https://github.com/projectdiscovery/openrisk
openrisk is a tool that generates a risk score based on the results of a Nuclei scan.
https://github.com/projectdiscovery/openrisk
ai gpt-3 nuclei openai risk-score
Last synced: 6 months ago
JSON representation
openrisk is a tool that generates a risk score based on the results of a Nuclei scan.
- Host: GitHub
- URL: https://github.com/projectdiscovery/openrisk
- Owner: projectdiscovery
- License: mit
- Created: 2022-12-15T09:12:45.000Z (almost 3 years ago)
- Default Branch: main
- Last Pushed: 2025-02-04T12:00:57.000Z (8 months ago)
- Last Synced: 2025-04-11T16:15:43.531Z (6 months ago)
- Topics: ai, gpt-3, nuclei, openai, risk-score
- Language: Go
- Homepage:
- Size: 63.5 KB
- Stars: 168
- Watchers: 13
- Forks: 17
- Open Issues: 6
-
Metadata Files:
- Readme: README.md
- License: LICENSE.md
Awesome Lists containing this project
README
openrisk
openrisk is an experimental tool which reads [nuclei](http://github.com/projectdiscovery/nuclei) output (text, markdown, and JSON) and generates a risk score for the host using OpenAI's GPT-3 model. It is intended, for now, to work against a single target at a time.
> **NOTE**: This is an experimental program released by the ProjectDiscovery Research Team. As such, it may not meet the same code quality standards as our other projects, and may not be as well-tested. We welcome suggestions, bug fixes, and ideas on integrating these experiments into our other tools!
### Install openrisk
openrisk requires **go1.20** to install successfully. Run the following command to install the latest version -```sh
go install -v github.com/projectdiscovery/openrisk@latest
```### Usage
```sh
openrisk -h
``````console
_ __
____ ____ ___ ____ _____(_)____/ /__
/ __ \/ __ \/ _ \/ __ \/ ___/ / ___/ //_/
/ /_/ / /_/ / __/ / / / / / (__ ) ,<
\____/ .___/\___/_/ /_/_/ /_/____/_/|_| Powered by OpenAI (GPT-3)
/_/ v0.0.1 (experimental)
projectdiscovery.ioopenrisk is an experimental tool generates a risk score from nuclei output for the host using OpenAI's GPT-3 model.
Usage:
openrisk [flags]Flags:
INPUT:
-f, -files string[] Nuclei scan result file or directory path. Supported file extensions: .txt, .md, .jsonl
```> **NOTE**: `OPENAI_API_KEY` is required to run this program and can be obtained by signing up at `https://openai.com/api/`
### Generating Risk Score
```sh
export OPENAI_API_KEY=openrisk -f nuclei_scan_result.txt
```### Example Run:
```console
openrisk -f nuclei_results.txt_ __
____ ____ ___ ____ _____(_)____/ /__
/ __ \/ __ \/ _ \/ __ \/ ___/ / ___/ //_/
/ /_/ / /_/ / __/ / / / / / (__ ) ,<
\____/ .___/\___/_/ /_/_/ /_/____/_/|_| Powered by OpenAI (GPT-3)
/_/ v0.0.1 (experimental)
projectdiscovery.io[RISK SCORE] The 10-scale risk score for the Nuclei scan results is 10. There are multiple high-severity vulnerabilities related to Pantheon, AWS, and Netlify takeovers.
```### Using `openrisk` as a library
To utilize `openrisk` as a library, simply create an instance of the `Options` structure and input your OpenAI API key. With these options, you can then create `OpenRisk` and `IssueProcessor` by including a sample nuclei scan result file. To generate a score for the sample file, call the `openRisk.GetScore` function. For a clear example, refer to the code provided in the [examples](examples/) folder.