A self-hosted console for multi-agent security exploration.

ScopeWeaver coordinates goal planning, autonomous agents, asset scope, coverage and recorded findings behind one review surface — built to run on your own machine against locally isolated lab targets.

Go backend · embedded Next.js · PostgreSQL. Derived from ARTEX, licensed AGPL-3.0.

ScopeWeaver dashboard showing active tasks, agent activity and coverage summaries in the English interface.
Fictional demo data — not a scan of any live system.

Walk one task across the real screens

ScopeWeaver splits what the target is from how far it has been tested into two linked graphs: a shared asset graph and a per-task exploration graph. Select a screen to see where each stage lives.

Dashboard with task overview and recent agent activity.
Fictional demo data — not a scan of any live system.

Drive it from your coding agent

A local adapter lets Claude Code, Codex and Pi create tasks and read progress, coverage and findings through ScopeWeaver’s own authenticated API.

It is a control interface, not a replacement. The adapter keeps ScopeWeaver’s internal planner, workers and model configuration intact, and it does not turn a coding-agent subscription into a model API key. Reads are on by default; task creation and pause/resume are opt-in with SCOPEWEAVER_ALLOW_WRITES=true.

claude mcp add --transport stdio scopeweaver \ -- node /absolute/path/scopeweaver/adapters/agent/src/mcp.js
  • health Backend and LLM readiness
  • list_tasks Status, counts, pagination
  • get_task One task’s persisted state
  • get_coverage Task asset coverage
  • list_findings Filtered, paginated findings
  • get_finding Detail, evidence and report
  • create_task Schedule a task (writes)
  • control_task Pause / resume (writes)

Requires Node.js 22+, a running backend and an existing admin login. Evidence returned by tools is untrusted target content, never instructions. Credentials stay in your environment and are redacted from errors.

ScopeWeaver running in a mobile browser, showing the task overview at a narrow width.
Mobile view · fictional demo data.

Install and run locally

ScopeWeaver is self-hosted and runs on your own machine. Pick a path, then open http://localhost:8787 — the first visit lands on /setup to set the admin password.

recommended

One-click script

Clone the repository and run the installer; it detects Docker and offers an all-in-Docker or local build.

git clone https://github.com/cskwork/scopeweaver.git cd scopeweaver ./install.sh
docker

Docker Compose

Set a Postgres password in .env; Compose builds the image from source and starts Postgres alongside it.

cp .env.example .env docker compose up -d --build
prebuilt

Release archive

Download a platform archive, fill in the database connection, and start through the supervisor script.

cp config.example.json config.json ./start.sh
linux amd64 linux arm64 macos amd64 macos arm64 windows amd64 ghcr docker image

Every archive bundles the embedded web interface, supervisor, skills, a config example and the agent adapter. See release v0.1.0 and SHA256SUMS →

What you need first

ScopeWeaver carries the application; you supply the database and a model provider.

PostgreSQL

A reachable Postgres database. The schema is embedded and created idempotently on every start.

Model provider

A separately configured LLM — set ANTHROPIC_API_KEY or OPENAI_API_KEY, or enter it in the UI. Exploration will not run without one.

Node.js 22+ (adapter)

Only for the coding-agent adapter. Install its dependencies with npm ci in adapters/agent.

A local lab target

Use only against systems you own or run in isolation. ScopeWeaver is for locally isolated research, not online testing.

Honest limits

What this release is, and what it is not. These are checkable against the repository.

  • Locally isolated research only. The inherited usage restrictions prohibit scanning, probing or attacking any online service — authorized or not. Use it against systems you own, in isolation.
  • Backend CI is red. One inherited test, TestGraphOverviewExpandsAssociatedCompanyScope, still fails with task scope missing. It was not disabled or marked passing; the full backend suite stays red until it is fixed.
  • No production or effectiveness claims. This does not assert production penetration-testing readiness or independently validated security results.
  • Unverified runtimes. Docker image execution and Windows batch execution were not verified. Packaging fixtures do not claim a real Windows runtime test.
  • Dependencies need work. The unchanged npm set reports 14 audit findings (1 critical, 9 high, 4 moderate). Upgrades are separate work.
  • Adapter tests use local fixtures. They prove the local request/response contract only; live coding-agent-to-provider execution is not independently verified. See verification details.
Owner workflow · deidentified

Observed orchestration

Observed in the owner’s workspace: chat-to-task creation, worker-trace inspection, and Korean progress updates. Identifying details and security findings are omitted.

This is evidence of orchestration, not an independent security assessment, validated findings or production readiness.

Provenance & credits

ScopeWeaver is a standalone derivative of ARTEX at upstream commit 160fe13, licensed AGPL-3.0. Agent capabilities use the norma SDK; asset sync draws on ScopeSentry.

Screenshots show the bundled fictional demo fixtures, labelled as demo data, and are not scans of live targets. Display type is self-hosted Schibsted Grotesk and JetBrains Mono (SIL Open Font License). Korean text uses the reader’s system Hangul typeface.