The beginner friendly security tool that uses sub-agents to automate network vulnerability scans via Nmap and generate structured, actionable reports.
NOTE: Unauthorized vulnerability scanning is illegal. To ensure safe and lawful use, this project features strict target guardrails. The agents are restricted to running test scans only against authorized Nmap test servers and my local network.
For cybersecurity professionals, manually executing vulnerability scans and reviewing the raw data is a time consuming task and a headache.
So let's fix this! This project implements a lightweight multi-agent framework. The system splits responsibilities across a dedicated hierarchy to maximize workflow efficiency:
- Coordinator Agent: Leads the operation, delegates tasks, and ensures smooth data flow.
- Two Sub-Agents: Handle specialized execution and analysis tasks independently.
Workflow Diagram:
Meet the Agents:
- Coordinator: The master mind behind the operation who routes the users request and provides the final report.
- Scanner Agent: The worker who scans the target and provides the results.
- Analyst Agent: Our personal analyst of the group who receives the results from the scan and provides a structured response.
Tech Stack:
- Agents & Tools: LangChain
- Orchestration: LangGraph
- Model: OpenAI gpt-4o
- Scanner: Nmap + NSE
- Environment: Codespaces/VSCode, Devcontainer
Guardrails:
- Least Privilege: The analyst is not given any tools and has no hand in the scanning process.
- Allowlist Gate: All targets must go through a strict allowlist. Any target not listed will immediately be denied.
- Prompt Injection: The system scans external text that third parties control, therefore the text is filtered.
Results:
