🐘 Maroon Elephant
AI-era threat modeling & repository scanning — OWASP-2026 aligned, deterministic-first, zero-dependency core.
Detect the AI/agentic/MCP components in a repo, infer its architecture, and produce evidence-backed threat findings mapped to the OWASP LLM Top 10, Agentic (ASI) Top 10, GenAI Data Security (DSGAI), and MCP security guidance — worst-first, across a whole org.
Status: 🚧 Alpha / under active construction. The design is specified in Findings.md (research) and Build Plan.md (engineering spec).
Why
LLMs collapse the control plane and the data plane into one flat token namespace — the root cause behind prompt injection, data exfiltration, excessive agency, and memory poisoning. The security market is crowded with runtime products but thin on open-source, repo-driven, design-time threat modeling for AI systems. Maroon Elephant fills that gap.
It stands on top of grey-panda (the deterministic, in-the-file AI-security scanner) and adds architecture inference, multi-repo orchestration, a governance verdict, GitHub integration, and a local UI.
Grey Panda = the calm deterministic guardian. Maroon Elephant = the orchestrating, design-time, multi-repo threat-modeler on top of it.
Principles
- Deterministic-first. Every finding has
file:lineevidence. The LLM is optional and only enriches an existing deterministic finding — it can never invent one. - Zero runtime dependencies. The core is Python standard library only; everything heavier is an
optional extra (
[polyglot],[llm],[github],[subscanners]). - Local-first & BYOK. Your source never leaves your machine by default; air-gapped mode makes zero external calls.
- Standards-anchored. Every finding carries a cross-framework tuple (LLM / ASI / DSGAI / MAESTRO layer / AIVSS / MITRE ATLAS / CWE / NIST / regulatory).
Quick start (target UX)
pip install maroon-elephant
maroon scan . # scan the current repo
maroon scan https://github.com/org/repo
maroon scan ./app --format sarif -o results.sarif
maroon scan ./app --format html -o report.html # shareable threat-model report
maroon serve # Enterprise: local dashboard on http://localhost:7879
Exit codes and --fail-on {low,medium,high,critical} make it CI-ready; --baseline old.sarif
scans diff-aware (fail only on new findings).
Grey Panda (the deterministic sub-scanner) is optional:
pip install maroon-elephant[subscanners](orpip install grey-panda). Without it, Maroon Elephant's native rules still run. LLM enrichment is off by default and BYOK — enable with--explainafter settingMAROON_LLM_PROVIDER(anthropic/openai/ollama/lmstudio). With no provider, or withollama, the scan makes zero external calls.
What it produces
- Vulnerability findings → SARIF 2.1.0 (GitHub/Azure code scanning, VS Code).
- A design-time threat model → component graph → MAESTRO layers → threat-model-as-code + diagram.
- An AI inventory / AI-BOM → CycloneDX AI/ML-BOM ("what AI are we even running?").
Plus, in the Enterprise edition: crown-jewels P0→P1→P2 multi-repo prioritization and an AT×L governance verdict (adoption tier × maturity → "raise maturity or reduce tier").
What it can and cannot do
See docs/CAN_AND_CANNOT.md. In short: static analysis only; Python-first
deep analysis (other languages via [polyglot]); governance checks are partly presence/absence
("needs attestation"); live GitHub App hosting and package publishing need your own accounts.
Documentation
- Findings.md — the research synthesis (threat corpus, competitive landscape).
- Build Plan.md — the engineering spec (architecture, FRs, roadmap).
- docs/ — how-to guides, architecture, "What is BYOT?", and honest limits.
Contributing
Issues and rule contributions welcome — see CONTRIBUTING.md. The knowledge pack
(maroon/knowledge/) is versioned JSON, designed to be extended as OWASP/ATLAS/AIVSS evolve.
License
Apache-2.0 — see LICENSE. OWASP source documents referenced in the knowledge pack are CC BY-SA 4.0 and are credited in NOTICE.
Metadata
Release files for maroon-elephant 0.1.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| maroon_elephant-0.1.0.tar.gz | 86.1 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| maroon_elephant-0.1.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 180.4 kB
Release files / maroon_elephant-0.1.0.tar.gz
| Download URL | maroon_elephant-0.1.0.tar.gz |
|---|---|
| Size | 86.1 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
b602ce8bd276588ddd2f0b8823f3c9037c57124b9b59da46131124c1d768cb91
|
|
BLAKE2b-256 checksum How to use checksums |
8b2a03584c08771af70cbb435f7f7a0669493317463342d3c116eb356f8e942b
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/6.2.0 CPython/3.9.6
|
Release files / maroon_elephant-0.1.0-py3-none-any.whl
| Download URL | maroon_elephant-0.1.0-py3-none-any.whl |
|---|---|
| Size | 94.3 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
cd3ef237d42d4e6b32bbd67c3b153a9a9e08927b3068fe6e0d715d1de76c497f
|
|
BLAKE2b-256 checksum How to use checksums |
3b958e04c943c0b2bdfe63eba3f5f184a2c3976fbae088b14da314e9a5f9173c
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/6.2.0 CPython/3.9.6
|