Skill Detail

Run authorized AI-assisted pentest workflows with Guardian CLI

Use Guardian CLI to orchestrate authorized penetration tests with AI planning, tool selection, evidence capture, triage, and reporting across common security scanners.

Security & VerificationMulti-Framework
Security & Verification Multi-Framework Security Reviewed
⭐ 1.7k GitHub stars
COPY SKILL INSTRUCTIONS (OPTIONAL)
npx skills add agentskillexchange/skills --skill run-authorized-ai-assisted-pentest-workflows-with-guardian-cli Copy
Uses the third-party skills CLI, not an ASE-owned installer. Check your agent’s compatibility. This copies instructions; complete the upstream tool setup below separately.
At a glance
Tools required
Python 3.11+, Guardian CLI, configured AI provider, optional security tools such as nmap, httpx, subfinder, nuclei, nikto, sqlmap, wpscan, testssl, sslyze, gobuster, ffuf, arjun, xsstrike, gitleaks, cmseek, and dnsrecon
Install & setup
Clone https://github.com/zakirkun/guardian-cli.git, create and activate a Python virtual environment, run pip install -e ., then configure config/guardian.yaml or provider API key environment variables before authorized testing.
Author
Guardian Team
Publisher
Community
Last updated
Jul 20, 2026
Quick brief

Guardian CLI is an AI-assisted penetration testing automation tool for authorized security assessments. An operator installs the Python CLI, configures an approved AI provider, ensures external scanners are available as needed, and runs supervised reconnaissance, vulnerability testing, false-positive triage, evidence capture, and reporting against systems they are explicitly permitted to test.

How it works

What this skill actually does

Use this when a security operator needs a repeatable assessment workflow that coordinates many pentest tools and AI reasoning into a documented run. The boundary is authorized security testing with local CLI execution, provider configuration, and operator oversight; it is not a general cybersecurity product card, an exploit feed, or a license to run unsupervised scans against third-party targets.

Inputs and prerequisites: Python 3.11+, Guardian CLI, configured AI provider, optional security tools such as nmap, httpx, subfinder, nuclei, nikto, sqlmap, wpscan, testssl, sslyze, gobuster, ffuf, arjun, xsstrike, gitleaks, cmseek, and dnsrecon.

Setup notes: Clone https://github.com/zakirkun/guardian-cli.git, create and activate a Python virtual environment, run pip install -e ., then configure config/guardian.yaml or provider API key environment variables before authorized testing.

Source and verification boundary: use https://github.com/zakirkun/guardian-cli as the canonical reference before running the workflow; keep commands, API calls, CLI usage, and generated outputs reviewable against that upstream source.

Framework fit: publish this as a Multi-Framework workflow only when the operator can invoke the documented toolchain directly, rather than treating the upstream project as a generic product listing.