Repository navigation
Home
Lophiarch is an AI-assisted reconnaissance and security-automation tool that uses Telegram as its ChatOps interface, a provider-agnostic agent core for AI tool selection, the Model Context Protocol (MCP) for tool exposure, and disposable Docker containers for scanner execution.
This Wiki contains operational and development documentation for the current 2.2 architecture.
Lophiarch is intended only for systems you own or are explicitly authorized to assess. Do not use it for unauthorized access, destructive testing, or disruption.
- Getting Started
- Architecture Overview
- Configuration
- Deployment
- Scanner and Tool Integrations
- Security and Responsible Use
- Troubleshooting
- Development and Contributing
- Frequently Asked Questions
- Telegram-based natural-language interaction.
- Provider-agnostic MCP tool selection with local or hosted AI models.
- Subdomain enumeration with Subfinder and an AlienVault OTX fallback.
- dnsx filtering for active subdomains.
- Nmap service and port discovery.
- Nuclei template-based vulnerability scanning.
- Ffuf content discovery with bundled SecLists wordlists.
- In-memory scan aggregation and PDF generation with ReportLab.
- Docker and Helm-based deployment options.
- Automated main-image publishing to GitHub Container Registry.
Lophiarch is not coupled to a single AI vendor. The same agent core and MCP tool surface can be used with:
- Ollama (the default) for locally hosted models such as Qwen.
- vLLM, LM Studio, or llama.cpp for self-hosted inference.
- Any service that exposes an OpenAI-compatible chat-completions endpoint.
- Gemini as an optional compatibility provider, not a required dependency.
Select the backend with AI_PROVIDER and configure AI_MODEL, AI_BASE_URL,
and AI_API_KEY only as required by that backend. See Configuration.
Lophiarch is under active development. The current stable release is v2.2.2. Interfaces, configuration, and deployment behavior may still change in later releases.
- Source repository
- Issue tracker
- Security policy
- Contributing guidelines
- Code of Conduct
- Sponsor Lophiarch
Lophiarch is available under your choice of the MIT License or Apache License
2.0: MIT OR Apache-2.0.