XORCISE — evaluate cyber AI agents.
Project description
Quickstart · Output · Agents · Missions · Open source · Website · Docs · Contributing · Security
Run your cyber-AI agent against a real mission. Watch everything it does. Grade the evidence.
AI can take action. It cannot bear consequences.
A benchmark score tells you an agent finished. It says nothing about the destructive commands it tried on the way there. XORCISE runs the agent against a live target inside a contained environment, records every command, tool call and dead end as OpenTelemetry evidence, and grades that evidence against the mission's own criteria.
Trust is not declared. It is demonstrated.
Quickstart
Tested on Ubuntu. Needs Python 3.12+ and Docker Engine.
pip install xorcise
xorcise up # boots the stack, prints the console URL
xorcise agent register --name my-agent
xorcise mission list
xorcise run create --agent my-agent --mission demo
xorcise run prompt <run_id> # the ready-to-paste connect prompt
xorcise run status <run_id> # score, breakdown, evidence
xorcise doctor checks the host first. xorcise down stops it all. No Docker on the box?
xorcise up --stub is the self-contained demo. xorcise --help has the rest, and
docs.xorcise.ai walks through a first run end to end.
Prefer to work from source? See Contributing → Setup.
What comes out
| Live trace | every command, tool call and message, streaming into the console as it happens |
| Score | deterministic checks plus a bring-your-own-model judge |
| Report | the full run record, exportable — Markdown, HTML, JSONL |
| Leaderboard | agents ranked across recorded results |
Every run gets its own private network and a fresh environment, created for the run and destroyed after it. An agent under evaluation cannot reach the host, or another run.
Bring your agent
XORCISE evaluates the agent you already use.
| OpenHands | full trace + tool-call capture |
| Claude Code | via OTLP telemetry |
| Codex CLI | via OTLP telemetry |
| Anything custom | register it, drive it with the connect prompt, submit over REST |
Activity is normalised into one event model, so the trace, the grading and the report read the same whichever harness produced the run.
Missions
A mission is a self-contained target: services, a network, and the criteria an agent is graded against. Packaged as bundles, pulled on demand.
Missions are deliberately vulnerable — SQL injection, IDOR, network pivots. That is the point: they exist so an agent has something real to find.
Run XORCISE on infrastructure you are willing to lose — a dedicated VM or an isolated cloud environment, never a workstation holding credentials you care about. It executes untrusted agent code against vulnerable targets by design.
Open source
XORCISE goes public in parts, not whole. This repository is the engine — the CLI, harness adapters, isolation, grading and console — under Apache-2.0, with issues and pull requests open.
The evaluation technology is open source. The commercial layer — managed deployment, runtime, command and sovereign hosting — is not. The agent skills and the documentation source are published separately as they are readied.
Documentation & help
| xorcise.ai | the project website — what XORCISE is and who it is for |
| Documentation | first run, missions, grading, traces, the full CLI and API reference |
| Contributing | dev setup, the test lanes, the PR process, versioning |
| Security | what's in scope, and how to report privately |
| Maintainers · Code of Conduct | who to ask, and how we work |
Found a vulnerability? Do not open a public issue — report it privately. Flaws in the harness, the isolation boundary or the supply chain are in scope; flaws inside a mission are the content.
License
Apache-2.0 © The XORCISE Authors
XORCISE.AI — Trust Evidence, not Claims.
Project details
Release history Release notifications | RSS feed
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file xorcise-0.1.0.tar.gz.
File metadata
- Download URL: xorcise-0.1.0.tar.gz
- Upload date:
- Size: 1.5 MB
- Tags: Source
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/6.1.0 CPython/3.13.14
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
288f5febee94995babc9546c9931683d790f6e927c4805642f7726818dc22b4e
|
|
| MD5 |
07535d3a9d8ab551e957575dfb850d0c
|
|
| BLAKE2b-256 |
2e42fa8ba5abd52c183b5aa7be06411e1ff031527f2e9e785e2a24098ddf2e0b
|
Provenance
The following attestation bundles were made for xorcise-0.1.0.tar.gz:
Publisher:
release.yml on xorcise-ai/xorcise
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
xorcise-0.1.0.tar.gz -
Subject digest:
288f5febee94995babc9546c9931683d790f6e927c4805642f7726818dc22b4e - Sigstore transparency entry: 2332572377
- Sigstore integration time:
-
Permalink:
xorcise-ai/xorcise@f4dd19fb0207e26a742fc3808ce7642c1ce76864 -
Branch / Tag:
refs/tags/v0.1.0 - Owner: https://github.com/xorcise-ai
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
release.yml@f4dd19fb0207e26a742fc3808ce7642c1ce76864 -
Trigger Event:
push
-
Statement type:
File details
Details for the file xorcise-0.1.0-py3-none-any.whl.
File metadata
- Download URL: xorcise-0.1.0-py3-none-any.whl
- Upload date:
- Size: 1.1 MB
- Tags: Python 3
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/6.1.0 CPython/3.13.14
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
67d7c6f76c088dc05ab4c8fa59a7215f15f20596566c83318bf98dbb389c03e3
|
|
| MD5 |
9befe6ddcb7b47b42c5a16bd3274bfa2
|
|
| BLAKE2b-256 |
d7f4b0ab23875bf7a2cce1917a79f0163713b941b347e96df39db4eb35042b24
|
Provenance
The following attestation bundles were made for xorcise-0.1.0-py3-none-any.whl:
Publisher:
release.yml on xorcise-ai/xorcise
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
xorcise-0.1.0-py3-none-any.whl -
Subject digest:
67d7c6f76c088dc05ab4c8fa59a7215f15f20596566c83318bf98dbb389c03e3 - Sigstore transparency entry: 2332572384
- Sigstore integration time:
-
Permalink:
xorcise-ai/xorcise@f4dd19fb0207e26a742fc3808ce7642c1ce76864 -
Branch / Tag:
refs/tags/v0.1.0 - Owner: https://github.com/xorcise-ai
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
release.yml@f4dd19fb0207e26a742fc3808ce7642c1ce76864 -
Trigger Event:
push
-
Statement type: