Skip to content
Back to the index

argus-idor

PyPIInfrastructure

No liveness check has reached it yet; it is registered on PyPI and has been in the index since 8 Oct 2026. How this is checked

argus-idor is an open-source autonomous security agent for identifying insecure direct object references and broken access control. It generates and executes real exploits in an isolated environment to validate findings for security teams and penetration testers.

Inferred · not functionally tested

Open SourceMITCLISelf-hosted
Visit PyPI

Overview

6 features

Purpose: Proving IDOR and broken access control vulnerabilities without manually creating and running exploits.

Inferred · not functionally tested

Audience: application security engineers and penetration testers

Inferred · not functionally tested

Functions: agents, data_extraction

Inferred · not functionally tested

Interfaces: API: unknown · MCP: unknown · CLI: indicated (inferred, not tested) · Self-hosting: indicated (inferred, not tested)

Recorded constraints: pricing: open_source · license: MIT · platforms: CLI · deployment: cli, self_hosted

Constraint provenance is unknown; confirm requirements with the publisher.

Record sources: pypi.org. These links do not verify the individual claims.

In the Penetration testing & red teaming space, argus-idor takes a focused approach. Inferred · not functionally tested: It focuses on proving IDOR and broken access control vulnerabilities without manually creating and running exploits. Inferred · not functionally tested: It is built as an open-source project for application security engineers and penetration testers. Basis unknown · not verified: The project is open source (MIT). Basis unknown · not verified: It ships for the command line, and it can be self-hosted.

argus-idor first shipped in 2026. Inferred · not functionally tested: Key capabilities include IDOR detection, access control testing, and exploit generation.

Summary written by a language model from the project’s public pages.

Tasks: Inferred · not functionally tested

  • IDOR detection
  • Access control testing
  • Exploit generation
  • Exploit execution
  • Isolated execution
  • Finding validation

Topics: Inferred · not functionally tested

Tags
idor-detectionbroken-access-controlexploit-validationsecurity-agent
AI capabilities
Code
Inference: Local

JSON profile · Text profile · Access guide

Built with & integrations

Runs on
CLISelf-hosted

Trust & compliance

License
MIT
Public signals
HTTPSOpen SourceFree tier

Indexing history

1

What PulseGate has recorded for this listing

  1. Indexed8 Oct · 10:10 UTC
    argus-idor seen via PyPI Bulk Enumerator
    Source: PyPI Bulk Enumerator · Open

Frequently asked questions about argus-idor

What does argus-idor do?
Inferred · not functionally tested: Argus-idor focuses on proving IDOR and broken access control vulnerabilities without manually creating and running exploits. It is catalogued under Penetration testing & red teaming on PulseGate.
Who is argus-idor for?
Inferred · not functionally tested: argus-idor is an open-source project built for application security engineers and penetration testers.
Does argus-idor have a free plan?
Basis unknown · not verified: Yes — argus-idor is open source under the MIT license and free to use.
What platforms does argus-idor run on?
Basis unknown · not verified: argus-idor runs on the command line. It can also be self-hosted.
Is argus-idor still active?
Unverified. argus-idor has not been re-checked since it entered the index, so there is no finding either way — and only a positive finding would say otherwise.
What are alternatives to argus-idor?
Similar projects tracked by PulseGate include Argus, argus-redteam-agent, and argus-panoptes.Argusargus-redteam-agentargus-panoptes
When did argus-idor launch?
argus-idor first shipped in 2026.
Is argus-idor open source?
Basis unknown · not verified: Yes — argus-idor is open source under the MIT license.

Similar projects

Closest matches by what these projects do