Point it at a repo. Maroon Elephant detects your AI, agentic, and MCP components, maps every risk to the OWASP 2026 standards, and hands you an enterprise governance verdict — deterministic-first, zero-dependency, local-first.
Deterministic findings with file:line evidence — then a governance verdict you can act on.
LLMs read instructions and data from one flat token stream — the root cause behind prompt injection, data exfiltration, excessive agency, and memory poisoning. The market is full of runtime products, but there's no strong open-source, repo-driven, design-time threat modeler for AI systems. That's the gap.
Fingerprint LangChain, LangGraph, CrewAI, MCP servers, vector DBs, model SDKs — and build an AI inventory / AI-BOM.
Infer the architecture, place components on MAESTRO's 7 layers, and produce a design-time threat model as code.
Score with AIVSS and place the repo on the AT×L governance matrix — from "Well-governed" to "DO NOT DEPLOY".
🐘 Imagine a very careful elephant that reads your code and asks: “If this app uses AI, how could someone trick it or steal from it?”
It doesn't guess. It looks for exact, known-risky patterns — a password typed into the code, an AI that can run shell commands, a tool that auto-approves dangerous actions — and points at the exact line.
Then it writes you a report card: what AI you're running, what could go wrong (in plain standards everyone trusts), and one clear next step to be safer.
Your code never leaves your machine. The AI parts are optional — the careful elephant works entirely offline.
Every finding comes from the deterministic engine with file:line evidence and a stable fingerprint. The optional LLM layer can only describe a finding that already exists — it can never invent one. That's what makes the output auditable.
Local path, git URL, or uploaded zip — safely (no path traversal).
Component inventory → AI-BOM + the system's adoption-tier signals.
Rules + AST taint + Lethal-Trifecta + Grey Panda, merged & deduped.
AIVSS severity + the AT×L governance verdict.
SARIF · CycloneDX AI-BOM · threat-model-as-code · governance.
Every finding carries a full cross-framework tuple: OWASP LLM/ASI/DSGAI · MAESTRO layer · AIVSS · NHI · MITRE ATLAS/ATT&CK · CWE · NIST · regulatory.
The calm, deterministic, in-the-file guardian — regex + AST, OWASP-tagged, ships its own MCP server. The ground truth.
The orchestrating, design-time, multi-repo threat-modeler that stands on top — architecture, governance, GitHub, and a UI.
# scan a repo, ranked report in seconds $ maroon scan . $ maroon scan https://github.com/org/repo # CI-ready: SARIF + exit codes $ maroon scan . -f sarif -o results.sarif --fail-on high
# local web UI — scan an org, worst-first $ maroon serve # its own MCP server, for agents & IDEs $ maroon serve-mcp
Drop-in workflow → SARIF in the Security tab + PR annotations. Public repos free.
Inline diagnostics with OWASP tags and the governance verdict in your status bar.
Bring your own key (or a local model). Keys never leave your machine; air-gapped mode makes zero external calls.
Static analysis, Python-first deep coverage, governance checks that say “needs attestation” rather than faking a pass. Read the research and the spec: