Skip to main content

🐘 Maroon Elephant

AI-era threat modeling & repository scanning — OWASP-2026 aligned, deterministic-first, zero-dependency core.

Detect the AI/agentic/MCP components in a repo, infer its architecture, and produce evidence-backed threat findings mapped to the OWASP LLM Top 10, Agentic (ASI) Top 10, GenAI Data Security (DSGAI), and MCP security guidance — worst-first, across a whole org.

License Python Core deps OWASP 2026

Live site & docs →

Status: 🚧 Alpha / under active construction. The design is specified in Findings.md (research) and Build Plan.md (engineering spec).


Why

LLMs collapse the control plane and the data plane into one flat token namespace — the root cause behind prompt injection, data exfiltration, excessive agency, and memory poisoning. The security market is crowded with runtime products but thin on open-source, repo-driven, design-time threat modeling for AI systems. Maroon Elephant fills that gap.

It stands on top of grey-panda (the deterministic, in-the-file AI-security scanner) and adds architecture inference, multi-repo orchestration, a governance verdict, GitHub integration, and a local UI.

Grey Panda = the calm deterministic guardian. Maroon Elephant = the orchestrating, design-time, multi-repo threat-modeler on top of it.

Principles

  • Deterministic-first. Every finding has file:line evidence. The LLM is optional and only enriches an existing deterministic finding — it can never invent one.
  • Zero runtime dependencies. The core is Python standard library only; everything heavier is an optional extra ([polyglot], [llm], [github], [subscanners]).
  • Local-first & BYOK. Your source never leaves your machine by default; air-gapped mode makes zero external calls.
  • Standards-anchored. Every finding carries a cross-framework tuple (LLM / ASI / DSGAI / MAESTRO layer / AIVSS / MITRE ATLAS / CWE / NIST / regulatory).

Quick start (target UX)

pip install maroon-elephant
maroon scan .                      # scan the current repo
maroon scan https://github.com/org/repo
maroon scan ./app --format sarif -o results.sarif
maroon scan ./app --format html  -o report.html   # shareable threat-model report
maroon serve                       # Enterprise: local dashboard on http://localhost:7879

Exit codes and --fail-on {low,medium,high,critical} make it CI-ready; --baseline old.sarif scans diff-aware (fail only on new findings).

Grey Panda (the deterministic sub-scanner) is optional: pip install maroon-elephant[subscanners] (or pip install grey-panda). Without it, Maroon Elephant's native rules still run. LLM enrichment is off by default and BYOK — enable with --explain after setting MAROON_LLM_PROVIDER (anthropic/openai/google/ollama/lmstudio). With no provider, or with ollama, the scan makes zero external calls.

What it produces

  1. Vulnerability findings → SARIF 2.1.0 (GitHub/Azure code scanning, VS Code).
  2. A design-time threat model → component graph → MAESTRO layers → threat-model-as-code + diagram.
  3. An AI inventory / AI-BOM → CycloneDX AI/ML-BOM ("what AI are we even running?").

Plus, in the Enterprise edition: crown-jewels P0→P1→P2 multi-repo prioritization and an AT×L governance verdict (adoption tier × maturity → "raise maturity or reduce tier").

What it can and cannot do

See docs/CAN_AND_CANNOT.md. In short: static analysis only; Python-first deep analysis (other languages via [polyglot]); governance checks are partly presence/absence ("needs attestation"); live GitHub App hosting and package publishing need your own accounts.

Documentation

  • Findings.md — the research synthesis (threat corpus, competitive landscape).
  • Build Plan.md — the engineering spec (architecture, FRs, roadmap).
  • docs/ — how-to guides, architecture, "What is BYOT?", and honest limits.

Contributing

Issues and rule contributions welcome — see CONTRIBUTING.md. The knowledge pack (maroon/knowledge/) is versioned JSON, designed to be extended as OWASP/ATLAS/AIVSS evolve.

License

Apache-2.0 — see LICENSE. OWASP source documents referenced in the knowledge pack are CC BY-SA 4.0 and are credited in NOTICE.

Metadata

Release files for maroon-elephant 0.1.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for maroon-elephant 0.1.0
File Size Uploaded
maroon_elephant-0.1.0.tar.gz 86.1 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for maroon-elephant 0.1.0
File Interpreter ABI Platform
maroon_elephant-0.1.0-py3-none-any.whl Python 3 none any Details

Total release size: 180.4 kB

Release files / maroon_elephant-0.1.0.tar.gz

Download URL maroon_elephant-0.1.0.tar.gz
Size 86.1 kB
Tags Source
SHA-256 checksum
How to use checksums
b602ce8bd276588ddd2f0b8823f3c9037c57124b9b59da46131124c1d768cb91
BLAKE2b-256 checksum
How to use checksums
8b2a03584c08771af70cbb435f7f7a0669493317463342d3c116eb356f8e942b
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.9.6

Release files / maroon_elephant-0.1.0-py3-none-any.whl

Download URL maroon_elephant-0.1.0-py3-none-any.whl
Size 94.3 kB
Tags Python 3
SHA-256 checksum
How to use checksums
cd3ef237d42d4e6b32bbd67c3b153a9a9e08927b3068fe6e0d715d1de76c497f
BLAKE2b-256 checksum
How to use checksums
3b958e04c943c0b2bdfe63eba3f5f184a2c3976fbae088b14da314e9a5f9173c
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.9.6

Release history Release notifications | RSS feed

This release

0.1.0 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page