About this project

CyberStrikeAI is an open-source, AI-native cybersecurity platform built in Go. It connects planning, execution, human oversight, evidence, and replay in one auditable workspace. The system translates natural-language intent into governed security actions, using Eino-powered agents, MCP-native tools, RAG knowledge, visual workflows, and attack-chain modeling and analysis. Key capabilities include: - **Agents and orchestration**: Single-agent execution plus Deep, Plan-Execute, and Supervisor multi-agent modes; graph workflows combining agents, tools, conditions, approvals, and outputs; role-based testing with focused prompts and tool policies. - **Tools and knowledge**: 100+ curated YAML security tool recipes (nmap, sqlmap, nuclei, metasploit, etc.), MCP integration (HTTP, stdio, SSE, federation), resilient tool execution with circuit breakers and concurrency limits, Agent Skills, RAG knowledge base with query rewriting and reranking, and vision analysis for screenshots/captchas. - **Governance and audit**: Human-in-the-loop approval modes, tool allowlists, regex-based call blocking, platform RBAC with multiple users and custom roles, audit logs, SQLite persistence, and capped tool result storage. - **Security operations**: Conversation management, projects and attack chains with risk scoring and replay, asset management (normalization, dedup, import/export), vulnerability management, batch tasks, and chatbot integrations (WeChat, WeCom, DingTalk, Lark, Telegram, Slack, Discord, QQ). - **Authorized high-risk features**: WebShell management (virtual terminal, file ops, AI-assisted workflows) and built-in C2 (listeners, encrypted beacons, sessions, task queues). These are explicitly for systems you own or are authorized to test. Plugins include a Burp Suite extension and a Chrome/Edge browser extension for capturing network traffic and sending it to CyberStrikeAI for AI-assisted testing. Deployment is one-command via `run.sh` (requires Go 1.25+ and Python 3.10+), with HTTPS by default using a self-signed certificate. Configuration uses a YAML file for server settings and AI channels (OpenAI-compatible providers). An upgrade script (`upgrade.sh`) supports one-click updates while preserving local tools, roles, and skills. Documentation covers deployment, configuration, security hardening, API reference, MCP federation, runbooks, and developer guides. The project is licensed under Apache 2.0 and is part of the 404Starlink program. It is intended strictly for educational and authorized testing purposes.