| Version | Supported |
|---|---|
| 0.1.x | ✅ |
Please do not open a public issue for security reports.
Email g.akashvarma@gmail.com with a description of the issue and, if possible, steps to reproduce. You can expect an acknowledgement within a few days and a fix or mitigation plan for confirmed issues.
Argus itself is a static browser app with no backend — no server-side attack surface, and all state lives in the browser's localStorage. The security-relevant components are the two optional companion CLIs, which run on the user's own machine:
argus-bridgespawns local processes to relay stdio MCP servers. It binds to127.0.0.1by default, parses the exec string argv-style, and rejects shell metacharacters unless--allow-shellis passed. The child's stderr is never forwarded to the browser. Do not expose it with--host 0.0.0.0on untrusted networks; prefer--cmdto pin a fixed command in shared or CI environments.argus-proxyforwards HTTP requests to enable cross-origin scans. It binds to127.0.0.1and refuses private/link-local address ranges unless--allow-privateis passed.
When scanning third-party MCP servers, treat their responses as untrusted input.