redshift-security-harness
v0.1.1
Published
Scoped, source-aware red-team security harness for local repositories.
Readme
What Is Redshift?
Redshift is a security harness for focused, source-aware red-team work. Give it a local target and a clear objective. It coordinates specialist agents to inspect the relevant code, challenge assumptions, and return one prioritized report in your terminal.
This is not a chat workspace or a general-purpose autonomous agent. Every assessment begins with an explicit target, stays within the requested repository scope, and ends with evidence-backed findings you can act on.
How It Works
- Define the component or path you want assessed.
- State the security question you want answered.
- Redshift maps the attack surface and assigns focused review work across trust boundaries, data flows, and supply-chain exposure.
- Findings are reconciled into a single report with evidence, impact, and recommended next actions.
Quick Start
npm start -- configure
npm start -- scan `
--target src `
--objective "Find authorization and untrusted-input paths"Check the proposed assessment scope before using a model:
npm start -- scan --target src --objective "Review the public API" --dry-runRun npm start -- scan --help for command options.
Bring Your Own Key
Run redshift configure once to choose a provider and save its model settings locally. Redshift supports OpenAI, Google Gemini, OpenCode Zen and Go, and local Ollama. OpenCode Zen and Go use the same OpenCode API key for Go subscribers. API-key entry is hidden in the terminal. Choose a model supported by your selected provider.
Your configuration is saved outside the repository in your user configuration directory. It is never committed with the project. Environment variables and command flags can still override saved settings for a single run.
What Redshift Reviews
- Entry points and exposed attack surfaces
- Authentication, authorization, tenancy, and privilege boundaries
- Untrusted data flowing into sensitive operations
- Dependencies, build paths, configuration, and release assumptions
- Candidate issues that benefit from a safe local validation step
Assessment Boundaries
Redshift is designed for authorized work against local source code.
- Targets must remain inside the selected repository root.
- Agents operate read-only and do not modify the source tree.
- Assessments do not probe external systems, use real credentials, or report secret values.
- Findings distinguish confirmed issues from likely risks, open questions, and hardening opportunities.
Using a remote model means the source excerpts it requests are sent to that provider. Configuration asks for explicit approval first. Configure only providers you trust with the repository under assessment.
Agent Roles
Redshift uses a small, purpose-built crew rather than a single general reviewer:
- Recon maps reachable surfaces and trust boundaries.
- Trust investigates identity, authorization, and privilege controls.
- Dataflow traces attacker-controlled input toward sensitive operations.
- Supply Chain examines dependency, configuration, and delivery risks.
- Validator performs narrow, safe local validation when needed.
- Reporter turns the collected evidence into the final terminal report.
The definitions are kept in agents/. The agent-to-agent coordination reference is available in blueprints/A2A_PORTABLE_PLAYBOOK.md.
License
Redshift is available under the MIT License.
