Run authorized AI-assisted pentest workflows with Guardian CLI
Use Guardian CLI to orchestrate authorized penetration tests with AI planning, tool selection, evidence capture, triage, and reporting across common security scanners.
npx skills add agentskillexchange/skills --skill run-authorized-ai-assisted-pentest-workflows-with-guardian-cli
Guardian CLI is an AI-assisted penetration testing automation tool for authorized security assessments. An operator installs the Python CLI, configures an approved AI provider, ensures external scanners are available as needed, and runs supervised reconnaissance, vulnerability testing, false-positive triage, evidence capture, and reporting against systems they are explicitly permitted to test.
What this skill actually does
Use this when a security operator needs a repeatable assessment workflow that coordinates many pentest tools and AI reasoning into a documented run. The boundary is authorized security testing with local CLI execution, provider configuration, and operator oversight; it is not a general cybersecurity product card, an exploit feed, or a license to run unsupervised scans against third-party targets.
Inputs and prerequisites: Python 3.11+, Guardian CLI, configured AI provider, optional security tools such as nmap, httpx, subfinder, nuclei, nikto, sqlmap, wpscan, testssl, sslyze, gobuster, ffuf, arjun, xsstrike, gitleaks, cmseek, and dnsrecon.
Setup notes: Clone https://github.com/zakirkun/guardian-cli.git, create and activate a Python virtual environment, run pip install -e ., then configure config/guardian.yaml or provider API key environment variables before authorized testing.
Source and verification boundary: use https://github.com/zakirkun/guardian-cli as the canonical reference before running the workflow; keep commands, API calls, CLI usage, and generated outputs reviewable against that upstream source.
Framework fit: publish this as a Multi-Framework workflow only when the operator can invoke the documented toolchain directly, rather than treating the upstream project as a generic product listing.