The Hybrid Governance Security Engine for AI-built web applications.
Pairs the intelligence of your AI Agent with a deterministic Go CLI to enforce strict security boundaries and patch limits.
- What Is TorusGuard?
- Features
- Autonomous Architecture & Workflow
- Prerequisites
- Installation
- Usage
- Commands
- Project Structure
- Security Invariants & Rule Governance
- AI Agent Integration
- Verified Test Suite & Benchmarks
- Non-Negotiable Invariants
- Contributing
- License
- Documentation
TorusGuard is a zero-dependency, single-binary security engine that scans, hardens, and validates AI-generated codebases. It enforces 88 security rules across 22 architectural families and works across three unified operational modes (Tri-Mode Parity):
- Mode A: Terminal CLI (Go Binary) β A deterministic scanner and enforcer that runs in your terminal or CI/CD pipeline (
torusguard <command>). - Mode B: AI Chat Slash Commands β Integrates natively with Antigravity, Cursor, Claude Code, Windsurf, VS Code, and other AI coding assistants via slash commands (
/torusguard <command>). - Mode C: Native MCP Tools β Stdio Model Context Protocol (JSON-RPC 2.0) interface exposing autonomous security tools and living resources directly to AI agents.
TorusGuard ensures that the code your AI assistant writes is secure before it reaches production.
- 88 Security Rules across 22 families (Secrets, Auth, SQL Injection, Deserialization, Open Redirects, SSRF, CSRF, GraphQL, Supply Chain, Containers, Git History, ReDoS, AI & RAG, and more)
- Taint Analysis & Interprocedural Dataflow Engine β Cross-file, interprocedural taint flow tracking from untrusted sources to critical sinks across imports, modules, and call graphs
- 7-Signal Calibrated Confidence Scorer β Evidence-chain calibration combining rule severity, taint confirmation, taint depth, sanitizer absence, framework context, multi-line evidence, and persistent memory
- First-Principles Security Suite β Built-in native scanners for Dockerfile/Compose privilege bounds, Git commit log secret mining, exponential regex backtracking, and cross-tenant vector isolation
- Polyglot Parser & AST Walker β Tree-sitter powered AST traversal with unified CST nodes and symbol resolution across Go, JavaScript, TypeScript, and Python
- Incremental Hash Cache & Parallel Scanning β SHA-256 mtime incremental scan caching, process-pool parallelization, and continuous file-watcher debounce
- Line-Level Reflection Module β Semantic patch synthesis (
find_snippet/replace_snippet) that accurately replaces exact code blocks without brittle line-number offsets - 1/9th Token Bounded Context Extraction β AST context extraction (Β±3 lines) via
scanner.ExtractContextto keep review prompts hyper-efficient and prevent context saturation - Ponytail Protocol β Surgical patch bounds (β€35 additions, β€25 deletions) to prevent full-file rewrites
- Pre-Apply Snapshots β Automatic
.bakrollback snapshots before every code modification - SARIF v2.1.0 Export β Standards-compliant output for GitHub Advanced Security, VS Code, and other SARIF consumers
- Dark-Mode HTML Reports β Single-file visual posture dashboards
- Golden Fix Recipes β Persistent memory of verified security patterns for reuse
- SSRF Defense β Built-in private IP blocking and AWS metadata protection in the web validator
- Fail-Closed Cryptography β No fallback tokens; panics on entropy failure
- DoS Resilience β 10,000-file scan limit and 5-minute context timeout to prevent resource exhaustion
- 16+ Language Stack Detection β Go, Rust, Java, C#, PHP, Ruby, Kotlin, Elixir, Dart, Swift, Python, TypeScript, and more
- Multi-Modal Vision OCR β Scans architecture diagrams, mockups, and screenshots (
.png,.jpg,.webp) via Tesseract OCR to detect leaked keys, tokens, and credentials - Native MCP Server (Model Context Protocol) β Exposes standard JSON-RPC 2.0 stdio tools and resources for direct agent integration
- Tri-Mode Parity β Terminal CLI, AI Chat slash commands, and Native MCP Tools share identical governance workflows
TorusGuardβs static scanner and enforcement binary have been rigorously tested and confirmed compatible across 20 major technology stacks and frameworks:
| Ecosystem | Tested Frameworks & Runtimes |
|---|---|
| JavaScript / TypeScript | React, Next.js, Express, Vue, Angular, SvelteKit, NestJS |
| Python | Django, Flask, FastAPI, raw Python scripts |
| Go | Gin |
| Java / C# (.NET) | Spring Boot, ASP.NET Core, .NET Core Middleware |
| Ruby | Ruby on Rails, Sinatra |
| PHP | Laravel, Symfony |
| Rust | Actix Web |
TorusGuard uses a tri-track architecture where intelligence, deterministic enforcement, and agent tool execution are cleanly separated across three unified operational modes:
flowchart TD
%% =========================================================================
%% STAGE 1: TRI-MODE INGRESS GATEWAY
%% =========================================================================
subgraph IngressGateway["1. Unified Tri-Mode Ingress Gateway"]
direction LR
CLI["<b>Mode A: Terminal CLI</b><br/><code>torusguard <cmd></code><br/>25 Deterministic Commands"]
Chat["<b>Mode B: AI Chat Commands</b><br/><code>/torusguard <cmd></code><br/>Cursor • Claude • Windsurf"]
MCP["<b>Mode C: Native MCP Server</b><br/><code>torusguard_*</code> (13 Tools • 2 Resources)<br/>Stdio JSON-RPC 2.0 Protocol"]
end
%% =========================================================================
%% STAGE 2: CORE DISPATCHER & RUNTIME KERNEL
%% =========================================================================
Kernel["<b>TorusGuard Core Dispatcher & Runtime Kernel</b><br/><code>cmd/torusguard</code> (Single Standalone Go Binary)<br/>Command Parsing • Flag Evaluation (<code>--yes</code>, <code>--html</code>, <code>--rules</code>) • Sandbox Isolation"]
CLI -->|"Terminal Exec"| Kernel
Chat -->|"Slash Bridge"| Kernel
MCP -->|"Agent Tool Call"| Kernel
%% =========================================================================
%% STAGE 3: DETECTION & MULTI-MODAL SUITE
%% =========================================================================
subgraph DetectionSuite["2. Polyglot Static AST & Multi-Modal Detection Suite"]
direction TB
subgraph StaticGroup["Static Code & Dependency Analysis"]
direction LR
AST["<b>Polyglot AST & Taint Engine</b><br/>Tree-sitter • 88 Rules across 22 Families<br/>Go • TS/JS • Python • Java • C# • Rust"]
TGQL["<b>TG-QL Declarative AST DSL</b><br/>Custom YAML Pattern Queries<br/>Syntax Trees • Taint Sinks • Constraints"]
Reach["<b>Reachability & OpenVEX</b><br/>Callgraph Traversal • Reachable CVEs<br/>Zero Ineffective Dependency Alerts"]
end
subgraph DeepGroup["Forensics, RegEx & Vision OCR"]
direction LR
OCR["<b>Multi-Modal Vision OCR Engine</b><br/>Tesseract v5.4.0 • Leaked Secrets<br/>Architecture Diagrams • Screenshots"]
ReDoS["<b>Thompson NFA ReDoS Engine</b><br/>Polynomial & Exponential Exploder<br/>Catastrophic Backtracking Loops"]
GitMine["<b>Git History & Container Audit</b><br/>Commit Packfile Secret Mining<br/>Dockerfile Non-Root Enforcement"]
end
end
Kernel -->|"Scan Code & Dependencies"| StaticGroup
Kernel -->|"Analyze Visuals & Commits"| DeepGroup
%% =========================================================================
%% STAGE 4: CONSENSUS DELIBERATION & TRIAGE
%% =========================================================================
subgraph DeliberationTriage["3. Deliberation Tournament & Evidence Triage"]
direction TB
Tournament["<b>3-Perspective Deliberation Tournament</b><br/>Vulnerability Hunter vs. Devil's Advocate / Sanitizer Verifier vs. Ponytail Remediator<br/>Eliminates False Positives • Calibrated Confidence Scoring (0-100%)"]
PRGate{"<b>Differential PR Diff Gate</b><br/><code>torusguard review</code><br/>Incremental Git Diff Changes?"}
Tournament --> PRGate
end
StaticGroup -->|"Raw AST Findings"| Tournament
DeepGroup -->|"Extracted Secrets & Complexities"| Tournament
%% =========================================================================
%% STAGE 5: GOVERNED REMEDIATION & PONYTAIL LOOP
%% =========================================================================
subgraph GovernedRemediation["4. Governed Remediation Loop & Safety Guardrails (Ponytail Protocol)"]
direction TB
Harden["<b>Surgical Patch Formulation</b><br/>Semantic Line Snippet Replacement<br/>Strict Line Budget: ≤35 Additions • ≤25 Deletions"]
BoundsCheck{"<b>Ponytail Bounds Check</b><br/>Exceeds 35 Add / 25 Del?"}
RejectDiff["<b>Diff Rejected</b><br/>Excess Churn Detected<br/>Prompt AI for Minimal Snippet"]
SnapshotStore[("<b>Pre-Apply Snapshot Store</b><br/><code>.torusguard/snapshots/<run_id>/</code><br/>Byte-for-Byte Rollback Backup")]
HumanGate{"<b>Human Gate Authorization</b><br/>Explicit <code>--yes</code> or Interactive Confirmation"}
UserAbort["<b>Operation Aborted</b><br/>Zero Files Touched • Safe Exit"]
ApplyPatch["<b>Atomic Patch Application</b><br/>Apply Unified Surgical Diff to Disk"]
RecheckGate{"<b>Differential Recheck Engine</b><br/><code>torusguard recheck</code><br/>Fix Closed with Zero Regressions?"}
RollbackExec["<b>Auto-Rollback Triggered!</b><br/>Instant Restoration from Snapshot<br/>Quarantine Candidate Patch"]
Harden --> BoundsCheck
BoundsCheck -->|"Violation"| RejectDiff
RejectDiff -.->|"Re-prompt AI"| Harden
BoundsCheck -->|"Pass (Within Bounds)"| SnapshotStore
SnapshotStore --> HumanGate
HumanGate -->|"Denied"| UserAbort
HumanGate -->|"Approved"| ApplyPatch
ApplyPatch --> RecheckGate
RecheckGate -->|"Regressions"| RollbackExec
RollbackExec -.->|"Restore Clean State"| SnapshotStore
end
PRGate -->|"Target Findings"| Harden
%% =========================================================================
%% STAGE 6: LIVING SECURITY LEDGER & ENTERPRISE OUTPUTS
%% =========================================================================
subgraph EnterpriseDeliverables["5. Living Security Ledger & Enterprise Deliverables"]
direction TB
Ledger[("<b>Living Security Ledger</b><br/><code>security_report.md</code><br/>Synchronized Single Source of Truth • Status: RESOLVED π’")]
subgraph DeliverableOutputs["Executive Reports & Verified Memory"]
direction LR
ThreatModel["<b>STRIDE Threat Model</b><br/><code>SECURITY_THREAT_MODEL.md</code><br/>DFD Architecture Diagrams"]
SARIF["<b>OASIS SARIF v2.1.0</b><br/>GitHub Advanced Security<br/>CI/CD Security Center"]
HTMLReport["<b>Executive Dashboard</b><br/>Single-File HTML Report<br/>Interactive Posture Heatmap"]
GoldenRecipes[("<b>Golden Fix Memory</b><br/><code>.torusguard/recipes/</code><br/>Verified Distilled Fixes")]
end
Ledger --> DeliverableOutputs
end
RecheckGate -->|"Fix Confirmed (Clean Closure)"| Ledger
%% =========================================================================
%% STYLING AND THEME (Modern Dark Cyber Palette)
%% =========================================================================
classDef ingressStyle fill:#0f172a,stroke:#38bdf8,stroke-width:2px,color:#f8fafc;
classDef routerStyle fill:#1e1b4b,stroke:#6366f1,stroke-width:2px,color:#f8fafc;
classDef scannerStyle fill:#022c22,stroke:#10b981,stroke-width:2px,color:#f8fafc;
classDef tourneyStyle fill:#2e1065,stroke:#a855f7,stroke-width:2px,color:#f8fafc;
classDef gateStyle fill:#451a03,stroke:#f59e0b,stroke-width:2px,color:#fef3c7;
classDef rejectStyle fill:#450a0a,stroke:#ef4444,stroke-width:2px,color:#fee2e2;
classDef actionStyle fill:#064e3b,stroke:#34d399,stroke-width:2px,color:#f8fafc;
classDef dbStyle fill:#1e293b,stroke:#94a3b8,stroke-width:2px,color:#f8fafc;
classDef ledgerStyle fill:#172554,stroke:#3b82f6,stroke-width:2px,color:#eff6ff;
classDef outputStyle fill:#042f2e,stroke:#14b8a6,stroke-width:2px,color:#f0fdfa;
class CLI,Chat,MCP ingressStyle;
class Kernel routerStyle;
class AST,TGQL,Reach,OCR,ReDoS,GitMine scannerStyle;
class Tournament tourneyStyle;
class PRGate,BoundsCheck,HumanGate,RecheckGate gateStyle;
class RejectDiff,UserAbort,RollbackExec rejectStyle;
class Harden,ApplyPatch actionStyle;
class SnapshotStore,GoldenRecipes dbStyle;
class Ledger ledgerStyle;
class ThreatModel,SARIF,HTMLReport outputStyle;
π Interactive Architecture Visualizations:
- System Architecture Diagram (HTML) β Dynamic zoomable/pannable pipeline with dark/light themes, live view switching (Tri-Mode Ingress, AST Engine, Multi-Modal Vision OCR, Ponytail Bounds, Fail-Closed Recovery), and SVG/PNG export.
- Governed Remediation Workflow (HTML) β Step-by-step visual trace of the 7-stage remediation loop, safety gates, and automatic rollback path.
Key design decisions:
- Tri-Mode Parity: The CLI (Mode A), Chat Slash Commands (Mode B), and Native MCP Tools (Mode C) share the exact same underlying governance and validation rules.
- Multi-Modal Vision OCR: Images, architecture diagrams, and screenshots are automatically scanned for leaked secrets using Tesseract OCR, bounded by strict 10MB memory safety limits.
- Deterministic Enforcement: The Go binary handles all deterministic operations (AST scanning, bounds checking, snapshotting, reporting).
- AI Intelligence: The AI agent handles intelligence-requiring tasks (patch generation, root-cause analysis, remediation formulation).
- Living Ground Truth: All modes synchronize with
security_report.mdto prevent finding drift or hallucination. - Zero-Bypass Guardrails: Neither human nor AI can bypass Ponytail Protocol bounds (β€35 additions, β€25 deletions) or the Human Gate before modifying code.
- Go 1.25+ (to build from source)
- Git (for
git applypatch operations) - Node.js 18+ (for npm package installation)
TorusGuard can be run without installation via npx, installed globally or locally via npm, compiled from source with go build, or installed via go install.
| Option | Method | Best For | Dedicated Guide |
|---|---|---|---|
| Option 1 | npm & npx | Node.js developers, zero-install CLI, CI/CD | π Option 1 Guide |
| Option 2 | Build from Source | Contributors, custom rules, Go development | π Option 2 Guide |
| Option 3 | Go Install | Go projects, single-binary, zero Node.js/npm | π Option 3 Guide |
Run directly without installing any packages globally or locally:
npx torusguard initTip: Use npx torusguard@latest init to guarantee the freshest release.
npm install -g torusguard
torusguard initnpm install -D torusguardπ‘ Using TorusGuard after
npm install torusguard:
TorusGuard is a CLI security engine, not an importable JavaScript library. When installed locally, the binary resides innode_modules/.bin/torusguard.
You can run it via:
npx torusguard init(npx automatically uses your localnode_modulesbinary)- Adding
"security:audit": "torusguard audit"to yourpackage.jsonscripts (npm run security:audit)- Direct path:
./node_modules/.bin/torusguard audit
π Read the Full Option 1 (npm & npx) Dedicated Guide β
git clone https://github.com/githubmofo/TorusGuard.git
cd TorusGuard
go build -o torusguard ./cmd/torusguardOn Windows:
go build -o torusguard.exe ./cmd/torusguardRun directly:
./torusguard init
./torusguard auditπ Read the Full Option 2 (Build from Source) Dedicated Guide β
Install directly into $GOPATH/bin:
go install github.com/githubmofo/TorusGuard/cmd/torusguard@latestVerify and run:
torusguard --version
torusguard initπ Read the Full Option 3 (Go Install) Dedicated Guide β
# Initialize TorusGuard in your project
torusguard init
# Run a full security audit
torusguard audit
# Check workspace posture
torusguard status
# Generate an HTML report
torusguard report --html
# Generate a SARIF report
torusguard report --sarif# Validate a candidate patch against Ponytail bounds
torusguard harden fix.patch
# Apply the patch with rollback snapshot (requires --yes for Human Gate)
torusguard apply --yes fix.patch
# Verify the fix was applied correctly
torusguard recheck
# Roll back if something went wrong
torusguard rollback# Generate authorization token for runtime probing
torusguard authorize
# Probe a running application for security headers
torusguard web-validate
# Send bounded inert payloads to test input handling
torusguard exploit-check| Command | Description |
|---|---|
init |
Scaffold .torusguard/ workspace, detect stack, activate rules |
status |
Diagnostic overview of posture, stack, and active rules |
audit |
Static heuristic security scan against active TG-* rules |
review |
Differential PR and Git diff incremental security review |
threatmodel |
Synthesize architectural STRIDE threat model & Mermaid DFDs |
benchmark |
Run SecurityReviewBench precision & recall evaluation suite |
verify |
Live disk line match audit and evidence sufficiency check |
harden |
Validate patches against Ponytail Protocol bounds |
apply |
Apply patches with pre-apply .bak rollback snapshots |
rollback |
Instant restoration from pre-apply snapshots |
recheck |
Differential re-scan on modified files |
report |
Generate HTML (--html) or SARIF (--sarif) posture reports |
recipes |
Manage the Golden Fix recipe library |
authorize |
Generate cryptographic auth tokens for runtime probing |
web-validate |
Authorized HTTP probing with X-TorusGuard-Audit headers |
exploit-check |
Bounded single-step exploitability confirmation |
ocr-scan |
Run Tesseract OCR secret scan on images/diagrams (<10MB) |
container |
Audit Dockerfile, compose, and container configurations |
git-mine |
Mine git commit history for leaked secrets & creds |
redos |
Analyze regex patterns for catastrophic backtracking |
ai-guard |
Scan AI/LLM code for prompt injection & RAG flaws |
mcp |
Run native Model Context Protocol (MCP) server over stdio |
full |
Master 7-stage closed-loop security governance pipeline |
update |
Self-update the TorusGuard engine |
help |
Show interactive command guide |
TorusGuard/
βββ cmd/torusguard/ # CLI entry point, command router & MCP server
β βββ main.go # CLI command router
β βββ mcp.go # Model Context Protocol (MCP) JSON-RPC 2.0 stdio server
βββ internal/
β βββ apply/ # Patch application + pre-apply snapshot engine
β βββ harden/ # Ponytail Protocol bounds enforcement & line-level reflection
β β βββ patch.go # Ponytail Protocol bounds verification
β β βββ reflection.go # Line-level reflection & semantic replacement
β βββ memory/ # Golden Fix recipe persistence
β βββ recheck/ # Differential re-scan engine
β βββ report/ # SARIF v2.1.0 + dark-mode HTML generators
β βββ rules/ # TG-* rule catalog loader
β βββ scanner/ # Heuristic polyglot security scanner + Tesseract OCR
β β βββ scanner.go # Polyglot code AST & heuristic scanner
β β βββ ocr.go # Multi-modal Vision OCR secret detection
β βββ termui/ # 75-column terminal UI formatting
β βββ validate/ # authorize / web-validate / exploit-check / verify
β βββ workspace/ # init + polyglot stack detection
βββ .torusguard/ # Generated workspace state
β βββ rules/ # Active security rule definitions
β βββ schemas/ # JSON schemas for findings, recipes, etc.
β βββ memory/ # Persistent security context
β βββ snapshots/ # Pre-apply rollback backups
βββ docs/ # Architecture and usage documentation
βββ bin/ # npm package CLI wrapper
βββ go.mod # Go module (github.com/torusguard/torusguard)
βββ package.json # npm package definition
TorusGuard enforces 88 security invariants across 22 architectural families covering Secrets, Authentication, Multi-Tenant Database Isolation, Input Sanitization, Rate Limiting, AI Agent Prompt Injection, SSRF, Webhooks, WebSockets, CSRF, GraphQL, Supply Chain, Business Logic, Cache Poisoning, Client Bundles, Platform Headers, Polyglot Bypasses, Edge Timeouts, Container & Docker Safety, Git History Secret Mining, Regular Expression Backtracking (ReDoS), and Vector Database RAG Isolation.
π Full Rules Catalog & Invariants:
The complete rulebook with formal invariant definitions, severity scores, and testing signatures is maintained inAGENTS.mdand therules/directory.
You can also explore verified Golden Fix patterns anytime viatorusguard recipesor stream the live catalog over MCP viatorusguard://rules_catalog.
TorusGuard works natively inside AI coding assistants. Add the configuration file to your project root and your AI agent automatically enforces TorusGuard security invariants.
| Agent | Configuration File | Status |
|---|---|---|
| Antigravity (Gemini) | AGENTS.md |
β Full support |
| Claude Code | CLAUDE.md |
β Full support |
| Cursor | .cursorrules |
β Full support |
| Windsurf | .windsurfrules |
β Full support |
| VS Code Copilot | AGENTS.md |
β Full support |
| Kimi | SKILL.md |
β Full support |
/torusguard init # Initialize workspace
/torusguard audit # Run security + OCR scan; sync security_report.md
/torusguard ocr-scan # Scan diagram or image assets for leaked credentials
/torusguard harden # Formulate remediation patches
/torusguard apply # Apply patches with Human Gate
/torusguard recheck # Verify fix closure
/torusguard report # Generate posture report
/torusguard status # Check posture overview
/torusguard full # End-to-end 7-stage pipeline
When configured with .agents/mcp_config.json or mcp_config.json, AI coding agents gain native tool calling (13 Tools & 2 Resources):
torusguard_audit: Deep static AST scan + Vision OCR; writessecurity_report.mdtorusguard_ocr_scan: Dedicated image credential analysis via Tesseract (5-10MB bounds)torusguard_container: Audits container files for root execution, docker socket exposure, and privileged modetorusguard_git_mine: Mines git commit history and config for leaked credentials and tokenstorusguard_redos: Analyzes regex patterns for catastrophic exponential backtrackingtorusguard_ai_guard: Audits AI agent prompt templates, tool registries, and vector database queriestorusguard_verify: Asserts evidence sufficiency & line-shift invariant fingerprint matchestorusguard_harden: Validates remediation diff against Ponytail Protocol boundstorusguard_recheck: Differential re-scan confirming fix closuretorusguard_review: Differential PR and Git diff incremental review; gate decisionstorusguard_threatmodel: Synthesizes STRIDE threat model & Mermaid DFDs (SECURITY_THREAT_MODEL.md)torusguard_benchmark: Runs SecurityReviewBench self-evaluating precision & recall suitetorusguard_status: Workspace posture and tech stack inspectiontorusguard://security_report: MCP Resource reading the living security reporttorusguard://rules_catalog: MCP Resource exploring verified rules catalog & Golden Fix patterns
TorusGuard undergoes rigorous automated multi-tier testing across polyglot stacks, multi-modal vision assets, and agent communication protocols:
| Testing Tier | Scope & Target Stacks | Pass Rate | Verified Capabilities |
|---|---|---|---|
| Go Engine & Unit Tests | cmd/torusguard, internal/scanner, internal/* |
100% Passing | Deterministic AST matching, 88 canonical rule patterns, JSON-RPC 2.0 MCP protocol (133/133 harness tests passing). |
| Mass Polyglot Benchmarks | 20 Enterprise Tech Stacks (Go, Python, Java, Node, Rust, PHP, C#, Ruby, Svelte, Vue, Angular) | 20/20 Passed | Framework auto-profiling, heuristic AST analysis, finding deduplication. |
| Unseen Tri-Mode Validation | 6 Unseen Framework Ecosystems (SvelteKit 2 + Bun, FastAPI AI RAG, DevOps Git Mine, OCR Asset Suite, Kotlin Ktor, Laravel 11) | 6/6 Passed (100%) | Mode A (CLI) + Mode B (Slash Commands) + Mode C (Native MCP Tools) across 18/18 canonical skills with automated sandbox cleanup. |
| Tri-Mode & Vision E2E | 16 Diverse Framework Repos (React, Next.js, Express, Django, FastAPI, Spring Boot, etc.) | 16/16 Passed | Mode A (CLI) + Mode B (Slash Commands) + Mode C (Native MCP Tools) + Multi-Modal Vision OCR. |
| Multi-Modal Vision OCR | Diagram & Image assets (.png, .jpg, .webp) via Tesseract v5.4.0 |
100% Recall | Secrets detection (TG-SEC-001 - TG-SEC-007), 10MB DoS bounding, OCR character substitution tolerance. |
| Ponytail Churn Limits | Surgical patch validation across all 88 rules | Bounded | Line bounds (β€35 additions, β€25 deletions), zero-bypass verification (TG-DIFF-001). |
All test environments are completely sandboxed, verified with byte-for-byte assertions, and cleaned up automatically.
- Browser-Code Truth: Never expose secrets in frontend bundles.
- Multi-Tenant Isolation: Always scope DB lookups by tenant/user ownership.
- Ponytail Churn Bounds: Patches β€35 additions, β€25 deletions. No full-file rewrites.
- Zero Security Bypasses: Never insert
# nosec,verify=False,InsecureSkipVerify: true. - Snapshots Before Edits: Mandatory
.bakbackup before every modification. - Fail-Closed Cryptography: Panic on entropy failure. No fallback tokens.
- SSRF Boundary Enforcement: Block private IPs and cloud metadata before probing.
- DoS Resilience: 10,000-file max, 5-minute timeout.
- Fork the repository
- Create a feature branch:
git checkout -b feat/your-feature - Commit changes:
git commit -m "feat: add your feature" - Push to branch:
git push origin feat/your-feature - Open a Pull Request
See CONTRIBUTING.md for detailed guidelines and CODE_OF_CONDUCT.md for community standards.
MIT Β© 2026 Jenish Lad
| Document | Description |
|---|---|
| Architecture | System design and module relationships |
| Security Architecture | Threat model and security design |
| Detection Engine | Scanner internals and rule matching |
| API Specification | CLI argument specification |
| Security Philosophy | Core design principles |
| Testing Playbook | Testing guide and CI integration |
| Demo Guide | Quick start and full lifecycle demo |
| Roadmap | Feature roadmap and release planning |
| Unseen Stacks Validation Report | Tri-mode validation across 6 unseen ecosystems & vision OCR |
| SECURITY.md | Vulnerability disclosure policy |
| CHANGELOG.md | Version history and release notes |
