Skip to main content

ScopeForge

Commercial-Grade Cybersecurity Multi-Agent Harness & Claude Code Style TUI
Autonomous SecOps Orchestrator, LangGraph Multi-Agent Team, LangChain Tool Harness, MCP Bridge & Interactive Terminal UI.

PyPI version Python Versions License: Apache-2.0 Built with Textual Orchestration LangGraph


⚡ What is ScopeForge?

ScopeForge is a standalone, commercial-grade autonomous cybersecurity agent harness and terminal interface designed to work like Claude Code and Open Code, but specifically engineered with ScopeGate Rules of Engagement (RoE) safety guarantees.

Powered by LangChain, LangGraph, Textual, and the Model Context Protocol (MCP), ScopeForge coordinates specialized cybersecurity agents to perform automated reconnaissance, vulnerability scanning, static code analysis (SAST), proof-of-concept verification, and executive reporting—or operates as a general-purpose AI coding and system administration assistant.


🚀 Installation & Quickstart

1. Install via pip / pipx / uv

# Recommended: Install using pipx (isolated environment)
pipx install scopeforge

# Or standard pip
pip install scopeforge

# Or run instantly without installation via uv
uvx scopeforge

2. Launch the Interactive TUI

Simply type scopeforge or the shorthand sf in your terminal:

scopeforge
# Or:
sf

ScopeForge will launch directly into the dark-themed reactive terminal UI.


⌨️ Modern Terminal Shortcuts

ScopeForge uses standard modern terminal Ctrl+[key] bindings:

Shortcut Secondary Action Description
Ctrl+M F1 Model Switcher Open live model picker, filter presets, or configure custom endpoints
Ctrl+H F2 Help Cheatsheet Show all slash commands, shortcuts, and agent roles
Ctrl+O F3 Toggle SecOps Mode Cycle policy gates (plan ↔ live ↔ artifacts)
Ctrl+B F4 Toggle Sidebar Expand or collapse agent telemetry and finding ledger
Ctrl+W F5 SecOps Wiki Open persistent knowledge base and user preferences
Ctrl+Y F6 Copy Last Response Copy the latest AI response to system clipboard
Ctrl+T F7 Toggle Native Mouse Switch between TUI clicks and terminal text selection
Ctrl+L — Clear Screen Clear conversation stream and reset buffer
Ctrl+Q — Quit Safely exit ScopeForge

🤖 Multi-Agent Team (LangGraph)

ScopeForge routes tasks dynamically to specialized autonomous agents:

  • 🧠 Supervisor: General architecture, system management, code discussion, and high-level strategy.
  • 💻 DevAgent: Local code workspace operations, terminal sandbox commands, skill installation, and live web research.
  • 🛰️ ReconAgent: Passive & active reconnaissance, port discovery telemetry, and attack surface enumeration.
  • 🔬 AuditAgent: Static code auditing (SAST), CVE advisory correlation, and OWASP vulnerability identification.
  • ⚡ ExploitAgent: Controlled proof-of-concept (PoC) validation within strict authorized bounds.
  • 📋 ReportAgent: Executive SecOps summary, CVSS scoring, and remediation action plans.

Agents communicate asynchronously using the cryptographically verified Agent-to-Agent (A2A) Protocol Bus.


🛠️ LangChain Autonomous Tool-Calling Harness

ScopeForge provides real autonomous tool execution through LangChain:

  • Autonomous Tool Binding: Models (OpenRouter, Groq, DeepSeek, Claude, OpenAI) are automatically bound to the complete toolsuite and active MCP tools via chat_model.bind_tools().
  • Iterative Tool Execution: The harness detects tool_calls, executes tools safely via the ScopeGate middleware pipeline, feeds ToolMessage outputs back into context, and synthesizes answers iteratively.
  • Built-in Tools:
    • bash_cli: Sandboxed shell execution with dangerous-pattern blocking.
    • google_web_search: Live web search for fast technical lookups.
    • view_file / write_file / edit_file: Surgical code workspace inspection and editing.
    • glob_files / grep_search: Fast repository pattern discovery.
    • git_status_tool / git_diff_tool / git_commit_tool: Git version control operations.
    • recon_port_scan / web_surface_probe: Perimeter discovery tools.
    • sast_code_audit / cve_advisory_search: Vulnerability triage tools.

🌐 Model Support & Custom API Configuration

ScopeForge supports any OpenAI-compatible, Anthropic, or Ollama provider:

Quick Presets (Zero Setup):

  • openrouter-free: Meta-router for high-availability free frontier models (openrouter/free).
  • openrouter-free-nemotron: NVIDIA Nemotron 550B Free.
  • groq-llama3: Llama 3.3 70B on Groq Ultra-Fast inference.
  • ollama-llama3: Offline local models via Ollama.

Custom Endpoints & Third-Party Proxies:

Open the Model Switcher (Ctrl+M) or use slash commands:

/model
/config set key <API_KEY>
/config set model <MODEL_ID>
/config set base <CUSTOM_URL>

ScopeForge features native paste de-duplication and custom endpoint normalization (no forced path appending).


🔌 Model Context Protocol (MCP) & Skills

MCP Integration:

/mcp                                    # List all configured MCP servers
/mcp tools                              # View all registered MCP tools
/mcp add <name> <command>               # Add and enable an MCP server
/mcp enable <name>                      # Enable a server
/mcp disable <name>                     # Disable a server

Extensible Skills (SKILL.md):

Install custom skills from any Git repository:

/skill install https://github.com/example/sec-skills
/skill list

🛡️ ScopeGate Rules of Engagement (RoE)

ScopeForge operates under 3 strict enforcement modes:

  1. PLAN (plan): Zero network egress. Generates falsifiable hypotheses, models attack surface, and plans audits.
  2. ARTIFACTS (artifacts): Inspects locally supplied source code, HAR files, and logs without external traffic.
  3. LIVE (live): Network tools enabled strictly against authorized scope domains and IPs.

📜 License

Licensed under the Apache License, Version 2.0.

Metadata

Release files for scopeforge 0.1.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for scopeforge 0.1.0
File Size Uploaded
scopeforge-0.1.0.tar.gz 199.7 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for scopeforge 0.1.0
File Interpreter ABI Platform
scopeforge-0.1.0-py3-none-any.whl Python 3 none any Details

Total release size: 407.8 kB

Release files / scopeforge-0.1.0.tar.gz

Download URL scopeforge-0.1.0.tar.gz
Size 199.7 kB
Tags Source
SHA-256 checksum
How to use checksums
f654181d2aa1cd581efa2c414ebaf2e9bc4a02cd2e0e6481714bcbb77d8bb101
BLAKE2b-256 checksum
How to use checksums
ca922e3a15b5d0a305cc00de6aa102751d22f63d28b8b118379ff8982303e913
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via uv/0.12.23 {"installer":{"name":"uv","version":"0.12.23","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}

Release files / scopeforge-0.1.0-py3-none-any.whl

Download URL scopeforge-0.1.0-py3-none-any.whl
Size 208.1 kB
Tags Python 3
SHA-256 checksum
How to use checksums
22af4dc24b691035929a84bb56eaa78a9cf2aeffb7f7d9dad28ea55fd161fcb8
BLAKE2b-256 checksum
How to use checksums
07b174762641a11761a2e2e2583bb508f580a61d1b271cfd7b9097e223defbad
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via uv/0.12.23 {"installer":{"name":"uv","version":"0.12.23","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}

Release history Release notifications | RSS feed

0.1.1

2 release files

This release

0.1.0 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page