frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Wiz – AI-Powered Pentest Assistant (Open Source)

https://github.com/code3hr/opencode
1•youncj•1h ago

Comments

youncj•1h ago
I built Wiz because I was tired of context-switching between remembering tool syntax and actually doing security work.

## Background

I've been doing security assessments for a while, and the workflow is always: 1. Remember the right tool for the job 2. Look up the flags (again) 3. Run the command 4. Parse the output manually 5. Copy findings to a spreadsheet 6. Repeat 100 times 7. Manually write the report

## What Wiz Does

Wiz lets you describe what you want in natural language:

"check if this Apache server is vulnerable to path traversal"

And it: 1. Selects the right tools (nuclei with CVE-2021-41773 templates) 2. Runs them with correct parameters 3. Parses the output into structured findings 4. Classifies by severity (Critical/High/Medium/Low) 5. Stores with evidence for the report 6. Generates professional reports when you're done

## Technical Details

Built on OpenCode (https://github.com/sst/opencode), which provides: - Superior agent architecture vs generic LLM CLIs - Extensible tool framework with typed I/O - Multi-LLM support (Claude, GPT-4, Gemini, local models)

Wiz adds a security layer: - 30+ tool integrations with output parsers - Findings database with OWASP/CVE categorization - Governance engine (scope enforcement, audit trails) - Report generation (HTML, PDF, Markdown)

## What It's NOT

- Not a replacement for knowing what you're doing - Not for unauthorized testing - Not a magic "hack anything" button

It's an assistant that handles the tedious parts so you can focus on analysis.

## Stack

- TypeScript/Bun - Runs on Kali, Parrot, any Linux, macOS, Windows - Requires API key (Claude recommended, GPT-4 works too)

## Links

- GitHub: https://github.com/code3hr/opencode - Downloads: https://github.com/code3hr/opencode/releases/latest

Open source, MIT licensed. Feedback welcome! ```

---

## Quick Demo Script (for Video/GIF)

``` # Terminal recording script

$ ./cyxwiz

> scan 10.0.0.5 for vulnerabilities

[Wiz runs nmap, detects Apache 2.4.41] [Wiz runs nikto, finds misconfigurations] [Wiz runs nuclei, matches CVE-2021-41773]

Found 1 critical, 2 high, 3 medium findings.

> show critical findings

CRITICAL: CVE-2021-41773 - Apache Path Traversal - Target: 10.0.0.5:80 - Impact: Remote Code Execution - Evidence: [response data] - Remediation: Upgrade to Apache 2.4.51+

> generate report

Report generated: assessment-2024-01-15.html ```

toomuchtodo•1h ago
I would find a new name.

https://www.wiz.io

Flux2kle.in Fast and Free Image Generator

https://flux2kle.in/
1•bingbing123•1m ago•1 comments

Learning to Discover at Test Time

https://test-time-training.github.io/discover/
1•emersonmacro•4m ago•0 comments

Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

https://techcrunch.com/2026/01/23/microsoft-gave-fbi-a-set-of-bitlocker-encryption-keys-to-unlock...
4•bookofjoe•4m ago•0 comments

The Gödel Problem: A Mathematical Argument Against AI Thought [video]

https://www.youtube.com/watch?v=Vtdcdcwm7iw&list=PLoYRQl2t0w0EjRIb9Jr1yI90sSqoirgGB&index=8
1•pedro_movai•5m ago•0 comments

Building a product in 20 hours and growing it to a 5-figure ARR

https://www.indiehackers.com/post/tech/building-a-product-in-20-hours-and-growing-it-to-a-5-figur...
2•uprooted•6m ago•0 comments

Fighting AI Slop

https://actualbudget.org/blog/fighting-ai-slop/
1•iM8t•6m ago•0 comments

Submit a pitch: what needs to be built before advanced AI?

https://ifp.org/rfp-launch/
2•jonahwei•7m ago•0 comments

Proof of Corn

https://proofofcorn.com/
1•rocauc•7m ago•0 comments

Route leak incident on January 22, 2026

https://blog.cloudflare.com/route-leak-incident-january-22-2026/
3•nomaxx117•9m ago•0 comments

MTV Rewind

https://wantmymtv.xyz/
1•CharlesW•9m ago•0 comments

Show HN: QuizYou – Paste text, generate quiz, test yourself

https://www.getquizyou.com/
1•yanis_t•9m ago•0 comments

Show HN: Mpak: a package manager for MCP server bundles

https://www.mpak.dev/
1•barefootsanders•9m ago•1 comments

'I'm stupid': SF tech founder jailed in Davos for bomb-lookalike device

https://sfstandard.com/2026/01/22/tech-dude-davos-bomb-lookalike-device/
4•cdrnsf•9m ago•0 comments

Startup will send 1k people's ashes to space – affordably – in 2027

https://techcrunch.com/2026/01/23/this-startup-will-send-1000-peoples-ashes-to-space-affordably-i...
1•bookofjoe•10m ago•0 comments

Embrace Limitations

https://www.bathysphere.org/p/embrace-limitations/
1•thunderbong•10m ago•0 comments

Show HN: Easy to use, open source voice clone app

https://github.com/gangtao/VoiceCraft
1•gangtao•13m ago•0 comments

All You Need Is an Acre: On Self-Sufficiency in a Digital Economy

https://opuslabs.substack.com/p/all-you-need-is-an-acre
1•opuslabs•15m ago•1 comments

There's only one Woz, but we can all learn from him

https://www.fastcompany.com/91477114/steve-wozniak-woz-apple-the-tech-interactive-humanitarian-award
1•coloneltcb•15m ago•0 comments

Show HN: Claude Tutor – an open source engineering tutor

https://twitter.com/michaelraspuzzi/status/2014756546195148988
2•mraspuzzi•15m ago•0 comments

Principles for Building an Effective MCP Server

https://www.featbit.co/feature-flag-mcp/principles-for-building-an-fffective-mcp-server
1•mikasisiki•15m ago•0 comments

Trump calls for $1.5T military budget in 2027, up from $901B in 2026

https://www.reuters.com/world/us/trump-says-us-military-budget-2027-should-be-15-trillion-2026-01...
4•doener•16m ago•0 comments

Asteroids the size of 22 penguins to pass Earth this weekend

https://www.jpost.com/science/article-729035
4•ohjeez•21m ago•4 comments

The Next Thing Will Not Be Big

https://blog.glyph.im/2026/01/the-next-thing-will-not-be-big.html
1•dotcoma•22m ago•0 comments

Doubting U.S. resolve, Europe looks to bolster its own nuclear arsenal

https://www.nbcnews.com/politics/white-house/doubting-us-resolve-europe-looks-bolster-nuclear-ars...
3•saubeidl•23m ago•0 comments

Introducing: Postgres Best Practices

https://supabase.com/blog/postgres-best-practices-for-ai-agents
1•arunkumar201•24m ago•0 comments

Supreme Court appears to carve out a murky exception for the Federal Reserve

https://apnews.com/article/federal-reserve-supreme-court-lisa-cook-e5ceaf7041b7c835c825afe1a5cacf07
2•kaycebasques•24m ago•0 comments

Show HN: Will this discover hidden YouTube video gems (or gems in the making)?

https://gizzapp.com/buyunderratedvideofinder/
1•johnboygiz•25m ago•0 comments

Show HN: Directory of 1000 open source alternatives to popular software

http://ww17.your-domain.com/
1•Zenith-Software•26m ago•0 comments

Deregulation is not the answer to the affordable housing crisis

https://48hills.org/2026/01/new-study-shows-that-deregulation-is-not-the-answer-to-the-affordable...
1•masterofsome•27m ago•0 comments

Digital Sovereignty: Why Tech Execs Must Act Now

https://www.forrester.com/blogs/digital-sovereignty-why-tech-execs-must-act-now/
1•doener•27m ago•0 comments