0sec
Health Uyari
- License — License: NOASSERTION
- Description — Repository has a description
- Active repo — Last push 0 days ago
- Low visibility — Only 5 GitHub stars
Code Basarisiz
- rm -rf — Recursive force deletion command in .github/workflows/release-verify.yml
Permissions Gecti
- Permissions — No dangerous permissions requested
Bu listing icin henuz AI raporu yok.
The open cybersecurity harness - by the Swiss Applied AI Cybersecurity Research Lab.
Your open-source AI cybersecurity agent.
It hacks, proves the problem, and writes the fix. Multi-model, multi-agent, but most importantly: yours.
🇨🇭 Swiss Applied AI Cybersecurity Research Lab · 0.security
Beta — in active development; interfaces may change. See Honest limitations.
Install
curl -fsSL https://raw.githubusercontent.com/0sec-labs/0sec/main/install.sh | bash
0 --help
Verified release binary (SHA-256 checked) → ~/.0sec/bin. macOS (Apple Silicon) and Linux (x64/arm64); Windows: 0sec-windows-x64.exe from the release; Docker: ghcr.io/0sec-labs/0sec:latest. Not on npm.
Quick start
# 1. say what you're allowed to touch
echo '{ "in_scope": ["example.com"] }' > scope.json
export ANTHROPIC_API_KEY=... # or OpenAI, Azure, OpenRouter, Ollama, …
# 2. scan a live target (out-of-scope requests are refused)
0 scan --target https://example.com --scope ./scope.json
# 3. or review code, audit a package, open the console
0 review ./my-app # source review
0 audit lodash # npm / pypi / cargo / oci package
0 console --scope ./scope.json # interactive; type / for commands
What it covers
Most tools stop at the app. 0sec goes all the way down.
| Layer | Finds |
|---|---|
| Web apps | SQLi, IDOR, XSS, SSRF, auth bypass |
| APIs | tenant isolation, BOLA, business-logic abuse |
| AI & LLMs | prompt injection, jailbreaks, MCP tool abuse |
| Source code | injection, auth, deserialization, memory safety |
| Dependencies | supply chain, malicious packages, CVE replay |
| Network / identity | AD, cloud, federation (read-only, offline) |
| Runtime / OS / kernel | container escape, privesc, 0-day hunt |
| Compiled binaries | no source → 0verse |
Commands
| Task | Commands |
|---|---|
| Pentest web / AI-LLM / MCP | scan, eval, agent-assure |
| Review source / packages / kernel | review, file-review, deep-review, audit |
| Recon an attack surface | recon, js-recon, npm-discovery, intel |
| Hunt a bug class / kernel variants | hunt, kernel, cve |
| Work with evidence | findings, history, resume, replay, verify, disclose |
| Generate & re-test a fix | fix |
| Identity / AD (read-only) | identity, adgraph, entragraph |
| Integrate | mcp-server, console, tui, dashboard |
Run 0 --help for the rest. Full docs: docs.0.security.

The interactive console — / opens the command palette.
How it works
It proves the bug before it reports it.
- Free-form agents, hard guardrails. Models decide what to probe; turn budgets, loop detection, and scope-on-every-call keep them in line.
- Reproduce before trust. A blind agent re-exploits each finding from the PoC alone. What it can't reproduce is dropped.
- Triage before verify. Class oracles and a second scanner cut noise before the expensive step.
- Bring your own model. Anthropic, OpenAI, Azure, OpenRouter, or local Ollama — you hold the key.
Every run keeps its own evidence under ~/.0sec/runs/<id>/, so you can resume, replay, or disclose it later.

Blind verification — every finding is re-exploited before it ships.
Track record
0sec has landed real, maintainer-reviewed fixes in the mainline Linux kernel and other open source. The verified list lives at 0.security. Benchmarks are secondary evidence — caveats in the benchmark docs.
Supported by
With special thanks to the startup and research programs supporting our work:
Honest limitations
- Kernel/IOKit findings stay hypotheses until a real oracle reproduces them (the
linux-kernelprofile is static). - Verification depth varies:
verificationSpeccovers file/diff predicates; the replay runner is local-shell only (Docker/QEMU are stubs). - The false-positive-moat layers are off by default and slice-dependent.
- Benchmarks are single-model/config/trial; the 10/10 AI-suite is self-authored, not independent.
fixis narrow: source-only, single-file, ≤3 attempts.- By design, never: network sweeps, credential spraying, persistence/C2, or stealth.
Build from source
git clone https://github.com/0sec-labs/0sec.git && cd 0sec
corepack enable && pnpm install --frozen-lockfile && pnpm build && node dist/0sec.js --help
Contributing & security
See CONTRIBUTING.md — synthetic or authorized targets only. Report vulnerabilities privately via SECURITY.md ([email protected]), not public issues.
License
Dual-licensed MIT OR Apache-2.0 — see LICENSE / LICENSE-MIT. © 2026 0sec Labs.
Yorumlar (0)
Yorum birakmak icin giris yap.
Yorum birakSonuc bulunamadi