from one CLI, dispatching specialist agents that run real tooling inside a shared Kali container and record every target, service, request variant, probe, finding, and attack chain into a durable orchestrator database. The tool's author reports that authorized web red-team engagements worked with Claude Opus 5 under Anthropic's Cyber Verification Program and GPT-5.6 Sol with OpenAI's Trusted Access for Cyber, while noting Vigil's workflows have not been validated with Claude Opus 5.5 or GPT-6.1 Sol. Vigil offers five modes against the same backend — web red-team, white-box code analysis, combined web and code, Android application analysis, and blue incident response — and the author plans to broaden support for GLM 5.3 and refine integrations with OpenCode as frontier model access becomes more restrictive. AI-driven offensive and incident-response engagements — operator prompts, a full Kali runtime, and durable orchestrator state in one CLI. Vigil drives a security engagement end to end from one CLI. An LLM operator reads a phased workflow prompt, dispatches specialist agents, runs real tooling inside a shared Kali container, and records every target, service, request variant, probe, finding, and attack chain into a durable orchestrator database. Five modes run against the same backend: web red-team, white-box code analysis, combined web and code, Android application analysis, and blue incident response. Authorized use only. Vigil can autonomously drive offensive tooling against live systems. Use it only where you have explicit authorization and a reviewed scope. It is provided without warranty under the Apache License 2.0 https://github.com/VigilOSS/Vigil/blob/main/LICENSE ; you are responsible for commands, credentials, infrastructure, and target effects. See SECURITY.md https://github.com/VigilOSS/Vigil/blob/main/SECURITY.md for private vulnerability reporting and the operator-data boundary. I have built and refined Vigil primarily around Claude Code and Codex . In my testing, authorized web red-team engagements have worked with Claude Opus 5 under Anthropic's Cyber Verification Program CVP and GPT-5.6 Sol with OpenAI's Trusted Access for Cyber. Those results reflect the models, clients, and access available in my own setup; blocking can vary with your account, access tier, model version, and engagement. To select Opus 5 in Claude Code, run /model claude-opus-5 1m in the session, if that model is available to your account. /model opens the model picker. The 1m suffix requests the extended context window; Opus 5 already has native 1M context. See Claude Code's model configuration https://code.claude.com/docs/en/model-config . I have not yet validated Vigil's engagement workflows with Claude Opus 5.5 or GPT-6.1 Sol. As of October 2026, Anthropic calls its defensive CVP tier Defense Access ; Red Team Access is a separate tier currently limited to qualifying organizations. OpenAI calls its defensive offering Daybreak Blue , with Daybreak Red requiring separate approval and provisioning. Defensive access alone should not be treated as assurance that a web red-team engagement will run through without refusals. Check the provider's current terms and the access enabled for your specific model and client before starting. See Anthropic's CVP tiers https://www.anthropic.com/news/cyber-verification-program and OpenAI's model and access guidance https://learn.chatgpt.com/docs/cyber-safety . I want Vigil to remain practical for independent researchers doing authorized work. As frontier model access becomes more restrictive, I plan to broaden support for GLM 5.3 and other models with more predictable access to these workflows. That will take substantial work: reducing orchestration overhead, adapting prompts to the models, and refining integrations with OpenCode and other harnesses. This is planned work; Claude Code and Codex remain the integrations I have refined most extensively today. - Findings are independently verified. A finding is confirmed, downgraded, or marked a false positive only by a dispatch other than its author's, citing a proof receipt of captured evidence. - Target-facing commands are audited. vigil assess kali records each command's technique, intent, and probe kind, so the engagement keeps a trail of what was sent and why. - Real attack tooling — a long-lived Kali container with ProjectDiscovery recon, fuzzers, an audited Playwright browser, MITM capture with multiple identities for cross-account testing, and out-of-band callbacks correlated back to the probe that caused them. - White-box code analysis against a sealed, content-addressed source snapshot with a tree-sitter structural index and a coverage ledger. - Durable state — targets, services, request variants, probes, findings, chains, and credentials in SQLite, with rotated backups and a web UI. - Six client integrations, one methodology — Claude Code, Codex, Kimi, goose, opencode, and Pi; Pi is currently limited to remediation engagements. 1. Install the CLI uv tool install --from git+https://github.com/VigilOSS/Vigil.git@v1.0.0 vigil ...or over SSH, if you authenticate to GitHub with a key uv tool install --from git+ssh://git@github.com/VigilOSS/Vigil.git@v1.0.0 vigil 2. Check the host: prerequisites, missing recon tools, and the ordered setup checklist vigil quickstart 3. Install a working root and bring the local stack up Kali runtime + orchestrator First run builds the Kali image — several GB, and it needs Docker running. vigil install ~/vigil && vigil up 4. Create an engagement against an authorized target vigil engagement create https://target.example --hosts target.example 5. Start the operator on it vigil engagement start