Sandboxed multi-scanner security for AI skills, MCP servers, and package trees — coverage honesty, SIE judging, heatmap posture, guided triage and fix. Scan what agents install; fail closed.
Meterian Security / Stability / Licensing badges mirror the public
Meterian project report
(dependency and policy scan for this GitHub repo — not a Tripwire scan adapter).
CI / Complexity badges reflect GitHub Actions on main. The Nightly badge is
A — comprehensive T4 (daily 02:00 UTC: Semgrep, CodeQL, full secrets/Trivy,
dashboard tests, coverage snapshots, complexity, dep audit). B — Supply chain
(SBOM / Meterian / Chalk) is weekly Mon 03:00 UTC; C — Mutation
(Stryker / mutmut, non-gating) is 1st+15th 04:00 UTC. PR CI is
ultra-minimal (ship-path coverage + OSV + targeted scans) — see
CONTRIBUTING and
docs/README.md § CI workflows.
| If you want to… | Go here |
|---|---|
| Try a hosted dashboard (no clone) | Live demo on neomatrix369.github.io |
| Watch the demo walkthrough | YouTube — Tripwire dashboard tour |
| Try a safe demo (no cloud accounts) — Recommended | QUICKSTART — Try the demo |
| Run a real Live scan — Advanced | QUICKSTART — Live |
| Change the code | CONTRIBUTING |
| Understand the system | Architecture · docs hub · Status |
Tripwire helps technical teams assess AI skills, MCP servers, and package manifests before they rely on them. It discovers targets, runs the enabled scanner adapters in an isolated Modal sandbox, stores findings in Supabase, and brings them together in one dashboard (Live or Mock) with coverage honesty, optional SIE judging, and a guided triage/fix flow.
Optionally, after each scan batch it runs a tiered router: Superlinked SIE triages findings, and Alibaba Cloud Model Studio escalates when scanners disagree or coverage looks incomplete (ADR-0016).
| Layer | Provider / tool | Role |
|---|---|---|
| Platform | Modal | Isolated scan sandbox (Docker image + Python adapters) |
| Platform | Supabase | Postgres + Realtime store for runs, scanners, findings |
| Scanner | Cisco Skill Scanner / MCP Scanner / AI Defense | Skill and MCP security inspection |
| Scanner | Snyk | Skills/MCP: snyk-agent-scan. Packages: snyk test SCA (npm/Python/Go/… — not Rust/Cargo; unsupported trees → not_applicable) |
| Scanner | Tessl | Five skill capabilities: Lint (auth-free), Review (Quality), Scenario Generation, Eval, Review (Security) |
| Scanner | Cargo Audit (RustSec) | Rust/Cargo SCA when Cargo.lock / Cargo.toml present |
| Scanner | DepShield (depshield-mcp) |
Dependency audit (npm + PyPI via OSV.dev); no credentials; skills, MCP, and packages |
| Scanner | Ossprey (ossprey-cli) |
Malware / malicious-package scan (skills, MCP, packages); needs OSSPREY_API_KEY |
| Router (optional) | Superlinked SIE | Cheap post-scan triage on every item |
| Router (optional) | Alibaba Cloud Model Studio | Escalation only when SIE signals |
Missing Snyk / Cisco / Tessl / Ossprey keys → that scanner reports skipped /
needs_setup / skipped_missing_credential rather than claiming a complete scan.
DepShield always runs when the sandbox image includes it (no secret sync).
When every package scanner is not_applicable or skipped (e.g. no Cargo Audit
and no other engine completed), the card is NO COVERAGE, not green.
UNSCANNED remains for never-run / no usable scan record.
Cargo / Rust crates: Cargo Audit (RustSec) runs when Cargo.lock or
Cargo.toml is present.
Capability honesty and evidence states: docs/STATUS.md ·
inventory: ARCHITECTURE §0 ·
Ossprey key allowlist: OPTIONAL_SCANNER_KEYS.
Tripwire is currently an early-adopter tool with a hands-on setup and management
component. It is a good fit if you are comfortable using a terminal and shell,
managing local tooling and environment variables, editing .env and other
configuration files carefully, creating cloud/vendor accounts, and using command
output to resolve a setup issue.
| You are... | You want to... |
|---|---|
| An AI-tooling developer or team | Assess skills, MCP servers, and package trees before using or sharing them |
| A platform, operations, or security practitioner | Run and maintain scans for a team |
| A contributor | Extend scanner support, the CLI, or the dashboard |
You do not need to be a security specialist, but you should be ready to interpret findings and decide when to escalate them. The optional Mock preview is available for evaluating the dashboard without accounts; real scans require the setup below.
If you plan to change Tripwire, start the contributor setup after cloning: it installs the commit and push hooks before your first change.
Follow this order before running a scan or opening the Live dashboard. The Quickstart supplies the commands; the linked guides explain each decision before you make it.
- Check the required tools and install the CLI.
- Create the accounts you need: Supabase,
Modal, then add Snyk, Tessl, and Cisco
(Skill/MCP LLM + optional AI Defense) credentials with the
environment-variable procurement guide.
DepShield needs no keys. Add
OSSPREY_API_KEYwhen you have Ossprey access (otherwise that adapter skips safely). For optional post-scan routing (ADR-0016), also set up Superlinked SIE (required for routing) and optionally Alibaba Cloud Model Studio (escalation only). Key map for every.envname: env-vars.md (mirrors.env.example). - Create
.envonly after you have the values, then fill it with env-vars.md as the single key reference. - Bootstrap Supabase and deploy the Modal scan app with the Live setup commands.
- Run a fixture scan and open the Live dashboard from the
Quickstart. After routing, use
tripwire routeto re-run a batch and read router results for pathway strips and Escalated / SIE-only filters.
Supabase and Modal are required for Live results. If Snyk, Tessl, Cisco, or Ossprey credentials are absent, Tripwire reports that scanner as skipped rather than calling the scan complete. SIE and Model Studio are optional: without SIE keys, scans still complete and auto-route logs a warning and skips. With SIE but without Model Studio, SIE-only reviews still log.
Use Mock demo data only when you want a no-account look at the UI; it does not replace the Live setup above or produce a scan result. Prefer the hosted demo when you do not need a local clone, or watch the demo walkthrough on YouTube.
git clone https://github.com/neomatrix369/tripwire.git
cd tripwire
node scripts/serve-dashboard.mjsOpen http://127.0.0.1:8765/.
On the dashboard toolbar, Skills can be triaged by Tessl quality score using Quality ≥ 80, Quality < 80, and No quality score tabs (skills only; MCP servers are excluded from quality buckets but remain visible on all tabs).
The first visit shows a landing intro screen (threat statistics, architecture overview,
shipped skills, and roadmap). Click Open Dashboard → to proceed to the scan results
view (primary Dashboard tab: inventory KPIs, filters, and cards). Use the secondary
Workflow tab for Run → Triage → Investigate → Fix → Verify → Report. Simple/Expert
on Workflow only changes finding-detail density, not which primary tab you are on.
Operator-visible judge/coverage narration and L→R soft-amend (parent target
meta, multi-select, role-labelled models) are IMPLEMENTED / VERIFIED (unit) on
main via Wave R slice 75 (PR #163);
Workflow chrome polish (shared panel typography + denser Triage filters) via
slice 76 (PR #165).
Dismiss the intro with Open Dashboard → before Workflow (the Workflow tab
does not clear the intro overlay). Slice 77 (branch) hardens Run CTA / count
reconciliation / triage disposition persistence / Verify honesty — see
docs/STATUS.md.
The "About" nav button toggles the intro back on at any time; the choice is
remembered in sessionStorage.
Visual identity v2: cream paper, tan primary CTA, and AA-readable ink tokens (Fraunces display headings) — shipped via PR #96. Screenshots in docs/screenshots/ regenerated 2026-09-21.
After installing the CLI, you can also validate target discovery locally without accounts or a scan:
tripwire scan --dry-discover ./fixtures/skills/safe-csv-cleanerTripwire’s Live path is a short pipeline. Each hop uses a concrete piece of the stack (same names as the badges above):
| Step | What runs | Stack | Setup |
|---|---|---|---|
| Discover | CLI finds skills / MCP servers / packages (tripwire scan --dry-discover or a real scan; Wave P package path on main) |
Node.js CLI | setup-commands · prerequisites |
| Scan | Adapters run in an isolated sandbox; CLI prints scanner inventory, coverage ledger, and [evidence] honesty rows (slices 63/65/66); optional tripwire judge panel (slice 67) |
Modal (+ Docker), Cisco / Snyk / Tessl / DepShield / Cargo Audit / Ossprey | modal-setup · env-vars |
| Store | Findings and scan_run rows land for the dashboard | Supabase / Postgres | supabase-setup |
| Route (optional) | Every item through SIE; escalate only when signaled | Superlinked SIE → Alibaba Cloud Model Studio via tripwire route / auto-route |
sie-setup · model-studio-setup |
| Review | Heatmap, drawers, pathway strips, Escalated / SIE-only filters; Run→Report chrome on Workflow tab (slices 75–77 on main #163/#165/#169) |
Dashboard (Live or Mock) | reading-router-results · screenshots |
Mock skips Discover→Scan→Store and still shows Review (plus router fixtures).
Without SIE keys, Route warns and skips; scanner results still store. Sample CLIs
for router backends (no full batch): prototypes/sie-studio/,
prototypes/model-studio/.
flowchart LR
discover["Discover<br/>skills / MCP / package"] --> scan["Scan<br/>Modal + Cisco/Snyk/Tessl/DepShield/Cargo Audit/Ossprey"]
scan --> store["Store<br/>Supabase"]
store --> inventory["CLI inventory / coverage / evidence"]
inventory --> route["Route optional<br/>SIE → Model Studio"]
route --> review["Review<br/>Dashboard"]
How to read strips and filters after Route: reading-router-results.md.
CLI scan — Modal (live)
|
Dashboard — Mock overview
|
Workflow — Run (Mock)
|
Skill — Red (Mock)
|
MCP — Red (Mock)
|
Full gallery (Escalated / SIE-only, Workflow Triage/Verify, severity filters, list view) → docs/screenshots/
| Your task | Start here |
|---|---|
| Check tools and technical fit | Prerequisites |
| Follow the Install → Live path map | Path commands · onboarding cheatsheet |
| Create the Supabase project | Supabase setup |
| Deploy the Modal scan app | Modal setup |
Procure scanner and router .env keys |
Environment variables |
| Run your first Live scan | Quickstart · setup commands |
| Preview Mock UI or dry-discover locally | Optional local validation |
| Enable SIE / Model Studio routing | SIE setup · Model Studio setup · tripwire route |
| Interpret pathway strips / Escalated / SIE-only | Reading router results |
| Browse CLI / dashboard / Workflow screenshots | Screenshot gallery |
| Smoke-test SIE or Model Studio alone | SIE sample CLI · Model Studio sample CLI |
| Understand results and system shape | Capability status · Architecture · ADRs |
| Contribute or maintain | Contributing · command catalog |
| Report a vulnerability | SECURITY |
Full map (including planning / CI): docs/README.md.
