Building JED AI: An Autonomous Security Agent Executing 45+ Tools via Real-Time SSE
DEV Community

Building JED AI: An Autonomous Security Agent Executing 45+ Tools via Real-Time SSE

Hey everyone! ๐Ÿ‘‹ As developers, we’ve all been there: you want to run a quick security audit or reconnaissance sweep, but you end up bogged down juggling local terminal CLI tools (Nmap, Amass, SQLMap, etc.), managing dependencies, and parsing massive blocks of raw text. Even worse, standard AI "chat wrappers" just give you text advice on how to run commands-leaving you to do all the heavy lifting manually. I wanted to bridge the gap between AI reasoning and real system execution. So, I built JED AI (https://jedcorp.ink) - a cloud-native, web-based autonomous security agent that lets users run multi-tool audits, OSINT reconnaissance, and vulnerability scans entirely in the browser using natural language or voice prompts. โš™๏ธ How It Works (The Architecture) - ReAct Agent Loop: Built with a custom reasoning and acting loop in Python (running on Gunicorn) that breaks high-level user directives down into discrete tasks (e.g., resolving subdomains via Amass, mapping ports via Nmap). - Process Isolation & The Kali Armory: It securely orchestrates 33+ integrated Kali tools on the backend, capturing raw stdout/stderr streams without exposing the host server to unsafe command injection. - Real-Time SSE (Server-Sent Events): Instead of waiting blindly for a long-running security scan to finish, the frontend receives live telemetry chunks via Server-Sent Events, updating the mission planner UI in real time. - Tech Stack & State: Powered by a Python backend, SQLite storage, JWT auth, Cloudflare Tunnel compatibility for secure remote access, and integrated Paystack infrastructure for billing/subscriptions. ๐Ÿš€ Traction & What's Next JED AI is live, monetized, and actively growing! It currently serves 1.2k registered users, with over 10k executed scans and 15k+ security findings logged. If you're interested in the code or want to test out the sandbox, you can check out the project here: - Live Platform: https://jedcorp.ink I’d love to hear your thoughts, feedback on the agent execution pipeline, or how you handle process safety when running arbitrary security tools via LLMs! Let's chat in the comments below. ๐Ÿ‘‡ Top comments (0)

Read on DEV Community ↗ ← Back to News

Comments

No comments yet. Start the discussion.