AI-native code security scanner: runtime sandbox-validated remediation. Confirm exploits, auto-patch, replay against the fix — all at machine scale.
Project description
Argus Scanner
Verified vulnerability remediation at machine scale. Argus runs every confirmed finding through a Firecracker sandbox, generates a patch, and replays the same exploit against the patched code — so you ship fixes that actually close the bug, not tickets that pile up.
Open source, BYOK, Apache 2.0.
The problem
Vulnerability throughput is up and to the right and it isn't slowing down. CVE counts, supply-chain advisories, AI-generated code, agent-authored PRs, agent-installed dependencies — the queue of "things to patch" grows every quarter while the team that has to patch them does not. CISOs aren't asking "can you find more bugs?" anymore. They're asking "how do I close 10,000 open findings before next audit?"
The bottleneck is not detection. It's two things:
- Triage paralysis. Static scanners flag thousands of patterns that may or may not be real. Engineers spend 60-80% of their security time deciding which ones to fix instead of fixing them.
- Patch validation. Even when you write a fix, you don't know if it actually closes the hole until something else (a pen-tester, a customer, an attacker) tells you it didn't. Most teams ship patches blind.
Static scanners give you more findings. Argus closes them.
How Argus closes findings
File → L1 (AI static analysis) → Finding Validation → Remediation
──────────────── ──────────────
Sandbox replays Auto-patch +
each finding to replay same
confirm/refute exploit against
with runtime the patched
evidence code to verify
Two stages, both default ON as of v1.11:
- Finding Validation (the runtime FP killer). Every L1 finding is re-run against the file's real runtime in a Firecracker microVM. A "potential SSRF" the file's own validation rejects →
BLOCKED. A path-traversal that never reachesopen()→UNREACHED. A pattern that fires for real →CONFIRMEDwith sandbox-captured proof. Only what survives is real work. - Remediation (the headline). For each
CONFIRMEDfinding, Argus generates a targeted patch, applies it to a clean copy of the source, and re-runs the original exploit against the patched code in the same sandbox. Per-finding post-patch verdict:NEUTRALIZED— sandbox replay shows the exploit no longer fires. Ship the patch.STILL_EXPLOITABLE— patch was insufficient; Argus tells you what still fires.UNVERIFIABLE— sandbox couldn't decisively replay; manual review.
You get a tested fix, not a ticket. At scan-repo scale, you get hundreds of tested fixes in one run — fanned out across your codebase, ready to PR.
Why machine-level remediation is the only credible answer
CISOs in 2026 are choosing between three remediation postures:
- Hire your way out. Doesn't scale. Security engineers don't materialize.
- AI-generate patches blind. Cheap, fast, dangerous. Without runtime validation, every "fix" is a guess. You ship regressions or insufficient patches and find out the hard way.
- Machine-validated remediation. Sandbox proves the bug. AI writes the patch. Sandbox proves the patch. Repeat at scale. This is Argus.
Sandbox validation is the difference between a remediation pipeline and a patch-ticket pipeline.
Coverage today
Static + LLM cascade (all listed formats):
- Code: Python, JavaScript / TypeScript, shell, Java bytecode (
.class,.jar) - Supply-chain manifests:
package.json,requirements.txt,Cargo.lock,go.mod,Gemfile,composer.json,pyproject.toml,Pipfile, Dockerfile, Makefile,.npmrc,.pypirc - AI-agent config sentinels:
CLAUDE.md,mcp.json,.cursorrules,claude_desktop_config.json,AGENTS.md,devcontainer.json - Doc / web attack surface: Markdown / RST / AsciiDoc (prompt-injection vectors), HTML / SVG / XML
Sandbox detonation + Remediation (executable formats only): Python, JavaScript / TypeScript, shell, Java bytecode. Non-executable formats stay cascade-only by definition.
Roadmap: Go, Rust, .NET.
Optional: deeper coverage
For zero-day hunting beyond Validation + Remediation, three opt-in stages are available:
| Stage | What it does | Flag |
|---|---|---|
| Exploit Discovery | Enumerates the file's callables, generates fresh attack inputs, hunts for exploits L1 didn't see | --enable-runtime-probe |
| Behavioral Profiling | Imports the module with benign inputs, captures runtime behavior (syscalls, network, file IO) | --enable-phase-3-discovery |
| Adversarial Reasoning | Model designs attack hypotheses anchored on the runtime profile, sandbox tests each | --enable-phase-3-loop |
Enable all three with the three flags together. Typical added cost: ~$0.50-1.50/file. Most operators don't need these — the default Validation + Remediation cascade handles 90% of the actual remediation workload.
Per-finding verdicts
| Status | Meaning |
|---|---|
CONFIRMED |
Sandbox observed the exploit firing. Patch generated + re-validated by default. |
BLOCKED |
Attack was tested; the file's own code defended (sanitization, escaping, allowlist). |
UNREACHED |
Attack was tested; the code path is genuinely unreachable. |
NOT_TESTED |
Sandbox couldn't execute the test. Sub-reason: infra_stub / inconclusive / not_planned. |
SUPPRESSED |
Production-grade FP-defense oracle (structured assertion / downstream-cap / syscall-sink) refuted the static match. |
A typical CONFIRMED + NEUTRALIZED shipping bundle:
{
"cwe": "CWE-200",
"type": "data_exfiltration",
"severity": "critical",
"status": "CONFIRMED",
"runtime_evidence": "Mock HTTP server at 127.0.0.1:8000 captured POST body containing 'FAKE_PRIVATE_KEY_CONTENT'. The function decoded its base64 payload and POSTed the contents of ~/.ssh/ to the C2 endpoint.",
"remediation": {
"status": "NEUTRALIZED",
"patch": "...unified diff...",
"verification": "Same exploit re-run against patched source: no HTTP POST observed, no /tmp/canary creation, exception raised at line 47 before any I/O."
}
}
This is what an SLA-grade remediation pipeline looks like.
Enterprise invariants
- BYOK. You control LLM access; bills go to your API meter, not ours.
- Zero telemetry. Cascade-only mode: nothing leaves your machine. DAST mode: file content goes only to a Fly.io app you own and control — never to Argus-operated infrastructure.
- Local execution. Self-contained pipeline; no SaaS dependency.
- Hardware isolation. Detonation happens in Firecracker microVMs (KVM hardware virtualization), ephemeral per-run, strict egress control. Patch verification re-uses the same isolation primitives.
Quick Start
pip install argus-ai-scanner
export ANTHROPIC_API_KEY="your-anthropic-key"
# Single file — Validation + Remediation by default
argus scan path/to/suspicious.py
# Whole repo — full remediation pipeline across every file
argus scan-repo .
# CI mode — only files changed vs main, SARIF for GitHub Code Scanning
argus scan-repo . --diff origin/main --output sarif --output-file findings.sarif
# Read-only audit (compliance scans / no source mods allowed)
argus scan-repo . --no-enable-remediation
# Full coverage including zero-day hunting
argus scan path/to/file.py \
--enable-runtime-probe \
--enable-phase-3-discovery \
--enable-phase-3-loop
Without DAST configured (Fly.io app), Argus gracefully degrades to cascade-only verdicts — Remediation requires the sandbox.
CLI reference
argus scan <file> — single-file scan
| Flag | Purpose |
|---|---|
--output {json,markdown} |
Output format (default: json) |
--no-dast |
Skip all sandbox stages (cascade-only) |
--no-enable-remediation |
Skip patch generation (default ON) |
--enable-runtime-probe |
Opt in to Exploit Discovery |
--enable-phase-3-discovery |
Opt in to Behavioral Profiling |
--enable-phase-3-loop |
Opt in to Adversarial Reasoning |
--dast-trigger-verdicts LIST |
L1 verdicts that trigger DAST. Default: suspicious,malicious,critical_malicious. |
--max-cost USD |
Abort if per-file API spend exceeds USD (default: $1.00; 0 disables) |
argus scan-repo <path> — directory tree scan
Same flags as scan plus:
| Flag | Purpose |
|---|---|
--diff REF |
Only scan files differing vs git ref (e.g., --diff origin/main for PR/CI) |
--output {markdown,json,sarif} |
Output format (default: markdown); sarif for GitHub Code Scanning |
--output-file PATH |
Write output to file instead of stdout |
--max-cost USD |
Abort run when cumulative API spend exceeds USD; remaining files marked cost_cap_reached |
--exclude GLOB |
Additional gitignore-style exclude pattern (repeatable) |
--no-gitignore |
Ignore .gitignore during walk (default: respected) |
--max-file-bytes BYTES |
Skip files larger than BYTES (default: 1 MiB) |
--continue-on-error / --no-continue-on-error |
On per-file exception, record and continue (default) or abort |
Documentation
| Topic | Page |
|---|---|
| Install guide | docs/install.md |
| API key sourcing | docs/api-keys.md |
| Architecture deep dive | docs/architecture.md |
| DAST sandbox setup | docs/dast-setup.md |
| Cost guide | docs/cost-guide.md |
| Roadmap | ROADMAP.md |
| Contributing | CONTRIBUTING.md |
| Security disclosures | SECURITY.md |
License
Project details
Release history Release notifications | RSS feed
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file argus_ai_scanner-1.11.0.tar.gz.
File metadata
- Download URL: argus_ai_scanner-1.11.0.tar.gz
- Upload date:
- Size: 1.4 MB
- Tags: Source
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/6.1.0 CPython/3.13.12
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
57d8e6dfcf6c77a5d9f910a771f2a373df5bba046bd9ff5ee6393b141e1b392a
|
|
| MD5 |
74b8079e3e6b075ed5f26cd6df9aca67
|
|
| BLAKE2b-256 |
eee4623cd159c542f3cbaaed35cc740e2e008b71bdb43496a599163c10bde7c1
|
Provenance
The following attestation bundles were made for argus_ai_scanner-1.11.0.tar.gz:
Publisher:
release.yml on dshochat/Argus_Scanner
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
argus_ai_scanner-1.11.0.tar.gz -
Subject digest:
57d8e6dfcf6c77a5d9f910a771f2a373df5bba046bd9ff5ee6393b141e1b392a - Sigstore transparency entry: 1677080065
- Sigstore integration time:
-
Permalink:
dshochat/Argus_Scanner@c3a5ece16927097abf13a4155f71f93213ed9ce8 -
Branch / Tag:
refs/tags/v1.11.0 - Owner: https://github.com/dshochat
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
release.yml@c3a5ece16927097abf13a4155f71f93213ed9ce8 -
Trigger Event:
push
-
Statement type:
File details
Details for the file argus_ai_scanner-1.11.0-py3-none-any.whl.
File metadata
- Download URL: argus_ai_scanner-1.11.0-py3-none-any.whl
- Upload date:
- Size: 941.4 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/6.1.0 CPython/3.13.12
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
c609db6272d488dfb54578b43df94ec5dc1513593d23c850ef6147d9b84cd431
|
|
| MD5 |
eab0f5275d113576b2fd0bef06dfef55
|
|
| BLAKE2b-256 |
c6e43645daab0463f52fd06037a319651ab45414e65b292a0dc0c4c0c5f9b2e0
|
Provenance
The following attestation bundles were made for argus_ai_scanner-1.11.0-py3-none-any.whl:
Publisher:
release.yml on dshochat/Argus_Scanner
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
argus_ai_scanner-1.11.0-py3-none-any.whl -
Subject digest:
c609db6272d488dfb54578b43df94ec5dc1513593d23c850ef6147d9b84cd431 - Sigstore transparency entry: 1677080084
- Sigstore integration time:
-
Permalink:
dshochat/Argus_Scanner@c3a5ece16927097abf13a4155f71f93213ed9ce8 -
Branch / Tag:
refs/tags/v1.11.0 - Owner: https://github.com/dshochat
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
release.yml@c3a5ece16927097abf13a4155f71f93213ed9ce8 -
Trigger Event:
push
-
Statement type: