Skip to content

About

Autonomous Security Guardrails & Governed Remediation for AI-Built Apps. Tri-Mode Parity (CLI, Chat Slash Commands, Native MCP Server), First-Principles Security Suite, Multi-Modal Vision OCR, 86 Rules across 22 Families & Ponytail Patch Bounds.

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

1 star

Watchers

0 watching

Forks

Latest commit

Β 

History

126 Commits

Folders and files

NameName
Last commit message
Last commit date
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 

Repository files navigation

TorusGuard Logo

TorusGuard

The Hybrid Governance Security Engine for AI-built web applications.
Pairs the intelligence of your AI Agent with a deterministic Go CLI to enforce strict security boundaries and patch limits.

License: MIT Version npm: v2.1.3 Privacy: Local First Dependencies: Zero SARIF OWASP

Unit Tests: 100% Passing Polyglot Tests: 36/36 Repos Passed Tri-Mode Validation: 6/6 Unseen Stacks Passed Tri-Mode E2E: 16/16 Verified Vision OCR: Tested & Verified Rules: 88/88 Verified

Tri-Mode Parity Go Node.js Python TypeScript Rust


Table of Contents


What Is TorusGuard?

TorusGuard is a zero-dependency, single-binary security engine that scans, hardens, and validates AI-generated codebases. It enforces 88 security rules across 22 architectural families and works across three unified operational modes (Tri-Mode Parity):

  • Mode A: Terminal CLI (Go Binary) β€” A deterministic scanner and enforcer that runs in your terminal or CI/CD pipeline (torusguard <command>).
  • Mode B: AI Chat Slash Commands β€” Integrates natively with Antigravity, Cursor, Claude Code, Windsurf, VS Code, and other AI coding assistants via slash commands (/torusguard <command>).
  • Mode C: Native MCP Tools β€” Stdio Model Context Protocol (JSON-RPC 2.0) interface exposing autonomous security tools and living resources directly to AI agents.

TorusGuard ensures that the code your AI assistant writes is secure before it reaches production.


✨ Features

  • 88 Security Rules across 22 families (Secrets, Auth, SQL Injection, Deserialization, Open Redirects, SSRF, CSRF, GraphQL, Supply Chain, Containers, Git History, ReDoS, AI & RAG, and more)
  • Taint Analysis & Interprocedural Dataflow Engine β€” Cross-file, interprocedural taint flow tracking from untrusted sources to critical sinks across imports, modules, and call graphs
  • 7-Signal Calibrated Confidence Scorer β€” Evidence-chain calibration combining rule severity, taint confirmation, taint depth, sanitizer absence, framework context, multi-line evidence, and persistent memory
  • First-Principles Security Suite β€” Built-in native scanners for Dockerfile/Compose privilege bounds, Git commit log secret mining, exponential regex backtracking, and cross-tenant vector isolation
  • Polyglot Parser & AST Walker β€” Tree-sitter powered AST traversal with unified CST nodes and symbol resolution across Go, JavaScript, TypeScript, and Python
  • Incremental Hash Cache & Parallel Scanning β€” SHA-256 mtime incremental scan caching, process-pool parallelization, and continuous file-watcher debounce
  • Line-Level Reflection Module β€” Semantic patch synthesis (find_snippet / replace_snippet) that accurately replaces exact code blocks without brittle line-number offsets
  • 1/9th Token Bounded Context Extraction β€” AST context extraction (Β±3 lines) via scanner.ExtractContext to keep review prompts hyper-efficient and prevent context saturation
  • Ponytail Protocol β€” Surgical patch bounds (≀35 additions, ≀25 deletions) to prevent full-file rewrites
  • Pre-Apply Snapshots β€” Automatic .bak rollback snapshots before every code modification
  • SARIF v2.1.0 Export β€” Standards-compliant output for GitHub Advanced Security, VS Code, and other SARIF consumers
  • Dark-Mode HTML Reports β€” Single-file visual posture dashboards
  • Golden Fix Recipes β€” Persistent memory of verified security patterns for reuse
  • SSRF Defense β€” Built-in private IP blocking and AWS metadata protection in the web validator
  • Fail-Closed Cryptography β€” No fallback tokens; panics on entropy failure
  • DoS Resilience β€” 10,000-file scan limit and 5-minute context timeout to prevent resource exhaustion
  • 16+ Language Stack Detection β€” Go, Rust, Java, C#, PHP, Ruby, Kotlin, Elixir, Dart, Swift, Python, TypeScript, and more
  • Multi-Modal Vision OCR β€” Scans architecture diagrams, mockups, and screenshots (.png, .jpg, .webp) via Tesseract OCR to detect leaked keys, tokens, and credentials
  • Native MCP Server (Model Context Protocol) β€” Exposes standard JSON-RPC 2.0 stdio tools and resources for direct agent integration
  • Tri-Mode Parity β€” Terminal CLI, AI Chat slash commands, and Native MCP Tools share identical governance workflows

πŸ§ͺ Proven Compatibility

TorusGuard’s static scanner and enforcement binary have been rigorously tested and confirmed compatible across 20 major technology stacks and frameworks:

Ecosystem Tested Frameworks & Runtimes
JavaScript / TypeScript React, Next.js, Express, Vue, Angular, SvelteKit, NestJS
Python Django, Flask, FastAPI, raw Python scripts
Go Gin
Java / C# (.NET) Spring Boot, ASP.NET Core, .NET Core Middleware
Ruby Ruby on Rails, Sinatra
PHP Laravel, Symfony
Rust Actix Web

πŸ—οΈ Autonomous Architecture & Workflow

TorusGuard uses a tri-track architecture where intelligence, deterministic enforcement, and agent tool execution are cleanly separated across three unified operational modes:

flowchart TD
    %% =========================================================================
    %% STAGE 1: TRI-MODE INGRESS GATEWAY
    %% =========================================================================
    subgraph IngressGateway["1. Unified Tri-Mode Ingress Gateway"]
        direction LR
        CLI["<b>Mode A: Terminal CLI</b><br/><code>torusguard &lt;cmd&gt;</code><br/>25 Deterministic Commands"]
        Chat["<b>Mode B: AI Chat Commands</b><br/><code>/torusguard &lt;cmd&gt;</code><br/>Cursor &bull; Claude &bull; Windsurf"]
        MCP["<b>Mode C: Native MCP Server</b><br/><code>torusguard_*</code> (13 Tools &bull; 2 Resources)<br/>Stdio JSON-RPC 2.0 Protocol"]
    end

    %% =========================================================================
    %% STAGE 2: CORE DISPATCHER & RUNTIME KERNEL
    %% =========================================================================
    Kernel["<b>TorusGuard Core Dispatcher &amp; Runtime Kernel</b><br/><code>cmd/torusguard</code> (Single Standalone Go Binary)<br/>Command Parsing &bull; Flag Evaluation (<code>--yes</code>, <code>--html</code>, <code>--rules</code>) &bull; Sandbox Isolation"]

    CLI -->|"Terminal Exec"| Kernel
    Chat -->|"Slash Bridge"| Kernel
    MCP -->|"Agent Tool Call"| Kernel

    %% =========================================================================
    %% STAGE 3: DETECTION & MULTI-MODAL SUITE
    %% =========================================================================
    subgraph DetectionSuite["2. Polyglot Static AST &amp; Multi-Modal Detection Suite"]
        direction TB
        subgraph StaticGroup["Static Code &amp; Dependency Analysis"]
            direction LR
            AST["<b>Polyglot AST &amp; Taint Engine</b><br/>Tree-sitter &bull; 88 Rules across 22 Families<br/>Go &bull; TS/JS &bull; Python &bull; Java &bull; C# &bull; Rust"]
            TGQL["<b>TG-QL Declarative AST DSL</b><br/>Custom YAML Pattern Queries<br/>Syntax Trees &bull; Taint Sinks &bull; Constraints"]
            Reach["<b>Reachability &amp; OpenVEX</b><br/>Callgraph Traversal &bull; Reachable CVEs<br/>Zero Ineffective Dependency Alerts"]
        end
        subgraph DeepGroup["Forensics, RegEx &amp; Vision OCR"]
            direction LR
            OCR["<b>Multi-Modal Vision OCR Engine</b><br/>Tesseract v5.4.0 &bull; Leaked Secrets<br/>Architecture Diagrams &bull; Screenshots"]
            ReDoS["<b>Thompson NFA ReDoS Engine</b><br/>Polynomial &amp; Exponential Exploder<br/>Catastrophic Backtracking Loops"]
            GitMine["<b>Git History &amp; Container Audit</b><br/>Commit Packfile Secret Mining<br/>Dockerfile Non-Root Enforcement"]
        end
    end

    Kernel -->|"Scan Code &amp; Dependencies"| StaticGroup
    Kernel -->|"Analyze Visuals &amp; Commits"| DeepGroup

    %% =========================================================================
    %% STAGE 4: CONSENSUS DELIBERATION & TRIAGE
    %% =========================================================================
    subgraph DeliberationTriage["3. Deliberation Tournament &amp; Evidence Triage"]
        direction TB
        Tournament["<b>3-Perspective Deliberation Tournament</b><br/>Vulnerability Hunter vs. Devil's Advocate / Sanitizer Verifier vs. Ponytail Remediator<br/>Eliminates False Positives &bull; Calibrated Confidence Scoring (0-100%)"]
        PRGate{"<b>Differential PR Diff Gate</b><br/><code>torusguard review</code><br/>Incremental Git Diff Changes?"}
        Tournament --> PRGate
    end

    StaticGroup -->|"Raw AST Findings"| Tournament
    DeepGroup -->|"Extracted Secrets &amp; Complexities"| Tournament

    %% =========================================================================
    %% STAGE 5: GOVERNED REMEDIATION & PONYTAIL LOOP
    %% =========================================================================
    subgraph GovernedRemediation["4. Governed Remediation Loop &amp; Safety Guardrails (Ponytail Protocol)"]
        direction TB
        
        Harden["<b>Surgical Patch Formulation</b><br/>Semantic Line Snippet Replacement<br/>Strict Line Budget: &le;35 Additions &bull; &le;25 Deletions"]
        
        BoundsCheck{"<b>Ponytail Bounds Check</b><br/>Exceeds 35 Add / 25 Del?"}
        RejectDiff["<b>Diff Rejected</b><br/>Excess Churn Detected<br/>Prompt AI for Minimal Snippet"]
        
        SnapshotStore[("<b>Pre-Apply Snapshot Store</b><br/><code>.torusguard/snapshots/&lt;run_id&gt;/</code><br/>Byte-for-Byte Rollback Backup")]
        
        HumanGate{"<b>Human Gate Authorization</b><br/>Explicit <code>--yes</code> or Interactive Confirmation"}
        UserAbort["<b>Operation Aborted</b><br/>Zero Files Touched &bull; Safe Exit"]
        
        ApplyPatch["<b>Atomic Patch Application</b><br/>Apply Unified Surgical Diff to Disk"]
        
        RecheckGate{"<b>Differential Recheck Engine</b><br/><code>torusguard recheck</code><br/>Fix Closed with Zero Regressions?"}
        RollbackExec["<b>Auto-Rollback Triggered!</b><br/>Instant Restoration from Snapshot<br/>Quarantine Candidate Patch"]
        
        Harden --> BoundsCheck
        BoundsCheck -->|"Violation"| RejectDiff
        RejectDiff -.->|"Re-prompt AI"| Harden
        BoundsCheck -->|"Pass (Within Bounds)"| SnapshotStore
        SnapshotStore --> HumanGate
        HumanGate -->|"Denied"| UserAbort
        HumanGate -->|"Approved"| ApplyPatch
        ApplyPatch --> RecheckGate
        RecheckGate -->|"Regressions"| RollbackExec
        RollbackExec -.->|"Restore Clean State"| SnapshotStore
    end

    PRGate -->|"Target Findings"| Harden

    %% =========================================================================
    %% STAGE 6: LIVING SECURITY LEDGER & ENTERPRISE OUTPUTS
    %% =========================================================================
    subgraph EnterpriseDeliverables["5. Living Security Ledger &amp; Enterprise Deliverables"]
        direction TB
        Ledger[("<b>Living Security Ledger</b><br/><code>security_report.md</code><br/>Synchronized Single Source of Truth &bull; Status: RESOLVED 🟒")]
        
        subgraph DeliverableOutputs["Executive Reports &amp; Verified Memory"]
            direction LR
            ThreatModel["<b>STRIDE Threat Model</b><br/><code>SECURITY_THREAT_MODEL.md</code><br/>DFD Architecture Diagrams"]
            SARIF["<b>OASIS SARIF v2.1.0</b><br/>GitHub Advanced Security<br/>CI/CD Security Center"]
            HTMLReport["<b>Executive Dashboard</b><br/>Single-File HTML Report<br/>Interactive Posture Heatmap"]
            GoldenRecipes[("<b>Golden Fix Memory</b><br/><code>.torusguard/recipes/</code><br/>Verified Distilled Fixes")]
        end

        Ledger --> DeliverableOutputs
    end

    RecheckGate -->|"Fix Confirmed (Clean Closure)"| Ledger

    %% =========================================================================
    %% STYLING AND THEME (Modern Dark Cyber Palette)
    %% =========================================================================
    classDef ingressStyle fill:#0f172a,stroke:#38bdf8,stroke-width:2px,color:#f8fafc;
    classDef routerStyle fill:#1e1b4b,stroke:#6366f1,stroke-width:2px,color:#f8fafc;
    classDef scannerStyle fill:#022c22,stroke:#10b981,stroke-width:2px,color:#f8fafc;
    classDef tourneyStyle fill:#2e1065,stroke:#a855f7,stroke-width:2px,color:#f8fafc;
    classDef gateStyle fill:#451a03,stroke:#f59e0b,stroke-width:2px,color:#fef3c7;
    classDef rejectStyle fill:#450a0a,stroke:#ef4444,stroke-width:2px,color:#fee2e2;
    classDef actionStyle fill:#064e3b,stroke:#34d399,stroke-width:2px,color:#f8fafc;
    classDef dbStyle fill:#1e293b,stroke:#94a3b8,stroke-width:2px,color:#f8fafc;
    classDef ledgerStyle fill:#172554,stroke:#3b82f6,stroke-width:2px,color:#eff6ff;
    classDef outputStyle fill:#042f2e,stroke:#14b8a6,stroke-width:2px,color:#f0fdfa;

    class CLI,Chat,MCP ingressStyle;
    class Kernel routerStyle;
    class AST,TGQL,Reach,OCR,ReDoS,GitMine scannerStyle;
    class Tournament tourneyStyle;
    class PRGate,BoundsCheck,HumanGate,RecheckGate gateStyle;
    class RejectDiff,UserAbort,RollbackExec rejectStyle;
    class Harden,ApplyPatch actionStyle;
    class SnapshotStore,GoldenRecipes dbStyle;
    class Ledger ledgerStyle;
    class ThreatModel,SARIF,HTMLReport outputStyle;
Loading

🌐 Interactive Architecture Visualizations:

  • System Architecture Diagram (HTML) β€” Dynamic zoomable/pannable pipeline with dark/light themes, live view switching (Tri-Mode Ingress, AST Engine, Multi-Modal Vision OCR, Ponytail Bounds, Fail-Closed Recovery), and SVG/PNG export.
  • Governed Remediation Workflow (HTML) β€” Step-by-step visual trace of the 7-stage remediation loop, safety gates, and automatic rollback path.

Key design decisions:

  • Tri-Mode Parity: The CLI (Mode A), Chat Slash Commands (Mode B), and Native MCP Tools (Mode C) share the exact same underlying governance and validation rules.
  • Multi-Modal Vision OCR: Images, architecture diagrams, and screenshots are automatically scanned for leaked secrets using Tesseract OCR, bounded by strict 10MB memory safety limits.
  • Deterministic Enforcement: The Go binary handles all deterministic operations (AST scanning, bounds checking, snapshotting, reporting).
  • AI Intelligence: The AI agent handles intelligence-requiring tasks (patch generation, root-cause analysis, remediation formulation).
  • Living Ground Truth: All modes synchronize with security_report.md to prevent finding drift or hallucination.
  • Zero-Bypass Guardrails: Neither human nor AI can bypass Ponytail Protocol bounds (≀35 additions, ≀25 deletions) or the Human Gate before modifying code.

πŸ“‹ Prerequisites

  • Go 1.25+ (to build from source)
  • Git (for git apply patch operations)
  • Node.js 18+ (for npm package installation)

πŸš€ Installation & How to Use (3 Options)

TorusGuard can be run without installation via npx, installed globally or locally via npm, compiled from source with go build, or installed via go install.

Option Method Best For Dedicated Guide
Option 1 npm & npx Node.js developers, zero-install CLI, CI/CD πŸ“– Option 1 Guide
Option 2 Build from Source Contributors, custom rules, Go development πŸ“– Option 2 Guide
Option 3 Go Install Go projects, single-binary, zero Node.js/npm πŸ“– Option 3 Guide

Option 1: npm (Primary)

Method A: Direct NPX Zero-Install (Recommended)

Run directly without installing any packages globally or locally:

npx torusguard init

Tip: Use npx torusguard@latest init to guarantee the freshest release.

Method B: Global Installation

npm install -g torusguard
torusguard init

Method C: Local Project Installation

npm install -D torusguard

πŸ’‘ Using TorusGuard after npm install torusguard:
TorusGuard is a CLI security engine, not an importable JavaScript library. When installed locally, the binary resides in node_modules/.bin/torusguard.
You can run it via:

  • npx torusguard init (npx automatically uses your local node_modules binary)
  • Adding "security:audit": "torusguard audit" to your package.json scripts (npm run security:audit)
  • Direct path: ./node_modules/.bin/torusguard audit
npm package

πŸ‘‰ Read the Full Option 1 (npm & npx) Dedicated Guide β†’


Option 2: Build from Source (Recommended for Contributors)

git clone https://github.com/githubmofo/TorusGuard.git
cd TorusGuard
go build -o torusguard ./cmd/torusguard

On Windows:

go build -o torusguard.exe ./cmd/torusguard

Run directly:

./torusguard init
./torusguard audit

πŸ‘‰ Read the Full Option 2 (Build from Source) Dedicated Guide β†’


Option 3: Go Install

Install directly into $GOPATH/bin:

go install github.com/githubmofo/TorusGuard/cmd/torusguard@latest

Verify and run:

torusguard --version
torusguard init

πŸ‘‰ Read the Full Option 3 (Go Install) Dedicated Guide β†’


πŸ’» Usage

Quick Start

# Initialize TorusGuard in your project
torusguard init

# Run a full security audit
torusguard audit

# Check workspace posture
torusguard status

# Generate an HTML report
torusguard report --html

# Generate a SARIF report
torusguard report --sarif

Remediation Workflow

# Validate a candidate patch against Ponytail bounds
torusguard harden fix.patch

# Apply the patch with rollback snapshot (requires --yes for Human Gate)
torusguard apply --yes fix.patch

# Verify the fix was applied correctly
torusguard recheck

# Roll back if something went wrong
torusguard rollback

Runtime Validation

# Generate authorization token for runtime probing
torusguard authorize

# Probe a running application for security headers
torusguard web-validate

# Send bounded inert payloads to test input handling
torusguard exploit-check

πŸ”§ Commands

Command Description
init Scaffold .torusguard/ workspace, detect stack, activate rules
status Diagnostic overview of posture, stack, and active rules
audit Static heuristic security scan against active TG-* rules
review Differential PR and Git diff incremental security review
threatmodel Synthesize architectural STRIDE threat model & Mermaid DFDs
benchmark Run SecurityReviewBench precision & recall evaluation suite
verify Live disk line match audit and evidence sufficiency check
harden Validate patches against Ponytail Protocol bounds
apply Apply patches with pre-apply .bak rollback snapshots
rollback Instant restoration from pre-apply snapshots
recheck Differential re-scan on modified files
report Generate HTML (--html) or SARIF (--sarif) posture reports
recipes Manage the Golden Fix recipe library
authorize Generate cryptographic auth tokens for runtime probing
web-validate Authorized HTTP probing with X-TorusGuard-Audit headers
exploit-check Bounded single-step exploitability confirmation
ocr-scan Run Tesseract OCR secret scan on images/diagrams (<10MB)
container Audit Dockerfile, compose, and container configurations
git-mine Mine git commit history for leaked secrets & creds
redos Analyze regex patterns for catastrophic backtracking
ai-guard Scan AI/LLM code for prompt injection & RAG flaws
mcp Run native Model Context Protocol (MCP) server over stdio
full Master 7-stage closed-loop security governance pipeline
update Self-update the TorusGuard engine
help Show interactive command guide

πŸ“ Project Structure

TorusGuard/
β”œβ”€β”€ cmd/torusguard/       # CLI entry point, command router & MCP server
β”‚   β”œβ”€β”€ main.go           # CLI command router
β”‚   └── mcp.go            # Model Context Protocol (MCP) JSON-RPC 2.0 stdio server
β”œβ”€β”€ internal/
β”‚   β”œβ”€β”€ apply/            # Patch application + pre-apply snapshot engine
β”‚   β”œβ”€β”€ harden/           # Ponytail Protocol bounds enforcement & line-level reflection
β”‚   β”‚   β”œβ”€β”€ patch.go      # Ponytail Protocol bounds verification
β”‚   β”‚   └── reflection.go # Line-level reflection & semantic replacement
β”‚   β”œβ”€β”€ memory/           # Golden Fix recipe persistence
β”‚   β”œβ”€β”€ recheck/          # Differential re-scan engine
β”‚   β”œβ”€β”€ report/           # SARIF v2.1.0 + dark-mode HTML generators
β”‚   β”œβ”€β”€ rules/            # TG-* rule catalog loader
β”‚   β”œβ”€β”€ scanner/          # Heuristic polyglot security scanner + Tesseract OCR
β”‚   β”‚   β”œβ”€β”€ scanner.go    # Polyglot code AST & heuristic scanner
β”‚   β”‚   └── ocr.go        # Multi-modal Vision OCR secret detection
β”‚   β”œβ”€β”€ termui/           # 75-column terminal UI formatting
β”‚   β”œβ”€β”€ validate/         # authorize / web-validate / exploit-check / verify
β”‚   └── workspace/        # init + polyglot stack detection
β”œβ”€β”€ .torusguard/          # Generated workspace state
β”‚   β”œβ”€β”€ rules/            # Active security rule definitions
β”‚   β”œβ”€β”€ schemas/          # JSON schemas for findings, recipes, etc.
β”‚   β”œβ”€β”€ memory/           # Persistent security context
β”‚   └── snapshots/        # Pre-apply rollback backups
β”œβ”€β”€ docs/                 # Architecture and usage documentation
β”œβ”€β”€ bin/                  # npm package CLI wrapper
β”œβ”€β”€ go.mod                # Go module (github.com/torusguard/torusguard)
└── package.json          # npm package definition

πŸ”’ Security Invariants & Rule Governance

TorusGuard enforces 88 security invariants across 22 architectural families covering Secrets, Authentication, Multi-Tenant Database Isolation, Input Sanitization, Rate Limiting, AI Agent Prompt Injection, SSRF, Webhooks, WebSockets, CSRF, GraphQL, Supply Chain, Business Logic, Cache Poisoning, Client Bundles, Platform Headers, Polyglot Bypasses, Edge Timeouts, Container & Docker Safety, Git History Secret Mining, Regular Expression Backtracking (ReDoS), and Vector Database RAG Isolation.

πŸ“˜ Full Rules Catalog & Invariants:
The complete rulebook with formal invariant definitions, severity scores, and testing signatures is maintained in AGENTS.md and the rules/ directory.
You can also explore verified Golden Fix patterns anytime via torusguard recipes or stream the live catalog over MCP via torusguard://rules_catalog.


πŸ€– AI Agent Integration

TorusGuard works natively inside AI coding assistants. Add the configuration file to your project root and your AI agent automatically enforces TorusGuard security invariants.

Supported Agents

Agent Configuration File Status
Antigravity (Gemini) AGENTS.md βœ… Full support
Claude Code CLAUDE.md βœ… Full support
Cursor .cursorrules βœ… Full support
Windsurf .windsurfrules βœ… Full support
VS Code Copilot AGENTS.md βœ… Full support
Kimi SKILL.md βœ… Full support

Slash Commands (AI Chat Mode)

/torusguard init          # Initialize workspace
/torusguard audit         # Run security + OCR scan; sync security_report.md
/torusguard ocr-scan      # Scan diagram or image assets for leaked credentials
/torusguard harden        # Formulate remediation patches
/torusguard apply         # Apply patches with Human Gate
/torusguard recheck       # Verify fix closure
/torusguard report        # Generate posture report
/torusguard status        # Check posture overview
/torusguard full          # End-to-end 7-stage pipeline

Native MCP Tools (Agent Toolkit Mode)

When configured with .agents/mcp_config.json or mcp_config.json, AI coding agents gain native tool calling (13 Tools & 2 Resources):

  • torusguard_audit: Deep static AST scan + Vision OCR; writes security_report.md
  • torusguard_ocr_scan: Dedicated image credential analysis via Tesseract (5-10MB bounds)
  • torusguard_container: Audits container files for root execution, docker socket exposure, and privileged mode
  • torusguard_git_mine: Mines git commit history and config for leaked credentials and tokens
  • torusguard_redos: Analyzes regex patterns for catastrophic exponential backtracking
  • torusguard_ai_guard: Audits AI agent prompt templates, tool registries, and vector database queries
  • torusguard_verify: Asserts evidence sufficiency & line-shift invariant fingerprint matches
  • torusguard_harden: Validates remediation diff against Ponytail Protocol bounds
  • torusguard_recheck: Differential re-scan confirming fix closure
  • torusguard_review: Differential PR and Git diff incremental review; gate decisions
  • torusguard_threatmodel: Synthesizes STRIDE threat model & Mermaid DFDs (SECURITY_THREAT_MODEL.md)
  • torusguard_benchmark: Runs SecurityReviewBench self-evaluating precision & recall suite
  • torusguard_status: Workspace posture and tech stack inspection
  • torusguard://security_report: MCP Resource reading the living security report
  • torusguard://rules_catalog: MCP Resource exploring verified rules catalog & Golden Fix patterns

πŸ§ͺ Verified Test Suite & Mass Benchmarks

TorusGuard undergoes rigorous automated multi-tier testing across polyglot stacks, multi-modal vision assets, and agent communication protocols:

Testing Tier Scope & Target Stacks Pass Rate Verified Capabilities
Go Engine & Unit Tests cmd/torusguard, internal/scanner, internal/* 100% Passing Deterministic AST matching, 88 canonical rule patterns, JSON-RPC 2.0 MCP protocol (133/133 harness tests passing).
Mass Polyglot Benchmarks 20 Enterprise Tech Stacks (Go, Python, Java, Node, Rust, PHP, C#, Ruby, Svelte, Vue, Angular) 20/20 Passed Framework auto-profiling, heuristic AST analysis, finding deduplication.
Unseen Tri-Mode Validation 6 Unseen Framework Ecosystems (SvelteKit 2 + Bun, FastAPI AI RAG, DevOps Git Mine, OCR Asset Suite, Kotlin Ktor, Laravel 11) 6/6 Passed (100%) Mode A (CLI) + Mode B (Slash Commands) + Mode C (Native MCP Tools) across 18/18 canonical skills with automated sandbox cleanup.
Tri-Mode & Vision E2E 16 Diverse Framework Repos (React, Next.js, Express, Django, FastAPI, Spring Boot, etc.) 16/16 Passed Mode A (CLI) + Mode B (Slash Commands) + Mode C (Native MCP Tools) + Multi-Modal Vision OCR.
Multi-Modal Vision OCR Diagram & Image assets (.png, .jpg, .webp) via Tesseract v5.4.0 100% Recall Secrets detection (TG-SEC-001 - TG-SEC-007), 10MB DoS bounding, OCR character substitution tolerance.
Ponytail Churn Limits Surgical patch validation across all 88 rules Bounded Line bounds (≀35 additions, ≀25 deletions), zero-bypass verification (TG-DIFF-001).

All test environments are completely sandboxed, verified with byte-for-byte assertions, and cleaned up automatically.


πŸ›‘οΈ Non-Negotiable Invariants

  1. Browser-Code Truth: Never expose secrets in frontend bundles.
  2. Multi-Tenant Isolation: Always scope DB lookups by tenant/user ownership.
  3. Ponytail Churn Bounds: Patches ≀35 additions, ≀25 deletions. No full-file rewrites.
  4. Zero Security Bypasses: Never insert # nosec, verify=False, InsecureSkipVerify: true.
  5. Snapshots Before Edits: Mandatory .bak backup before every modification.
  6. Fail-Closed Cryptography: Panic on entropy failure. No fallback tokens.
  7. SSRF Boundary Enforcement: Block private IPs and cloud metadata before probing.
  8. DoS Resilience: 10,000-file max, 5-minute timeout.

🀝 Contributing

  1. Fork the repository
  2. Create a feature branch: git checkout -b feat/your-feature
  3. Commit changes: git commit -m "feat: add your feature"
  4. Push to branch: git push origin feat/your-feature
  5. Open a Pull Request

See CONTRIBUTING.md for detailed guidelines and CODE_OF_CONDUCT.md for community standards.


πŸ“„ License

MIT Β© 2026 Jenish Lad


πŸ“š Documentation

Document Description
Architecture System design and module relationships
Security Architecture Threat model and security design
Detection Engine Scanner internals and rule matching
API Specification CLI argument specification
Security Philosophy Core design principles
Testing Playbook Testing guide and CI integration
Demo Guide Quick start and full lifecycle demo
Roadmap Feature roadmap and release planning
Unseen Stacks Validation Report Tri-mode validation across 6 unseen ecosystems & vision OCR
SECURITY.md Vulnerability disclosure policy
CHANGELOG.md Version history and release notes

About

Autonomous Security Guardrails & Governed Remediation for AI-Built Apps. Tri-Mode Parity (CLI, Chat Slash Commands, Native MCP Server), First-Principles Security Suite, Multi-Modal Vision OCR, 86 Rules across 22 Families & Ponytail Patch Bounds.

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages