Bravos
Bravos takes a repository and tells you which of its weaknesses an attacker can actually reach. Not which ones a scanner suspects: which ones were attacked, on a running instance of your application, under a real login, and either worked or did not.
It reads your code and writes the threats it can see into it as annotations. Then it attacks each one, from a different perspective each round, until it has nothing left to try. Every threat ends with a verdict and a reason:
| Verdict | Means |
|---|---|
| confirmed | a probe proved it, and the request that proved it is kept |
| refuted | probes ran against it and it did not hold up |
| mitigation held | the control you declared was attacked and it survived |
| not tested | nothing was learned, and the record says why |
That last row is the one that makes the others worth anything. A tool that folds “we could not reach the target” into “we found nothing” reports a cleaner application than it measured. Bravos keeps the two apart, counts them separately, and puts the untested count next to the confirmed one.
What you get from a run
Section titled “What you get from a run”- A ledger of every threat, its verdict, and the reason it holds.
- An advisory per confirmed finding, written like a GitHub security advisory, carrying the exact probe that produced the verdict so anyone can re-run it.
@confirmedannotations in your source, on a branch, next to the vulnerable line, so the knowledge outlives the run.- A build gate.
bravos citurns that ledger into an exit code against a policy you commit.
Three parts, one product
Section titled “Three parts, one product”Bravos is one product delivered in three pieces. The first is free and runs on a laptop. The other two are what a licence buys.
| Where it runs | What it is for | Cost | |
|---|---|---|---|
| The CLI | a developer’s machine | runs every scan, writes the ledger, gates the build | free |
| The server | your infrastructure | one place a team reads each other’s runs, with history | licensed |
| CI/CD execution | your pipeline | a prebuilt runner image, so a job pays no setup | licensed |
The line between them is worth being exact about, because guessing it wrong costs a pipeline:
- The CLI needs no server, no account and no network beyond the target. It
runs the whole loop, writes the ledger to disk, and
bravos cireads that ledger and exits, with no credential anywhere. A team can gate builds on a confirmed finding without buying anything. - The server is the paid product. It stores what the CLI proved so a colleague or a security team can read it. It is a private image, licensed by a signed licence, with seats enforced by that licence. It never runs a scan.
- CI/CD execution is gated too. The runner image that carries the CLI, cxg and guardlink pinned together is published privately; pulling it needs a registry credential that comes with the licence.
What it is made of
Section titled “What it is made of”Two engines sit under Bravos, and both are documented on this site because you may want to read them, run them yourself, or check what a flag does:
- guardlink holds the threat model. It is the annotation language the model is written in, and the SARIF export a probe is generated from.
- cert-x-gen executes the probes. Every request Bravos sends, it
sends through
cxg pentest.
Bravos is not a script that calls them in order. It is the part between them: the loop, the identities, the perspective rotation, the deduplication, and the ledger that keeps what was proven apart from what was only attempted. The places the two tools cannot answer on their own are the reason it exists.
The two tiers
Section titled “The two tiers”Everything Bravos does falls on one side of a line, and the line is whether packets leave your machine.
| Model tier | Verify tier | |
|---|---|---|
| What it does | reads code, writes and reads annotations, builds the threat model | stands up a target, logs identities in, fires real exploit traffic |
| Sends traffic | no | yes |
| Edits your repository | annotations only, on a branch | annotations only, on a branch |
| Needs | git, guardlink |
cxg, Docker, and a coding-agent CLI |
| Commands | model, inspect, annotate, plan, ledger, ci, dashboard, mcp |
auto, run, round, replay, env |
Start on the model tier. It needs two dependencies, sends nothing anywhere, and produces the threat model the verify tier later attacks. See Build your first threat model.
The verify tier sends real exploit traffic and lets a coding agent edit the repository it is testing. Read Authorization and blast radius before pointing it at anything.
Four surfaces, one engine
Section titled “Four surfaces, one engine”The CLI is the only thing that executes a run. Every other surface reads what it produced, or hands you the command to run, so there is no second execution path that can drift from the first.
Availability, as of 10 September 2026
Section titled “Availability, as of 10 September 2026”These pages are verified against real builds, so this table says what you can actually obtain today rather than what is intended.
| Component | Version | Where it is |
|---|---|---|
bravos CLI |
0.1.0 | not on PyPI yet. pipx install bravos is the command when it lands; today it is installed from the repository, which is private |
| bugb-server | 0.1.0 | published to a private registry, ghcr.io/bugb-technologies/bugb-server. The pull credential comes with the licence |
| The runner image | 0.1.0 | published to the same private registry as ghcr.io/bugb-technologies/bugb-ci |
| The VS Code extension | 0.9.1 | not published. Not on the VS Code Marketplace and not on Open VSX |
guardlink |
2.0.0 | public, on npm |
cxg |
1.3.0 | public, released binary and crate |
Start here
Section titled “Start here”These pages link into cxg and guardlink
Section titled “These pages link into cxg and guardlink”Most of what you need about a scan flag, an annotation, or a SARIF field is
already under /cxg/ and /guardlink/, generated from
those products’ own binaries. A page here covers what is genuinely Bravos’s:
the loop, the ledger, the verdicts, the ordering. It links out for the rest,
because a copy here would not change when the original does, and would be wrong
the next time a flag changes.
Source
Section titled “Source”- Engine
- Bugb-Technologies/siete (private)
- Threat model
- Bugb-Technologies/guardlink
- Probe execution
- Bugb-Technologies/cert-x-gen
- Licences and deployment keys
- account.bugb.io

