Bugb
Documentation for cxg, Bravos and guardlink: three security tools you run yourself, on your own machines.
Every command on these pages was executed against a real build and its actual output pasted in. What you read is what the binary does, not what its source suggests it should.
cxg and guardlink are open source and free to run. Bravos is free on your own machine and licensed beyond it.
- cxg
Scan a running target for vulnerabilities. Its checks are ordinary programs rather than pattern files, so a check can chain requests, compute, and parse a format before it decides. Every finding keeps the request and the response behind it.
Install cxgRun your first scanCLI reference
1.3.0Apache-2.0released - Bravos
Find out which weaknesses in your own codebase an attacker can actually reach. Point it at a repository and it attacks each one against a running instance, keeping the request that proved it. Free on your own machine; the self-hosted server and the CI runner are what a licence buys.
Install BravosBuild a threat modelWhat a licence buys
0.1.0CLI not yet on PyPI - guardlink
Keep a threat model in the repository it describes. Annotations anchor to real code positions, so the model changes when the code does. Validates and diffs in CI, and serves the model to a coding agent over MCP.
Install guardlinkAnnotate a repository
2.0.0MITon npm

