The hundred-eyed guardian for your codebase
Argus is an open-source security platform that unifies 20+ industry-standard scanning tools behind one CLI and MCP server.
What is Argus?
Argus wraps Semgrep, Trivy, OWASP ZAP, Gitleaks, tfsec, Bandit, Checkov, ansible-lint, and more behind a single, normalised interface. Run SAST, DAST, SCA, secret scanning, IaC audits, Terraform and Ansible checks, database and ML/LLM rules — from your terminal or through any MCP-compatible client.
The AI subscription is for the client (Cursor, Claude Desktop, VS Code Copilot, etc.) — Argus itself is always free and runs entirely on your machine.
All-seeing by design
Named after Argus Panoptes, the hundred-eyed giant of Greek mythology — Argus brings many scanners together so nothing slips through.
Security without lock-in
Every scanner runs locally. No vendor tokens, no cloud API keys, no paid tiers for the scanning itself.
Built for developers
CLI-first, MCP-native, and available via npm, pip, Go, Docker, and VS Code — pick the workflow that fits your stack.
Open source at the core
MIT licensed. Contributions welcome — scanners, clients, docs, and fixes all ship through GitHub.
GitHub repository metrics
Live stats from argus-code-scanning/argus-codescan-mcp. MIT licensed, built in the open.