Skip to main content

Autonomous web security research agent for controlled authorized targets

Project description

Ravage

Ravage is an evidence-first web security research agent for controlled, authorized targets. This package provides the ravage CLI and runtime modules.

The project is a pre-1.0 research alpha. Use it only on local fixtures, isolated labs, or systems you own and are explicitly authorized to assess. The active public CLI is localhost-first.

Source Checkout

The canonical development setup is the repository bootstrap:

scripts/bootstrap.sh
source .venv/bin/activate
ravage --version

The 0.0.1 PyPI package is a legacy preview. Until a newer tagged release is published, use a source checkout and record its exact commit when reporting results.

Active Commands

Run deterministic probes without model calls:

ravage scan brief.yaml --run-dir runs/local-scan --report

Run the model-driven agent after configuring a model route and adding a useful context.description to the brief:

ravage attack brief.yaml \
  --model-profile hosted-openai \
  --model-tier low \
  --allow-paid-models \
  --report

Inspect and verify a run:

ravage observe runs/<run-dir>
ravage audit verify runs/<run-dir>
ravage report runs/<run-dir> --brief brief.yaml

Use ravage --help and each subcommand's --help for the installed version.

External scanners such as nmap, sqlmap, katana, nuclei, and ffuf are not Python dependencies. From a source checkout, use scripts/install_tools.sh --method docker --execute, then run ravage tools check.

The optional browser extra adds Playwright support; install its Chromium runtime separately with playwright install chromium.

Documentation

See the repository README, setup guide, and operator guide.

Ravage is open source under the Apache License 2.0. See the repository SECURITY.md, CONTRIBUTING.md, DISCLAIMER.md, and LICENSE before use or contribution.

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

ravage-0.5.0.tar.gz (552.0 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

ravage-0.5.0-py3-none-any.whl (683.2 kB view details)

Uploaded Python 3

File details

Details for the file ravage-0.5.0.tar.gz.

File metadata

  • Download URL: ravage-0.5.0.tar.gz
  • Upload date:
  • Size: 552.0 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.12

File hashes

Hashes for ravage-0.5.0.tar.gz
Algorithm Hash digest
SHA256 262e0057f97555cd29c2eeb41b70cf0117f89d52dd1d092f66973b6c7cb05bbb
MD5 36180f3a37a532d0e78435a339f03516
BLAKE2b-256 d596090a9c9a228bca2aedc4d7b0e84d3431469b5cc72f3bee41e7c21f0b9fc1

See more details on using hashes here.

Provenance

The following attestation bundles were made for ravage-0.5.0.tar.gz:

Publisher: publish-pypi.yml on duriantaco/ravage

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file ravage-0.5.0-py3-none-any.whl.

File metadata

  • Download URL: ravage-0.5.0-py3-none-any.whl
  • Upload date:
  • Size: 683.2 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.12

File hashes

Hashes for ravage-0.5.0-py3-none-any.whl
Algorithm Hash digest
SHA256 371bb914565097a90ae7652b5e47b6ece1740c9528d15ddad456bd06ab7a0aeb
MD5 ea00af685aa6bb338cacd6859625d65e
BLAKE2b-256 122cc6618cfaf65d8e03e81aeec85c60c7241971f98f10d23b971e56859575e3

See more details on using hashes here.

Provenance

The following attestation bundles were made for ravage-0.5.0-py3-none-any.whl:

Publisher: publish-pypi.yml on duriantaco/ravage

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page