Autonomous web security research agent for controlled authorized targets
Project description
Ravage
Ravage is an evidence-first web security research agent for controlled,
authorized targets. This package provides the ravage CLI and runtime modules.
The project is a pre-1.0 research alpha. Use it only on local fixtures, isolated labs, or systems you own and are explicitly authorized to assess. The active public CLI is localhost-first.
Source Checkout
The canonical development setup is the repository bootstrap:
scripts/bootstrap.sh
source .venv/bin/activate
ravage --version
The 0.0.1 PyPI package is a legacy preview. Until a newer tagged release is
published, use a source checkout and record its exact commit when reporting
results.
Active Commands
Run deterministic probes without model calls:
ravage scan brief.yaml --run-dir runs/local-scan --report
Run the model-driven agent after configuring a model route and adding a useful
context.description to the brief:
ravage attack brief.yaml \
--model-profile hosted-openai \
--model-tier low \
--allow-paid-models \
--report
Inspect and verify a run:
ravage observe runs/<run-dir>
ravage audit verify runs/<run-dir>
ravage report runs/<run-dir> --brief brief.yaml
Use ravage --help and each subcommand's --help for the installed version.
External scanners such as nmap, sqlmap, katana, nuclei, and ffuf are
not Python dependencies. From a source checkout, use
scripts/install_tools.sh --method docker --execute, then run
ravage tools check.
The optional browser extra adds Playwright support; install its Chromium
runtime separately with playwright install chromium.
Documentation
See the repository README, setup guide, and operator guide.
Ravage is open source under the Apache License 2.0. See the repository
SECURITY.md, CONTRIBUTING.md, DISCLAIMER.md, and LICENSE before use or
contribution.
Project details
Release history Release notifications | RSS feed
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file ravage-0.5.0.tar.gz.
File metadata
- Download URL: ravage-0.5.0.tar.gz
- Upload date:
- Size: 552.0 kB
- Tags: Source
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/6.1.0 CPython/3.13.12
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
262e0057f97555cd29c2eeb41b70cf0117f89d52dd1d092f66973b6c7cb05bbb
|
|
| MD5 |
36180f3a37a532d0e78435a339f03516
|
|
| BLAKE2b-256 |
d596090a9c9a228bca2aedc4d7b0e84d3431469b5cc72f3bee41e7c21f0b9fc1
|
Provenance
The following attestation bundles were made for ravage-0.5.0.tar.gz:
Publisher:
publish-pypi.yml on duriantaco/ravage
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
ravage-0.5.0.tar.gz -
Subject digest:
262e0057f97555cd29c2eeb41b70cf0117f89d52dd1d092f66973b6c7cb05bbb - Sigstore transparency entry: 2167023392
- Sigstore integration time:
-
Permalink:
duriantaco/ravage@43f159e166b1009942d6b3126af5942d15e78fb3 -
Branch / Tag:
refs/tags/v0.5.0 - Owner: https://github.com/duriantaco
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
publish-pypi.yml@43f159e166b1009942d6b3126af5942d15e78fb3 -
Trigger Event:
release
-
Statement type:
File details
Details for the file ravage-0.5.0-py3-none-any.whl.
File metadata
- Download URL: ravage-0.5.0-py3-none-any.whl
- Upload date:
- Size: 683.2 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/6.1.0 CPython/3.13.12
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
371bb914565097a90ae7652b5e47b6ece1740c9528d15ddad456bd06ab7a0aeb
|
|
| MD5 |
ea00af685aa6bb338cacd6859625d65e
|
|
| BLAKE2b-256 |
122cc6618cfaf65d8e03e81aeec85c60c7241971f98f10d23b971e56859575e3
|
Provenance
The following attestation bundles were made for ravage-0.5.0-py3-none-any.whl:
Publisher:
publish-pypi.yml on duriantaco/ravage
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
ravage-0.5.0-py3-none-any.whl -
Subject digest:
371bb914565097a90ae7652b5e47b6ece1740c9528d15ddad456bd06ab7a0aeb - Sigstore transparency entry: 2167023498
- Sigstore integration time:
-
Permalink:
duriantaco/ravage@43f159e166b1009942d6b3126af5942d15e78fb3 -
Branch / Tag:
refs/tags/v0.5.0 - Owner: https://github.com/duriantaco
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
publish-pypi.yml@43f159e166b1009942d6b3126af5942d15e78fb3 -
Trigger Event:
release
-
Statement type: