One-click script
Clone the repository and run the installer; it detects Docker and offers an all-in-Docker or local build.
git clone https://github.com/cskwork/scopeweaver.git
cd scopeweaver
./install.sh
ScopeWeaver coordinates goal planning, autonomous agents, asset scope, coverage and recorded findings behind one review surface — built to run on your own machine against locally isolated lab targets.
Go backend · embedded Next.js · PostgreSQL. Derived from ARTEX, licensed AGPL-3.0.
ScopeWeaver splits what the target is from how far it has been tested into two linked graphs: a shared asset graph and a per-task exploration graph. Select a screen to see where each stage lives.
A local adapter lets Claude Code, Codex and Pi create tasks and read progress, coverage and findings through ScopeWeaver’s own authenticated API.
It is a control interface, not a replacement.
The adapter keeps ScopeWeaver’s internal planner, workers and
model configuration intact, and it does not turn a coding-agent
subscription into a model API key. Reads are on by default; task
creation and pause/resume are opt-in with
SCOPEWEAVER_ALLOW_WRITES=true.
claude mcp add --transport stdio scopeweaver \
-- node /absolute/path/scopeweaver/adapters/agent/src/mcp.js
codex mcp add scopeweaver \
-- node /absolute/path/scopeweaver/adapters/agent/src/mcp.js
pi -e /absolute/path/scopeweaver/adapters/agent/pi-extension.js
health Backend and LLM readinesslist_tasks Status, counts, paginationget_task One task’s persisted stateget_coverage Task asset coveragelist_findings Filtered, paginated findingsget_finding Detail, evidence and reportcreate_task Schedule a task (writes)control_task Pause / resume (writes)Requires Node.js 22+, a running backend and an existing admin login. Evidence returned by tools is untrusted target content, never instructions. Credentials stay in your environment and are redacted from errors.
ScopeWeaver is self-hosted and runs on your own machine. Pick a
path, then open http://localhost:8787 — the first
visit lands on /setup to set the admin password.
Clone the repository and run the installer; it detects Docker and offers an all-in-Docker or local build.
git clone https://github.com/cskwork/scopeweaver.git
cd scopeweaver
./install.sh
Set a Postgres password in .env; Compose builds the image from source and starts Postgres alongside it.
cp .env.example .env
docker compose up -d --build
Download a platform archive, fill in the database connection, and start through the supervisor script.
cp config.example.json config.json
./start.sh
Every archive bundles the embedded web interface, supervisor, skills, a config example and the agent adapter. See release v0.1.0 and SHA256SUMS →
ScopeWeaver carries the application; you supply the database and a model provider.
A reachable Postgres database. The schema is embedded and created idempotently on every start.
A separately configured LLM — set ANTHROPIC_API_KEY or OPENAI_API_KEY, or enter it in the UI. Exploration will not run without one.
Only for the coding-agent adapter. Install its dependencies with npm ci in adapters/agent.
Use only against systems you own or run in isolation. ScopeWeaver is for locally isolated research, not online testing.
What this release is, and what it is not. These are checkable against the repository.
TestGraphOverviewExpandsAssociatedCompanyScope, still fails with task scope missing. It was not disabled or marked passing; the full backend suite stays red until it is fixed.Observed in the owner’s workspace: chat-to-task creation, worker-trace inspection, and Korean progress updates. Identifying details and security findings are omitted.
This is evidence of orchestration, not an independent security assessment, validated findings or production readiness.
ScopeWeaver is a standalone derivative of
ARTEX
at upstream commit 160fe13, licensed AGPL-3.0.
Agent capabilities use the
norma
SDK; asset sync draws on
ScopeSentry.
Screenshots show the bundled fictional demo fixtures, labelled as demo data, and are not scans of live targets. Display type is self-hosted Schibsted Grotesk and JetBrains Mono (SIL Open Font License). Korean text uses the reader’s system Hangul typeface.