ScopeForge
Commercial-Grade Cybersecurity Multi-Agent Harness & Claude Code Style TUI
Autonomous SecOps Orchestrator, LangGraph Multi-Agent Team, LangChain Tool Harness, MCP Bridge & Interactive Terminal UI.
⚡ What is ScopeForge?
ScopeForge is a standalone, commercial-grade autonomous cybersecurity agent harness and terminal interface designed to work like Claude Code and Open Code, but specifically engineered with ScopeGate Rules of Engagement (RoE) safety guarantees.
Powered by LangChain, LangGraph, Textual, and the Model Context Protocol (MCP), ScopeForge coordinates specialized cybersecurity agents to perform automated reconnaissance, vulnerability scanning, static code analysis (SAST), proof-of-concept verification, and executive reporting—or operates as a general-purpose AI coding and system administration assistant.
🚀 Installation & Quickstart
1. Install via pip / pipx / uv
# Recommended: Install using pipx (isolated environment)
pipx install scopeforge
# Or standard pip
pip install scopeforge
# Or run instantly without installation via uv
uvx scopeforge
2. Launch the Interactive TUI
Simply type scopeforge or the shorthand sf in your terminal:
scopeforge
# Or:
sf
ScopeForge will launch directly into the dark-themed reactive terminal UI.
⌨️ Modern Terminal Shortcuts
ScopeForge uses standard modern terminal Ctrl+[key] bindings:
| Shortcut | Secondary | Action | Description |
|---|---|---|---|
| Ctrl+M | F1 | Model Switcher | Open live model picker, filter presets, or configure custom endpoints |
| Ctrl+H | F2 | Help Cheatsheet | Show all slash commands, shortcuts, and agent roles |
| Ctrl+O | F3 | Toggle SecOps Mode | Cycle policy gates (plan ↔ live ↔ artifacts) |
| Ctrl+B | F4 | Toggle Sidebar | Expand or collapse agent telemetry and finding ledger |
| Ctrl+W | F5 | SecOps Wiki | Open persistent knowledge base and user preferences |
| Ctrl+Y | F6 | Copy Last Response | Copy the latest AI response to system clipboard |
| Ctrl+T | F7 | Toggle Native Mouse | Switch between TUI clicks and terminal text selection |
| Ctrl+L | — | Clear Screen | Clear conversation stream and reset buffer |
| Ctrl+Q | — | Quit | Safely exit ScopeForge |
🤖 Multi-Agent Team (LangGraph)
ScopeForge routes tasks dynamically to specialized autonomous agents:
- 🧠 Supervisor: General architecture, system management, code discussion, and high-level strategy.
- 💻 DevAgent: Local code workspace operations, terminal sandbox commands, skill installation, and live web research.
- 🛰️ ReconAgent: Passive & active reconnaissance, port discovery telemetry, and attack surface enumeration.
- 🔬 AuditAgent: Static code auditing (SAST), CVE advisory correlation, and OWASP vulnerability identification.
- ⚡ ExploitAgent: Controlled proof-of-concept (PoC) validation within strict authorized bounds.
- 📋 ReportAgent: Executive SecOps summary, CVSS scoring, and remediation action plans.
Agents communicate asynchronously using the cryptographically verified Agent-to-Agent (A2A) Protocol Bus.
🛠️ LangChain Autonomous Tool-Calling Harness
ScopeForge provides real autonomous tool execution through LangChain:
- Autonomous Tool Binding: Models (
OpenRouter,Groq,DeepSeek,Claude,OpenAI) are automatically bound to the complete toolsuite and active MCP tools viachat_model.bind_tools(). - Iterative Tool Execution: The harness detects
tool_calls, executes tools safely via the ScopeGate middleware pipeline, feedsToolMessageoutputs back into context, and synthesizes answers iteratively. - Built-in Tools:
bash_cli: Sandboxed shell execution with dangerous-pattern blocking.google_web_search: Live web search for fast technical lookups.view_file/write_file/edit_file: Surgical code workspace inspection and editing.glob_files/grep_search: Fast repository pattern discovery.git_status_tool/git_diff_tool/git_commit_tool: Git version control operations.recon_port_scan/web_surface_probe: Perimeter discovery tools.sast_code_audit/cve_advisory_search: Vulnerability triage tools.
🌐 Model Support & Custom API Configuration
ScopeForge supports any OpenAI-compatible, Anthropic, or Ollama provider:
Quick Presets (Zero Setup):
openrouter-free: Meta-router for high-availability free frontier models (openrouter/free).openrouter-free-nemotron: NVIDIA Nemotron 550B Free.groq-llama3: Llama 3.3 70B on Groq Ultra-Fast inference.ollama-llama3: Offline local models via Ollama.
Custom Endpoints & Third-Party Proxies:
Open the Model Switcher (Ctrl+M) or use slash commands:
/model
/config set key <API_KEY>
/config set model <MODEL_ID>
/config set base <CUSTOM_URL>
ScopeForge features native paste de-duplication and custom endpoint normalization (no forced path appending).
🔌 Model Context Protocol (MCP) & Skills
MCP Integration:
/mcp # List all configured MCP servers
/mcp tools # View all registered MCP tools
/mcp add <name> <command> # Add and enable an MCP server
/mcp enable <name> # Enable a server
/mcp disable <name> # Disable a server
Extensible Skills (SKILL.md):
Install custom skills from any Git repository:
/skill install https://github.com/example/sec-skills
/skill list
🛡️ ScopeGate Rules of Engagement (RoE)
ScopeForge operates under 3 strict enforcement modes:
- PLAN (
plan): Zero network egress. Generates falsifiable hypotheses, models attack surface, and plans audits. - ARTIFACTS (
artifacts): Inspects locally supplied source code, HAR files, and logs without external traffic. - LIVE (
live): Network tools enabled strictly against authorized scope domains and IPs.
📜 License
Licensed under the Apache License, Version 2.0.
Metadata
Release files for scopeforge 0.1.1
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| scopeforge-0.1.1.tar.gz | 199.9 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| scopeforge-0.1.1-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 408.2 kB
Release files / scopeforge-0.1.1.tar.gz
| Download URL | scopeforge-0.1.1.tar.gz |
|---|---|
| Size | 199.9 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
a06f8b7e752d9cc261a4b0a9e21685c7141667baca67051f47492ff485979119
|
|
BLAKE2b-256 checksum How to use checksums |
f3fa6e6f0f9754be23a4985746833e194464d4cd5e77b8c5e1dacbd33c67e841
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
uv/0.12.23 {"installer":{"name":"uv","version":"0.12.23","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}
|
Release files / scopeforge-0.1.1-py3-none-any.whl
| Download URL | scopeforge-0.1.1-py3-none-any.whl |
|---|---|
| Size | 208.3 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
2e396bf9215f5ac6773b899925e65251aa3f70003d499e3e931b2ea183b6de60
|
|
BLAKE2b-256 checksum How to use checksums |
1250bdcdf766050fb41b5cc950d4288b2c487769f73c66a4eb45e2bcdc3778c5
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
uv/0.12.23 {"installer":{"name":"uv","version":"0.12.23","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}
|