
cynative v1.6.0
केवल पढ़ने योग्य AI एजेंट जो आपके क्लाउड, कोड और रनटाइम इंफ्रास्ट्रक्चर की जाँच करता है ताकि गलत कॉन्फ़िगरेशन, लीक हुए रहस्यों और विशेषाधिकार वृद्धि मार्गों को सत्यापित, साक्ष्य-समर्थित निष्कर्षों के साथ उजागर किया जा सके।

अपने स्वयं के सुरक्षा एजेंट बनाएं
आपके इंफ्रास्ट्रक्चर तक लाइव, रीड-ओनली पहुंच वाले सुरक्षा एजेंट के लिए ओपन-सोर्स फ्रेमवर्क।
क्विकस्टार्ट · अंतर्निहित एजेंट · आपका पहला एजेंट · डॉक्स
अपने इंफ्रास्ट्रक्चर से कुछ भी पूछें। Cynative आपके कोड, क्लाउड और रनटाइम पर फ्रंटियर मॉडल चलाता है - GitHub, GitLab, AWS, GCP, Azure और Kubernetes को एक सिस्टम के रूप में समझता है - और सत्यापित उत्तरों के साथ वापस आता है।```bash cynative "what in my cloud is publicly exposed that shouldn't be?"
**45 अंतर्निहित एजेंट** AWS, GCP, Azure, GitHub और Kubernetes के लिए - privilege escalation, public exposure, supply chain, detection coverage और अधिक - या आप एक markdown फ़ाइल में अपना खुद का लिख सकते हैं।
एक प्रश्न आपके पूरे स्टैक में फैल जाता है: Cynative एक ephemeral sandbox में कोड लिखता और चलाता है, आपके APIs को समानांतर में क्वेरी करता है। प्रत्येक निष्कर्ष को क्रॉस-चेक किया जाता है और उसके मूल तक ट्रेस किया जाता है।
कोडिंग एजेंट और MCP सर्वर के विपरीत, यह **read-only by construction** है: प्रत्येक कॉल को गेट किया जाता है और प्रमाण-पत्र संलग्न होने से *पहले* अधिकृत किया जाता है - इसे विश्वास के साथ production पर इंगित करें।
<!-- END agent-about -->
<p align="center">
<img src="https://assets.kitploit.com/production/public/readmes/9087/1b3db179a03479f5951d624c8adbb4890465aa86d038d3312dc9aec9801bcfb9.gif"
alt="cynative auditing a CI to cloud privilege escalation"
width="900">
</p>
## आपके एजेंट क्या प्राप्त करते हैं
- **Code-to-runtime**: AWS, GCP, Azure, किसी भी K8s, GitHub और GitLab के माध्यम से तर्क करता है
- **Sandbox**: बड़े पैमाने पर शोध के लिए कोड उत्पन्न और चलाता है, इसकी अपनी कोई नेटवर्क या होस्ट एक्सेस नहीं होती
- **Action-gate**: प्रत्येक कॉल को उसकी आवश्यक IAM क्रियाओं में हल करता है और प्रमाण-पत्र संलग्न होने से पहले read-only नीति लागू करता है
- **Evidence-backed**: प्रत्येक निष्कर्ष को सत्यापित करने के लिए क्रॉस-चेक करता है
- **Sovereign**: एक बाइनरी, आपका मॉडल, आपका डेटा आपका ही रहता है
## Quickstart
इंस्टॉल करें और एक LLM सेट करें:
<!-- BEGIN quickstart-example -->```bash
brew install cynative/tap/cynative
export CYNATIVE_LLM_PROVIDER=anthropic
export CYNATIVE_LLM_MODEL=claude-opus-5
export ANTHROPIC_API_KEY=...
यह आपके शेल में पहले से मौजूद क्रेडेंशियल्स को उठा लेता है। एक अंतर्निहित एजेंट चलाएँ:```bash cynative -p --agent aws-network-exposure
या इससे कुछ भी पूछें:```bash
cynative -p "which IAM roles can escalate to admin?"
cynative -p "high-risk cloud permissions, trace each to the PR where it was granted"
cynative -p "cloud credentials leaked in source code and their current blast radius"
cynative "live cloud resources absent from IaC - drift" # starts an interactive session
cat findings.json | cynative -p "triage these findings by exploitability"
अंतर्निहित एजेंट
45 एजेंट बाइनरी में एम्बेडेड हैं। प्रत्येक एक विशिष्ट प्रश्न के लिए समीक्षित प्रॉम्प्ट है।
| एजेंट | उदाहरण के लिए | |
|---|---|---|
| AWS | 20 | aws-privilege-escalation, aws-public-storage, aws-unpatched-workloads, aws-supply-chain |
| Azure | 11 | azure-keyvault-exposure, azure-storage-exposure, azure-privilege-escalation |
| GCP | 5 | gcp-public-bindings, gcp-static-credentials, gcp-inference-exposure |
| GitHub | 4 | github-workflow-trust, github-unpatched-dependencies, github-branch-protection |
| Kubernetes | 5 | k8s-pod-privilege, k8s-self-managed-apiserver-access |
| cynative agents list # every agent, with its description | ||
| cynative agents show # the exact prompt that would run |
पूरी सूची, जिसमें प्रत्येक एजेंट का एक-पंक्ति विवरण है, यहाँ है
[docs/agents-catalog.md](https://github.com/cynative/cynative/blob/main/docs/agents-catalog.md)।
## आपका पहला एजेंट
`cynative agents show <name>` वह सटीक फ़ाइल प्रिंट करता है जिसे कोई एजेंट चलाएगा। अपना स्वयं का संस्करण बनाने के लिए, इसे एक नए नाम के साथ अपनी एजेंट्स डायरेक्टरी में कॉपी करें और इसे संपादित करें:```bash
mkdir -p ~/.cynative/agents
cynative agents show aws-public-datastores > ~/.cynative/agents/my-aws-public-datastores.md
# edit ~/.cynative/agents/my-aws-public-datastores.md, then:
cynative -p --agent my-aws-public-datastores
एक एजेंट एक markdown फ़ाइल है: सख्त YAML frontmatter जिसका एकमात्र key
description है, फिर prompt body। फ़ाइल का नाम ही नाम है। ~/.cynative/agents/ में
मौजूद फ़ाइल समान नाम के built-in पर प्राथमिकता लेती है, इसलिए दोनों को बनाए रखने के लिए
अपनी प्रति को एक अलग नाम दें। प्रारूप के लिए docs/agents.md देखें।
एजेंट चलाना```bash
cynative -p --agent aws-public-datastores "AWS account 128149835728 only" # with a task cynative -p --agent aws-public-datastores # without cynative --agent aws-public-datastores # seeds an interactive session
`--agent` `-p`, `--auto-approve`, `--config` और piped stdin के साथ compose होता है, इसलिए वही फ़ाइल विकास के दौरान interactively चलती है और स्थिर होने पर non-interactively।
Agents `~/.cynative/agents/` से और binary में built-in सेट से पढ़े जाते हैं; समान नाम के built-in पर user फ़ाइल जीतती है। `cynative agents list` हर agent को उसके source के साथ दिखाता है और shadowed copies को चिह्नित करता है, और `cynative agents show <name>` वह सटीक फ़ाइल प्रिंट करता है जो चलेगी।
## क्या MCPs वाला coding agent यह नहीं कर सकता?
| | Coding agent + MCPs | Cynative |
|---|---|---|
| Throughput | प्रति call एक action | Sandboxed code लिखता है जो calls को concurrently fan out करता है - कम tokens, तेज़ उत्तर |
| Findings | Unverified output | Verifier हर finding को live evidence के विरुद्ध cross-check करता है |
| Read-only | Opt-in read filter | डिफ़ॉल्ट रूप से on, fails closed - आवश्यक IAM actions security-audit policy के विरुद्ध जाँचे जाते हैं। `secretsmanager:GetSecretValue` एक IAM *Read* है: filter इसे allow करता है, `SecurityAudit` इसे block करता है |
| Credentials | Ambient, unchanged | STS session read-only तक scoped - AWS भी boundary enforce करता है |
| Blast radius | आपका shell, कोई भी network | Research code एक sandbox में चलता है जिसमें host access नहीं, network आपकी mapped services तक pinned |
| Secrets | Model को as-is भेजे जाते हैं | Model को भेजने से पहले tool output से redact किए जाते हैं |
| Supply chain | आपके creds के साथ चलने वाले third-party MCPs और skills | एक open-source binary, connectors built in |
| Audit trail | Bिखरे session logs, best effort | हर tool call का fail-closed JSONL log - अगर record नहीं कर सकता, तो abort कर देता है |
एक binary, आपका model endpoint, आपका account। इसे उस cloud में एक instance पर चलाएँ जिसका यह audit करता है, उस cloud के managed inference के माध्यम से, और कुछ भी आपके environment से बाहर नहीं जाता: security आपके infrastructure पर, आपके infrastructure के भीतर से।
## Installation