What can my agents do?
Every server, tool, hook and skill. Cross-server attack paths with evidence. Yes/no answers computed from the graph.
aspex scan · aspex explainWhat did they actually do?
Tool calls from your clients’ own logs. Kill chains and provenance labeled OBSERVED, INFERRED, POSSIBLE.
aspex trace · aspex exploreWhat changed?
New tools, poisoned descriptions, wider scope, new attack paths. Exit 1 in CI on drift you did not accept.
aspex lock · verify · diffRun this first
aspex with no arguments joins your MCP configs with your clients’ logs and shows one screen. Real output from the maintainer’s machine, nothing sent anywhere:
How it reasons
Three ideas are kept apart on purpose. Everything Aspex prints is one of them, and says which.What Aspex is not
- Not a proxy. Never in your agent’s request path.
- Not a blocker. It shows you. You decide.
- Not a SaaS. No account, no telemetry. The only network call is the download.
- Not omniscient. Cloud connectors it cannot scan are shown as “in use, never scanned”.
Quickstart
Install, see what your agents can do, harden it. About a minute.
Common workflows
Task first, command second. Where to start for what you want to do.
How Aspex reasons
Why a finding exists, and how to reproduce it.
Using a coding agent?
These docs are available as
llms.txt for your agent to read.