One input, auto-routed
Point Argus at an MCP URL, a GitHub repository, an npm or PyPI package, a local script or a framework fixture, and it dispatches to the right target factory.
ArgusAutonomous Red-Team Assessment
Argus is an autonomous red team for AI systems. It engages MCP servers, agent frameworks and live endpoints with generic attack techniques, then confirms each finding against a baseline transcript using deterministic detectors.
Argus Core is MIT-licensed and installable today. The full eleven-agent kit is delivered as a Warden red-team engagement rather than as installable software.
SAST, DAST and network scanners test the infrastructure underneath an agent. None of them test the surface the agent itself introduces — the tools it can call, the content it will trust, and the instructions it will follow. Argus is complementary to those tools, not a replacement for them.
Argus attacks with generic techniques and records what actually happened, so a finding survives contact with the engineer who has to fix it.
Point Argus at an MCP URL, a GitHub repository, an npm or PyPI package, a local script or a framework fixture, and it dispatches to the right target factory.
Untrusted target processes run under Docker with capabilities dropped, no network, a read-only filesystem, an unprivileged user and a process cap.
A single gateway dispatches to OpenAI, Anthropic and Gemini with a dead-provider blacklist, so an engagement survives a provider outage mid-run.
Mutation may use a model. Scoring never does. Every verdict comes from a regex, shape or counter detector that you can read and re-run.
Findings ship as signed, reproducible bundles with the exact trigger, source and reason — suitable for a vulnerability disclosure submission.
A GitHub Action, a pre-commit hook and a webhook receiver mean the same engagement can gate a merge rather than sit in a quarterly report.
Every Argus finding is a claim an operator hands to someone's CISO or regulator, so the rules that keep findings honest are published rather than implied.
Methodology. These are engineering constraints in the Argus repository, not measured outcomes — the integrity contract is published in full at docs/NO_CHEATING.md and acceptance tests run real agents against real target fixtures rather than constructing findings by hand. Argus reports what a technique achieved against a specific target; it does not publish a portfolio-wide vulnerability rate, because that number would say more about the sample than about your estate.
Argus on GitHubRun the public core yourself, or have the team that wrote it run the full kit against your deployment.
MIT licensed
The public CLI. Self-sufficient for a focused engagement you run yourself.
The eleven-agent kit, the swarm correlation layer and a findings report, delivered by Odingard engineers.
Warden · By Odingard
Warden runs the full kit, interprets the findings against your obligations, and re-tests once the fix lands.
Install the core and test your own agents this afternoon, or have Warden run the full kit and hand you findings with the evidence attached.