
VulnAgent-X: A Layered Agentic Framework for Repository-Level Vulnerability Detection
VulnAgent-X is a research-focused multi-agent prototype for bug and vulnerability detection. It takes a local repository or diff as input, and outputs structured findings, evidence chains, localization, confidence, and experiment logs.
repo path or unified diffscreening -> context expansion -> scheduler -> router -> experts -> sceptic -> verification(stub) -> evidence fusionissue_typelocation(file + line range)evidence_summaryconfidenceseverityoptional_cwefix_hintevidence_chaincounter_evidencescreening: fast suspicious-region extraction (rules + metadata signals)context_expansion: fetch minimal sufficient local context around suspicious locationsscheduler: confidence-aware escalation policy (early_exit / expert_review / verification)router_agent: choose specialist agents per suspicious regionsemantic/security/logic: produce structured claims and evidence from different perspectivessceptic_agent: generate counter-evidence and confidence penaltiesverification: optional dynamic verification (currently a safe placeholder)evidence_fusion: merge all evidence and produce final findingsRequirement: Python 3.11+ (higher versions also work in this prototype).
cd /Users/xiaolu/Documents/Python_code/vulnAgentX
python3 -m venv .venv
source .venv/bin/activate
python -m pip install -e '.[dev]'
Analyze a repository:
.venv/bin/vulnagentx analyze --repo /path/to/repo --output json
Analyze a diff file:
.venv/bin/vulnagentx analyze --diff-file /path/to/patch.diff --output json
Short summary output:
.venv/bin/vulnagentx analyze --repo /path/to/repo --output summary
Start server:
.venv/bin/uvicorn vulnagentx.app.api:app --reload
Health check:
curl http://127.0.0.1:8000/health
Run analysis request:
curl -X POST http://127.0.0.1:8000/analyze \
-H "Content-Type: application/json" \
-d '{"repo_path":"/path/to/repo"}'
docker compose -f docker/docker-compose.yml up --build
.venv/bin/ruff check src tests
.venv/bin/mypy src
.venv/bin/pytest
{
"run_id": "...",
"findings": [
{
"issue_type": "command_injection",
"location": {"file_path": "app.py", "start_line": 42, "end_line": 42},
"evidence_summary": "Command execution surface detected...",
"confidence": 0.87,
"severity": "critical",
"optional_cwe": "CWE-78",
"fix_hint": "Avoid shell command composition...",
"source_agents": ["security_agent", "semantic_agent"],
"evidence_chain": [],
"counter_evidence": []
}
],
"metrics": {
"runtime_seconds": 0.07
},
"logs": []
}
| File | Purpose |
|---|---|
.env.example | Environment template for optional runtime settings (for example log level). |
pyproject.toml | Build system, dependencies, script entrypoints, pytest/ruff/mypy configuration. |
README.md | Main README with language switch buttons (default Chinese). |
README.zh.md | Full Chinese documentation. |
README.en.md | Full English documentation. |
docker/Dockerfile | Container image build file for API service. |
docker/docker-compose.yml | One-command local container startup. |
rules/semgrep/vulnagentx-rules.yml | Built-in Semgrep rules for injection/deserialization/unsafe C APIs. |
scripts/run_experiment.py | Batch dataset runner that writes JSONL predictions. |
scripts/evaluate.py | Metrics evaluator for experiment outputs. |
scripts/run_ablation.py | Component ablation runner (no_semgrep/no_treesitter/no_sceptic/no_verification). |
src/vulnagentx)