Argus — security grade SAFE, quality 48/100

Security audit verdict: SAFE · quality 48/100

No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →

by gy15901580825 · MCP Server · ★ 204

Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h

🔒 Is Argus safe to install? View the security audit →

About Argus

Argus Black-box red-team testing for AI agents. Point Argus at any HTTP, gRPC, MCP, payment-agent, or browser-using agent endpoint, run 205 adversarial probes (OWASP LLM Top 10, MITRE ATLAS, NIST AI RMF, garak wrappers, TAP / PAIR / GCG), and get LLM-judged findings as SARIF 2.1.0 / JUnit XML / HTML — drop straight into CI as a GitHub Code Scanning gate. Motivation LLM eval frameworks score single prompt-response pairs. That's not what ships. What ships is an agent — a system that plans, calls tools, recovers from errors, reads documents, opens browsers, holds state across turns. The failure surface of that system is dominated by adversarial robustness, not benchmark accuracy: prompt injection through retrieved docs, tool-call confusion, sleeper triggers, indirect injection via visited URLs, jailbreaks that compose across turns. Argus tests the agent the way an attacker would: as a black box, over the wire, against the production endpoint, without source access. It picks up where unit tests and LLM-evals leave off, and it produces reports your security team can map to OWASP LLM Top 10, MITRE ATLAS and NIST AI RMF controls without translation.

Quick Facts

Stars204
Forks28
LanguagePython
CategoryMCP Server
LicenseApache-2.0
Quality Score47.7973807990376/100
Open Issues3
Last Updated2026-08-25
Created2026-05-28
Platformsbrowser, cli, mcp, python
Est. Tokens~13k

Compatible Skills

These tools work well together with Argus for enhanced workflows:

  • moonshot — semantic(0.19)+complementary+same_lang+similar_pop+shared_platform (57%)
  • AgentPoison — semantic(0.17)+complementary+same_lang+similar_pop+shared_platform (56%)

More MCP Server Tools

Explore other popular mcp server tools:

View all MCP Server tools →

Popular Python Agent Tools

Frequently Asked Questions

What is Argus?

Argus is Black-box, open-source red-team testing for AI agents. Point it at any HTTP, gRPC, or browser-using agent endpoint; run 205 probes mapped to OWASP LLM Top 10 / MITRE ATLAS / NIST AI RMF, incl. payment. It is categorized as a MCP Server with 204 GitHub stars.

What programming language is Argus written in?

Argus is primarily written in Python.

How do I install or use Argus?

You can find installation instructions and usage details in the Argus GitHub repository at github.com/gy15901580825/Argus. The project has 204 stars and 28 forks, indicating an active community.

What license does Argus use?

Argus is released under the Apache-2.0 license, making it free to use and modify according to the license terms.

How this security grade is produced

Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.

The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.

Sources & who's responsible:

View on GitHub → Browse MCP Server tools