
로컬 LLM 기반 보안 분석을 위한 Python 라이브러리로, Ghidra 바이너리 분석, C/C++ 취약점 스캐닝, 자동 리버스 엔지니어링 및 보고서 생성을 위한 MCP 도구 통합을 제공합니다.
TrustedSec LLM Library는 도구 사용을 지원하는 로컬 LLM과 상호작용하기 위한 Python 라이브러리입니다. 로컬 LLM 엔드포인트와 MCP(Model Context Protocol) 통합을 활용하여 기존에는 최첨단 모델에서만 가능했던 대규모 워크플로우를 실행할 수 있습니다.
# 저장소를 클론하거나 복사
git clone https://github.com/trustedsec/ts_llmlib.git
cd ts_llmlib
# pip로 설치
pip install -e .
ts_llmlib/ 디렉토리를 프로젝트에 복사:
cp -rf ts_llmlib /path/to/your/project/
from ts_llmlib import ChatSession
# 기본값으로 초기화 (http://localhost:1234/v1/chat/completions에 연결)
chat = ChatSession()
# 프롬프트 실행
response = chat.run_prompt("What files are in the current directory?")
print(response['content'])
from ts_llmlib import ChatSession
# 사용자 정의 설정으로 구성
chat = ChatSession(
system_prompt="You are a helpful assistant that uses file tools.",
tool_list=[], # 빈 리스트 = 기본 파일 도구 사용
mcp_servers={
"default": "http://localhost:3000/mcp"
},
llm_endpoint_url="http://localhost:1234/v1/chat/completions",
model_name="qwen3-coder-next",
timeout=60,
max_runtime=300
)
response = chat.run_prompt("Write 'hello' to /tmp/greeting.txt")
print(response['content'])
from ts_llmlib import ChatSession
chat = ChatSession()
history = [
{"role": "user", "content": "What is 2+2?"},
{"role": "assistant", "content": "The answer is 4."}
]
response = chat.run_prompt("Can you write that to a file?", history=history)
| 도구 | 매개변수 | 설명 |
|---|---|---|
read_local_file | path: str | 로컬 파일의 내용을 읽습니다 |
write_local_file | path: str, content: str | 로컬 파일에 내용을 씁니다 |
list_directory | path: str | 경로의 파일과 디렉토리를 나열합니다 |
MCP(Model Context Protocol)는 외부 도구 및 서비스와의 통합을 가능하게 합니다. MCP 서버가 구성되면 ts_llmlib는 다음을 수행합니다:
from ts_llmlib import ChatSession
chat = ChatSession(
mcp_servers={
"ghidraSvr": "http://localhost:8081/sse"
},
llm_endpoint_url="http://localhost:1234/v1/chat/completions",
model_name="qwen3-coder-next"
)
# 채팅 세션은 자동으로 Ghidra 도구를 가져와 통합합니다.
# (list_methods, decompile_function, get_xrefs_to 등)
ts_llmlib는 RPC 스타일과 SSE(Server-Sent Events) 엔드포인트를 모두 지원합니다:
http://localhost:3000/mcphttp://localhost:3000/sse (RPC 호출을 위해 자동으로 /mcp로 변환됨)ChatSession(
system_prompt: str | None = None,
tool_list: list | None = None,
mcp_servers: dict[str, str] | None = None,
llm_endpoint_url: str = "http://localhost:1234/v1/chat/completions",
model_name: str = "default",
timeout: int = 60,
max_runtime: int = 300
)
매개변수:
system_prompt (str | None): 사용자 정의 시스템 프롬프트. 기본값은 최소한의 어시스턴트 프롬프트입니다.tool_list (list | None): 사용자 정의 도구 정의 목록. 빈 리스트는 내장 도구를 사용합니다.mcp_servers (dict[str, str] | None): 서버 이름을 URL에 매핑하는 딕셔너리.llm_endpoint_url (str): LLM API 엔드포인트의 URL.model_name (str): LLM 엔드포인트의 모델 식별자.timeout (int): HTTP 요청 시간 초과(초).max_runtime (int): 프롬프트 최대 실행 시간(초).response = chat.run_prompt(
user_prompt: str,
conversation_history: list[dict] | None = None,
disable_tools: list[str] | None = None,
max_runtime: int | None = None
) -> dict
매개변수:
user_prompt (str): 사용자의 메시지 또는 질문.conversation_history (list[dict] | None): 선택적 대화 기록(role/content 쌍 목록).disable_tools (list[str] | None): 이 호출에서 비활성화할 도구 이름 목록.max_runtime (int | None): 이 특정 호출에 대한 기본 최대 실행 시간을 재정의합니다.반환값:
{
"content": str, # LLM 응답 텍스트
"tool_calls": list, # 실행된 도구 호출 목록 (있는 경우)
"usage": dict | None, # LLM에서 사용 가능한 토큰 사용량
"error": str | None # 실패 시 오류 메시지
}
ToolRegistry는 채팅 세션에서 사용 가능한 모든 도구를 관리합니다:
tool_list 매개변수를 통한 사용자 정의 도구기본 경로를 재정의하려면 다음 변수를 설정할 수 있으며, 이들은 ChatSession에서 확인됩니다.
TS_LLM_MODEL=qwen3-coder-next TS_LLM_ENDPOINT=http://HOSTNAME:1234/v1/chat/completions
# 사용 예제
export TS_LLM_MODEL=qwen3-coder-next
export TS_LLM_ENDPOINT=http://HOSTNAME:1234/v1/chat/completions
ts_llmlib-redclippy
# 또는
TS_LLM_MODEL=qwen3-coder-next TS_LLM_ENDPOINT=http://HOSTNAME:1234/v1/chat/completions ts_llmlib-redclippy
보안 취약점에 대해 C/C++ 소스 파일을 분석합니다:
ts_llmlib-cpp-analyze <source_folder> <output_folder>
Ghidra 통합을 통한 리버스 엔지니어링 바이너리 분석:
# 기본 분석
ts_llmlib-ghidra-analyze <output_folder>
# 이름 변경 전용 모드 (첫 번째 패스)
ts_llmlib-ghidra-analyze --rename_only <output_folder>
# 이전에 이름이 지정되지 않은 함수만 처리
ts_llmlib-ghidra-analyze --process_unnamed_only <output_folder>
# 호출 관계 그룹화를 위한 그룹 분석
ts_llmlib-ghidra-analyze --grouped <output_folder>
--rename_only를 사용하지 않고 실행을 완료한 후 다음을 실행하여 구조를 정리할 수 있습니다:
ts_llmlib-ghidra-cleanup <input_folder> <output_folder>
JSON 검토 파일에서 형식화된 취약점 보고서를 생성합니다:
ts_llmlib-ghidra-report <review_folder>
RedClippy Qt 기반 채팅 인터페이스를 실행합니다 (이 예제는 pyside6가 필요합니다):
ts_llmlib-redclippy
ts_llmlib는 OpenAI 호환 API 엔드포인트에 연결됩니다. 일반적인 로컬 LLM 서버:
| 서버 | 기본 URL |
|---|---|
| Ollama | http://localhost:11434/v1/chat/completions |
| LM Studio | http://localhost:1234/v1/chat/completions |
| vLLM | http://localhost:8000/v1/chat/completions |
두 가지 시간 초과 설정이 실행을 제어합니다:
timeout): 단일 API 요청의 최대 시간max_runtime): 프롬프트 처리에 허용되는 총 실제 시간 (도구 호출 포함)두 제한 중 하나라도 초과되면 응답에 오류 메시지가 포함됩니다.
모든 오류는 응답 사전에 반환됩니다:
response = chat.run_prompt("Some prompt")
if response.get('error'):
print(f"Error: {response['error']}")
else:
print(response['content'])
max_runtime 제한을 초과했습니다ts_llmlib/
├── __init__.py # 패키지 초기화, ChatSession 내보내기
├── client.py # LLM 엔드포인트로 HTTP 요청을 위한 LLMClient
├── chat.py # ChatSession 클래스 (주요 API)
├── mcp.py # MCP 통합을 위한 MCPClient
├── tools.py # 도구 관리를 위한 ToolRegistry
├── HOW_TO_TS_LLMLIB.md # 원본 문서
└── examples/ # 예제 스크립트
├── c_cpp_analyze.py # C/C++ 취약점 분석 스크립트
├── redclippy.py # Qt 기반 GUI 채팅 애플리케이션
├── ghidra_analyze.py # MCP 통합을 통한 Ghidra 바이너리 분석
├── ghidra_vuln_report.py # 취약점 보고서 생성기
├── ghidra_cleanup.py # 출력 파일 재구성 유틸리티
└── example_ts_llmlib.py # 라이브러리 사용법을 보여주는 예제 스크립트
pyproject.toml # 최신 Python 패키지 구성 (스크립트는 여기에 정의됨)
LICENSE.txt # BSD-3-Clause 라이선스
README.md # 이 파일
BSD-3-Clause 라이선스 - 자세한 내용은 LICENSE.txt 파일을 참조하십시오.
기여를 환영합니다! 언제든지 Pull Request를 제출해 주세요.
git checkout -b feature/AmazingFeature)git commit -m 'Add some AmazingFeature')git push origin feature/AmazingFeature)