Skip to content

Nuclei Templates ​

Nuclei templates are YAML-based scanning definitions that power automated vulnerability detection across the platform. They define what to check, how to check it, and how to classify the results.

What Are Nuclei Templates ​

Nuclei is an open-source vulnerability scanner that uses YAML templates to define detection logic. Hashiro integrates Nuclei for automated scanning in AI Assessments.

Each template defines:

  • Request: what HTTP request (or other protocol interaction) to send
  • Matchers: conditions that indicate a vulnerability is present
  • Extractors: data to pull from responses for evidence
  • Severity: classification of the finding
  • Metadata: CVE references, tags, descriptions

Custom Templates ​

Hashiro includes a catalog of built-in Nuclei templates. You can also create custom templates for:

  • Proprietary application vulnerabilities
  • Internal configuration standards
  • Custom compliance checks
  • Application-specific business logic tests

YAML Editor ​

The Hashiro UI includes a YAML editor with syntax highlighting and validation for writing Nuclei templates.

Nuclei template library

Screenshots use fictional demonstration data.

Importing Templates ​

Import existing templates from the public Nuclei template repository, your internal collections, or third-party sources.

How Templates Are Used ​

In AI Assessments ​

AI agents can trigger Nuclei scans as part of their pipeline. The agent selects relevant templates based on discovered technologies.

Results ​

Nuclei scan results appear as findings in the project's issues list with severity badges and template metadata attached. They can be reviewed and managed like any other finding.

Hashiro. Continuous Threat Exposure Management.