Open source · local-first security assessment workbench 開源軟體 · 在你電腦上執行的整合式資安評估工作台

Find risks. Act on them. 找出問題,知道怎麼做。

Check your code, websites and company systems from one desktop app. Get one report that explains what needs attention, why it matters and what you can do next. 在一個桌面程式裡,檢查你的程式碼、網站與公司系統。看一份報告,了解哪裡需要注意、為什麼重要,以及接下來可以怎麼做。

v0.5.0 stable release. Windows setup .exe and MSI (unsigned; SmartScreen may warn), macOS Universal .dmg (not notarized; run one xattr command before the first launch), and Debian/Ubuntu .deb. The app prepares its own scanning runtime; Docker is not required. v0.5.0 正式版。提供 Windows 安裝程式 .exe 與 MSI(未簽章,SmartScreen 可能警告)、macOS Universal .dmg(未經 Apple 公證,第一次開啟前執行一行 xattr 指令)與 Debian/Ubuntu .deb。應用程式會自行準備掃描環境,不需要另外安裝 Docker。

See the install steps and the release notes. 詳見安裝步驟與發布說明。

New in v0.5.0: related findings grouped into problem cards, fresh folder snapshots when checking fixes, and clearer before-and-after reports. What changed. v0.5.0 更新:相關發現合併成問題卡;修復重掃讀取最新資料夾,報告清楚標出修復前後的變化。查看更新內容。

  • 25 tools in v0.5.0 個 v0.5.0 工具
  • 3 ways to start 種開始方式
  • 1 unified report 份統一報告
EXAMPLE REPORT 報告示意 Saved 已儲存

What needs attention 需要優先處理的項目

Code, website and internal system results together 程式碼、網站與內部系統,結果一起看

Possible exposed password or key 可能留下了密碼或金鑰 repository / api-service
Critical 嚴重
Website security setting needs attention 網站安全設定需要注意 website / portal.example
High 高
No problems in completed checks 已完成檢查未發現問題 internal system / 10.0.0.24
Checked 已檢查
2 priority actions 2 個優先動作 1 check still needed 1 項還需要檢查
You choose what to check 由你決定檢查範圍 Network checks contact only the targets and ports you approve. 網路檢查只會連到你核准的目標與連接埠。
Your project stays as it is 保留專案原貌 The app checks a copy of your local project. It does not change your files or apply fixes. 程式會複製本機專案來檢查,不會改動檔案或自行套用修正。
The evidence is there 每個問題都有依據可查 Open the details to see the original finding, its rating and the recommended fix. 展開細節,就能查看原始檢查結果、嚴重程度與修正建議。

v0.4.0 / 2026-10-04

See what you receive.直接看你會拿到的報告。

These examples show how the report looks, using simulated data from all 25 tools: 62 findings and 42 inventory observations. Inventory is listed separately from security problems.先看看報告會怎麼呈現。範例使用模擬資料,包含 25 個工具的 62 筆發現與 42 筆盤點紀錄。盤點會另外列出,不算成安全問題。

02 / FULL

Report with names included保留名稱的報告

See the example system names, addresses and account details. These are fictional. Passwords and keys stay hidden in both versions.看得到範例中的系統名稱、網址與帳號資訊;這些資料都是虛構的。兩個版本都會隱藏密碼與金鑰。

See if the fix worked看有沒有修好

Run the same checks again and compare them with a scan that already finished.再跑一次同樣的檢查,跟一次已經跑完的掃描比。

  1. Earlier run

    Pick a finished scan from before the fix.

  2. Same checks

    Pick each folder again so this check reads your changes.

  3. Mark changes

    Each problem is marked No longer observed, Still present, New, or Verification incomplete.

  • baseline picked
  • folders chosen again
  • changes marked
A problem that only moved to another line still counts as Still present.
  1. 先前那次

    選修復前已經跑完的那一次。

  2. 相同檢查

    每個資料夾都要再選一次,這次才讀得到你的修改。

  3. 標出變化

    每個問題會標成「這次沒有再看到」、「仍然存在」、「新出現」或「驗證未完成」。

  • 已選先前掃描
  • 資料夾已重選
  • 差異已標好
只換了行號的問題,還是算仍然存在。

From your first scan to your next step. 從第一次掃描,到知道怎麼處理。

Start with one folder or website, or bring several company systems into the same scan. The app selects the checks that fit. 可以先檢查一個資料夾或網站,也可以把多個公司系統放在同一次掃描。程式會選用適合的檢查。

01

Choose what to check 選好要檢查的東西

Add project folders, website addresses or internal systems. Review the list and confirm that you may scan the network targets. 加入專案資料夾、網站網址或內部系統。確認清單,並確認你有權對這些網路目標進行檢查。

02

Start the scan in the app 在程式裡開始掃描

The app runs suitable security tools and shows their progress. You can pause or stop from the app window. 程式會執行適合的安全工具,讓你看到目前進度。需要時,可以從視窗暫停或停止掃描。

03

See what to do first 先看最需要處理的問題

When the scan ends, the report explains the problems, their impact and the next steps. It also lists unfinished checks. A failed check does not erase other results. 掃描結束後,報告會說明發現的問題、可能的影響與下一步,也會列出未完成的檢查。某項檢查失敗,其他結果仍然保留。

What you select 你選好的檢查對象 Repositories · websites · endpoints · cloud · containers · Kubernetes 程式碼專案 · 網站 · 端點 · 雲端 · 容器 · Kubernetes
Security checks 執行安全檢查 Each tool checks what it is designed to find 各工具負責自己擅長的檢查
Your report 你的檢查報告 Problems, priorities, next steps and unfinished checks 問題、處理順序、下一步與未完成項目

How one scan proceeds. 一次掃描如何進行。

One fails, the rest stay一項失敗,其他留下

Each scanner only handles the assets you gave it. You confirm that list before the run.每個掃描器只處理你分給它的資產。開跑之前,你要先確認那份清單。

  1. Choose targets

    New scan lists your environment, a website, or a code folder.

  2. Confirm scope

    Review and start shows the targets and checks you approved.

  3. Run checks

    Picking an engine for one asset does not turn it on for the others too.

  4. Read results

    If one check fails, the ones that finished stay in the report.

  • scope confirmed
  • checks running
  • finished results kept
If a check cannot run, the report still explains the failure.
  1. 選好目標

    新掃描會列出環境、一個網站,或一個程式資料夾。

  2. 確認範圍

    「確認後開始」會列出你核准的目標和檢查。

  3. 執行檢查

    為某一項資產選了引擎,不會連其他資產一起掃。

  4. 看結果

    有一項沒跑完時,已經完成的仍留在報告裡。

  • 範圍已確認
  • 檢查在跑
  • 完成的結果留下
有檢查跑不起來時,報告還是會說明為什麼失敗。

Where the scan starts掃描從哪裡開始

The environment start can mix folders, sites, and approved internal hosts.環境起點可以同時放資料夾、網站和核准過的內部主機。

  1. New scan

    It opens in the desktop window, and nothing runs yet.

  2. Pick a start

    Scan my environment, Check a website, or Check code or an AI project.

  • start picked
  • checks follow that start
A website start covers the whole origin, so other paths on that host can be requested. A code start stays on the one folder you chose.
  1. 新掃描

    在桌面視窗裡打開,這時候還沒開始跑。

  2. 選定起點

    可以選掃描我的環境、檢查一個網站,或檢查程式碼或 AI 專案。

  • 起點已選定
  • 檢查跟著起點走
網站查的是整個 origin,同一個主機上的其他路徑也在範圍裡。程式只查你選的那一個資料夾。

The window stays out視窗碰不到引擎

The desktop app has no privileges of its own. Work that needs them goes to the Rust case service.桌面程式自己沒有高權限。要用權限的動作,都進到 Rust 的案件服務。

  1. Desktop window

    It never talks to the runtime, the broker, an engine, or an evidence file.

  2. Case service

    It owns the case, the permission check, redaction, and the export.

  3. Engine process

    It receives the declared inputs and a read-only credential for those assets.

  • window has no privilege
  • login stays behind
  • engine gets declared inputs
  • The app
  • Trust line
  • Engine
The window's own checks are only there to help you.
  1. 桌面視窗

    它碰不到執行環境、憑證代理、引擎,也碰不到證據檔。

  2. 案件服務

    案件、權限、遮蔽和匯出,都在這個 Rust 服務。

  3. 引擎行程

    它只拿到宣告過的輸入,和那些資產的唯讀憑證。

  • 視窗沒有高權限
  • 登入留在後面
  • 引擎拿宣告輸入
  • 應用程式
  • 信任界線
  • 引擎
視窗自己做的檢查,只是方便你操作。

An AI assistant can help you get started. 讓 AI 助手陪你完成第一次掃描。

Claude Code or Codex on your computer can help install the app, check setup, explain the results and save your report. You choose the targets and start the scan in the desktop app. 同一台電腦上的 Claude Code 或 Codex,可以協助安裝、確認設定、解讀結果與儲存報告。你選好目標,再從桌面程式開始掃描。

Ask your assistant to use the ai-security-scanner skill. If it runs on another computer, it can give you instructions and download links. 告訴助手使用 ai-security-scanner skill 即可。如果助手在另一台電腦上,它可以提供操作說明與下載連結。

25 tools, with their uses explained. 25 個工具,各自能幫你看什麼?

v0.4.0 adds optional ZAP passive website checks, Agentic Radar offline workflow inventory and bounded Garak model checks. Every card links to the official GitHub repository. Star counts are a dated snapshot, not a security rating or endorsement. Research-only candidates are tracked separately and are not counted as scan capabilities. v0.4.0 新增可選的 ZAP 被動網站檢查、Agentic Radar 離線工作流程盤點與受限的 Garak 模型檢查。每張卡片都直接連到官方 GitHub repository。星星數是有日期的快照,不代表安全評分或背書。研究用候選另行追蹤,不計為掃描能力。

Code, software packages and deployment settings 程式碼、套件與部署設定

8

Semgrep

16.9k
Code security程式碼安全

Semgrep is a widely used open-source static application security testing (SAST) tool: it looks for security problems in source code without compiling or running the project. A plain text search sees only characters, so a line break, different spacing, or a renamed variable can hide the same code. Semgrep parses code into a syntax tree and matches its structure instead. In the Community Edition this app runs, rules that track untrusted data follow it only within one function. We include it in this app because it helps you quickly find risky patterns, such as unsafe command calls or database queries built from user input, using the security rule pack bundled with this app rather than the complete current registry.Semgrep 是一套廣泛使用的開源靜態應用程式安全測試(SAST)工具,也就是不編譯、不執行專案,直接檢查程式碼裡的安全問題。一般的文字搜尋只看字面,換行、空白不同或變數改名,都可能讓同一種寫法躲過去;Semgrep 則會把程式碼解析成語法樹(程式碼的結構),比對的是結構而不是字面。本程式使用的是社群版(Community Edition),追蹤不受信任資料流向的規則,只會在同一個函式內追蹤。我們把它放進本程式,是因為它能幫你很快找出有風險的寫法,例如不安全的指令呼叫,或直接拿使用者輸入組成的資料庫查詢;使用的是本程式內附的安全規則包,不是目前完整的規則庫。

GitHub repositoryGitHub 專案 Uses, limits and versions →用途、限制與版本 →

Gitleaks

29.6k
Secret scanning密碼與金鑰檢查

Gitleaks is an open-source secret scanner, and one of the most popular and trusted tools for finding hardcoded passwords, API keys, tokens, and other credentials in project files. Its rules recognize many known key formats, and some also weigh nearby words or how random a value looks. Upstream Gitleaks can also search a repository's Git history, so a key deleted later can still be found. We include it in this app because it helps you quickly find passwords and keys left in the project you select. Here it reads a read-only copy of the current files only: it does not search deleted Git history or test whether a credential still works, and the report hides the secret values.Gitleaks 是一套開源工具,也是最受歡迎且備受信任的密碼與金鑰掃描工具之一,用來找出寫死在專案檔案裡的密碼、API 金鑰、token 與其他憑證。它的規則認得許多已知金鑰的格式,有些規則還會參考附近的字詞,或字串看起來有多隨機。上游的 Gitleaks 也能搜尋儲存庫的 Git 歷史,就算金鑰後來刪掉了也找得到。我們把它放進本程式,是因為它能幫你很快找出你所選專案裡留下的密碼與金鑰。這裡只讀取目前檔案的唯讀副本,不搜尋已刪除的 Git 歷史,也不測試憑證是否仍然有效,報告也會遮蔽密碼與金鑰本身。

GitHub repositoryGitHub 專案 Uses, limits and versions →用途、限制與版本 →

TruffleHog

28.3k
Secret scanning密碼與金鑰檢查

TruffleHog is an open-source secret scanner, and one of the most popular and trusted tools for finding exposed credentials such as API keys and tokens. It has dedicated detectors for many kinds of credentials. Upstream, it can also ask the matching live service whether a found key works, and it can search Git history. We include it in this app because it helps you quickly find secrets in the current files, with detectors that complement Gitleaks. Here networking is turned off and the scan reads a read-only copy of those files: it does not search Git history or try any credential on a live service. A match is not proof that the key still works, and the report leaves the secret values out.TruffleHog 是一套開源工具,也是最受歡迎且備受信任的密碼與金鑰掃描工具之一,用來找出 API 金鑰、token 這類可能外洩的憑證。它為許多種憑證各準備了專屬的偵測器。上游的 TruffleHog 還能向對應的線上服務確認找到的金鑰是否有效,也能搜尋 Git 歷史。我們把它放進本程式,是因為它能幫你很快找出目前檔案裡的密碼與金鑰,偵測器也和 Gitleaks 互補。這裡會關閉網路,只讀取這些檔案的唯讀副本,不搜尋 Git 歷史,也不拿憑證去線上服務測試。找到結果不代表金鑰仍然有效,報告也不會放上金鑰內容。

GitHub repositoryGitHub 專案 Uses, limits and versions →用途、限制與版本 →

Trivy

38.2k
Package vulnerabilities套件弱點

Trivy, from Aqua Security, is an open-source security scanner, and one of the most popular and trusted tools for finding known vulnerabilities in software packages. It reads the dependency files it recognizes, plus individual packages such as Java JAR files, and matches their versions against public advisories in a vulnerability database, usually CVEs, the standard IDs for known flaws. Upstream Trivy can also check settings and secrets. We include it in this app because it helps you quickly find known vulnerable packages, along with a fixed version when the database lists one. Here only its vulnerability checks run, using the database bundled with this app. In a container image it checks operating-system packages only; Grype covers the image's application libraries.Trivy 來自 Aqua Security,是一套開源的資安掃描工具,也是最受歡迎且備受信任的套件弱點掃描工具之一。它會讀取認得出的相依套件檔,以及 JAR 這類個別的 Java 套件檔,再把版本拿去和漏洞資料庫裡的公開公告比對;這些公告通常是 CVE,也就是已知漏洞的標準編號。上游的 Trivy 還能檢查設定與密碼金鑰。我們把它放進本程式,是因為它能幫你很快找出已知有漏洞的套件;資料庫列有修正版本時,也會一併告訴你。這裡只執行漏洞檢查,使用本程式內附的資料庫。檢查容器映像時只看作業系統套件,映像裡的應用程式函式庫交給 Grype 檢查。

GitHub repositoryGitHub 專案 Uses, limits and versions →用途、限制與版本 →

Grype

13.0k
Package vulnerabilities套件弱點

Grype, from Anchore, is a widely used open-source tool that matches software packages to known vulnerabilities. It compares package names and versions with a vulnerability database and reports the matching advisory, such as a CVE, the standard ID for a known flaw, or a GitHub security advisory, plus any fixed version the database lists. We include it in this app because it helps you quickly find known vulnerable packages in a selected project or container image; in an image, that includes application libraries as well as operating-system packages. When Trivy reports the same issue, the report still shows which tool found what. Here it uses the database bundled with this app, and it does not pull images from a registry or run the container.Grype 來自 Anchore,是一套廣泛使用的開源工具,用來把軟體套件對上已知漏洞。它拿套件名稱與版本去比對漏洞資料庫,回報對應的公告,例如 CVE(已知漏洞的標準編號)或 GitHub 安全公告;資料庫若列有修正版本,也會一併呈現。我們把它放進本程式,是因為它能幫你很快找出所選專案或容器映像裡已知有漏洞的套件;檢查映像時,應用程式函式庫和作業系統套件都包含在內。即使 Trivy 也回報同一個問題,報告仍會標明各是哪個工具找到的。這裡使用本程式內附的資料庫,不會自己從 registry 下載映像,也不會執行容器。

GitHub repositoryGitHub 專案 Pin and recorded result釘選與實測紀錄 Uses, limits and versions →用途、限制與版本 →

Checkov

9.1k
Configuration設定檢查

Checkov is a widely used open-source scanner for infrastructure as code (IaC): the files that describe how cloud resources and deployments should be set up. It reads those files as resources and the relationships between them, not as plain text, and checks them against a library of security policies. We include it in this app because it helps you quickly find unsafe settings in files such as Terraform, CloudFormation, and Dockerfiles before anything is deployed. Here it reads a read-only copy of the selected project. It does not connect to a cloud account, download platform policy data, or apply the files, so the result describes the files, not the live environment.Checkov 是一套廣泛使用的開源工具,專門檢查基礎設施即程式碼(IaC),也就是描述雲端資源與部署該怎麼設定的檔案。它把這些檔案讀成資源以及資源之間的關係,而不是一段純文字,再用一套安全政策逐一檢查。我們把它放進本程式,是因為它能幫你在真正部署之前,很快找出 Terraform、CloudFormation 與 Dockerfile 等檔案裡不安全的設定。這裡只讀取你所選專案的唯讀副本,不連接雲端帳號、不下載平台政策資料,也不套用這些檔案,所以結果描述的是檔案本身,不是線上環境實際的狀態。

GitHub repositoryGitHub 專案 Uses, limits and versions →用途、限制與版本 →

KICS

2.7k
Configuration設定檢查

KICS (Keeping Infrastructure as Code Secure), from Checkmarx, is an open-source scanner for infrastructure as code (IaC): the files that describe how your systems are deployed. It runs a library of security queries over formats such as Terraform, CloudFormation, Kubernetes manifests, and Dockerfiles, and ties each result to a file and line. Its bundled queries also look for passwords and keys left in those files. We include it in this app because it helps you quickly find risky deployment settings, with a query library independent of Checkov's that gives a second view. Here it scans a read-only copy of the selected project with the queries bundled in the tool. It does not connect to a cloud account or download extra queries.KICS(Keeping Infrastructure as Code Secure)來自 Checkmarx,是一套開源工具,用來找出基礎設施即程式碼(IaC)裡不安全的設定;IaC 就是描述系統要怎麼部署的檔案。它用一套安全查詢檢查 Terraform、CloudFormation、Kubernetes 設定檔與 Dockerfile 等格式,並把每筆結果對應到檔案與行號;內附的查詢也會找出檔案裡留下的密碼與金鑰。我們把它放進本程式,是因為它能幫你很快找出有風險的部署設定,查詢庫和 Checkov 各自獨立,能提供第二種觀點。這裡用工具內附的查詢掃描你所選專案的唯讀副本,不連接雲端帳號,也不另外下載查詢。

GitHub repositoryGitHub 專案 Uses, limits and versions →用途、限制與版本 →

Syft

9.6k
SBOM inventorySBOM 盤點

Syft, from Anchore, is a widely used open-source tool that builds a software bill of materials, or SBOM: a list of the software components inside a project or container image, such as libraries and operating-system packages. It records the name, version, and type of each component it recognizes. We include it in this app because it helps you quickly see which software the selected project or image contains, so you know what the vulnerability checks are looking at. The list shows what is there; it is not a vulnerability report. Here it reads a read-only copy with no network connection and does not download images from a registry. Known vulnerabilities are left to Trivy and Grype.Syft 來自 Anchore,是一套廣泛使用的開源工具,用來建立軟體物料清單(SBOM),也就是列出專案或容器映像裡有哪些軟體元件的清單,例如函式庫與作業系統套件。它會記下每個認得出的元件名稱、版本與類型。我們把它放進本程式,是因為它能幫你很快看清所選專案或映像裡有哪些軟體,也就知道漏洞檢查看的是哪些東西。這份清單只說明有什麼,不是漏洞報告。這裡只讀取唯讀副本、不連網路,也不會從 registry 下載映像;已知漏洞交給 Trivy 與 Grype 檢查。

GitHub repositoryGitHub 專案 Uses, limits and versions →用途、限制與版本 →

Websites and internal systems 網站與內部系統

5

Nuclei

31.7k
HTTP securityHTTP 安全

Nuclei is an open-source vulnerability scanner from ProjectDiscovery, and one of the most widely used and trusted tools of its kind. Each check is a template: a written request plus the response that signals a known exposure or vulnerability. It first recognizes which technologies a site uses, then picks the templates that fit. We include it in this app because it helps you quickly find those known problems; it is the default website check, using the templates bundled here. It stays on one approved site address and sends only read-only requests. It does not log in, submit forms, fuzz, run exploits, drive a browser, or ask an outside server to call back. A path you type does not narrow the check to that path.Nuclei 是 ProjectDiscovery 維護的開源弱點掃描工具,也是同類工具中最受歡迎且備受信任的工具之一。它的每一項檢查都是一份範本:寫好的請求,加上代表已知曝露或漏洞的回應特徵。它會先辨識網站用了哪些技術,再挑出適合的範本。我們把它放進本程式,是因為它能幫你很快找出這些已知問題;它是預設的網站檢查,使用本程式內附的範本。它只對一個核准的網站位址送出唯讀請求,不登入、不送出表單、不做模糊測試或漏洞利用、不操作瀏覽器,也不請外部伺服器回撥。你輸入的路徑不會把檢查範圍縮小到那個路徑。

GitHub repositoryGitHub 專案 Uses, limits and versions →用途、限制與版本 →

ZAP

15.9k
Passive web checks · v0.4.0被動網站檢查 · v0.4.0

ZAP (Zed Attack Proxy, long known as OWASP ZAP) is an open-source web application security scanner, and one of the most widely used and trusted tools of its kind. Upstream, it can sit between a browser and a website, crawl pages, inspect every response, and actively send attack payloads. Its passive rules only read the responses, including headers and cookies, without attacking. We include it in this app because those passive rules help you find problems such as missing security headers or unsafe cookie settings on the pages it reaches, as a complement to Nuclei. Here it is optional: it crawls one approved website within fixed limits and does not log in, submit forms, send attack payloads, or leave the site. Nuclei remains the default.ZAP(Zed Attack Proxy,也就是大家熟悉的 OWASP ZAP)是開源的網站應用程式安全掃描工具,也是同類工具中最受歡迎且備受信任的工具之一。上游的 ZAP 可以站在瀏覽器與網站之間、爬取頁面、檢查每一個回應,也能主動送出攻擊內容。它的被動規則只讀取回應,包括標頭與 cookie,不發動攻擊。我們把它放進本程式,是因為這些被動規則能幫你在它走得到的頁面上,找出缺少安全標頭、cookie 設定不安全這類問題,和 Nuclei 互補。在本程式裡它是選用的:只在固定限制內爬一個核准的網站,不登入、不送出表單、不送攻擊內容,也不跟著連結到其他網站。預設的網站檢查仍是 Nuclei。

GitHub repositoryGitHub 專案 Uses, limits and versions →用途、限制與版本 →

Greenbone OpenVAS

4.8k
Remote security遠端安全

Greenbone OpenVAS is an open-source network vulnerability scanner maintained by Greenbone. Its tests come from a fixed copy of the Greenbone Community Feed, a separately maintained library of checks. It first identifies which service is listening on a port, then runs the tests that apply to it. We include it in this app because it helps you find known security problems on internal devices and servers that a simple connection cannot reveal. Here it tests only the exact hosts and ports you approved. It does not log in or inspect the machine from inside, guess passwords, try default accounts, or run disruptive checks. When it cannot identify a service, those tests do not run, and the report lists the host as not tested.Greenbone OpenVAS 是 Greenbone 維護的開源網路弱點掃描工具。它使用一份固定版本的 Greenbone Community Feed 來做弱點測試;Community Feed 是 Greenbone 另外維護的檢查項目庫。它會先辨識連接埠上跑的是什麼服務,再執行適用的測試。我們把它放進本程式,是因為它能幫你找出內部設備與伺服器上、光靠連線看不出來的已知安全問題。這裡只測試你核准的主機與連接埠,不登入、不進到主機內部檢查、不猜密碼、不試預設帳號,也不做可能中斷或壓垮服務的檢查。辨識不出服務時,這些測試就不會執行,報告會把該主機列為未測試。

GitHub repositoryGitHub 專案 Uses, limits and versions →用途、限制與版本 →

Naabu

6.3k
Exposure discovery對外服務盤點

Naabu is an open-source port-discovery tool from ProjectDiscovery that shows which TCP ports are accepting connections. A TCP port is the number a network service listens on. Its connect scan opens an ordinary TCP connection to each address and port, and a completed connection means the port is open; upstream also offers other discovery methods. We include it in this app because it helps you quickly find out which approved services are listening, so the security checks that follow have a real target. Here it connects only to the exact addresses and ports you approved. It does not add nearby hosts or scan UDP, the other common way services listen, and an open port is inventory, not a vulnerability.Naabu 是 ProjectDiscovery 維護的開源連接埠探索工具,用來找出哪些 TCP 連接埠正在接受連線。TCP 連接埠就是網路服務等候連線時使用的編號。它的連線掃描會對每個位址與連接埠嘗試一次一般的 TCP 連線,連得上就代表連接埠是開的;上游另外還有其他探索方式。我們把它放進本程式,是因為它能幫你很快看出哪些核准的服務正在等候連線,讓接下來的安全檢查有明確的對象。這裡只連你核准的位址與連接埠,不會把附近的主機加進來,也不掃描 UDP(另一種常見的服務連線方式)。開著的連接埠會記在盤點裡,本身不是漏洞。

GitHub repositoryGitHub 專案 Uses, limits and versions →用途、限制與版本 →

httpx

10.4k
HTTP observationHTTP 觀察

httpx is an open-source web-probing tool from ProjectDiscovery, not the Python HTTPX library of the same name. It sends an ordinary web (HTTP) request to an address and records whether a web service answers, the status code it returns, and other basic response details, which a port check alone cannot tell you. We include it in this app because it helps you quickly confirm that an approved web service is responding before a real security check runs against it. Upstream, it can run many more probes. Here it asks only the exact service you approved and does not crawl, log in, or enable every upstream probe. The result is inventory that describes the service, not a vulnerability finding.httpx 是 ProjectDiscovery 維護的開源網站探測工具,和 Python 裡同名的 HTTPX 程式庫不是同一個東西。它會對一個位址送出一般的網頁(HTTP)請求,記下有沒有網站服務回應、回傳的狀態碼,以及其他基本的回應資訊;這些都是只看連接埠開不開無法得知的。我們把它放進本程式,是因為它能幫你在真正的安全檢查開始前,很快確認核准的網站服務是否有在回應。上游還能做更多種探測,這裡只詢問你核准的那一個服務,不爬網站、不登入,也不開啟所有上游探測。結果是描述這個服務的盤點資料,本身不代表有漏洞。

GitHub repositoryGitHub 專案 Uses, limits and versions →用途、限制與版本 →

Cloud and Microsoft 365 雲端與 Microsoft 365

7

Prowler

14.9k
Cloud configuration雲端設定

Prowler is a widely used open-source cloud security assessment tool. It calls the cloud provider's APIs, runs its built-in checks, and records each check's name, the affected resource, what failed, and how to fix it. Upstream, it can cover many services and compliance frameworks. We include it in this app because it helps you quickly find identity and permission settings that need attention. Here each run uses a narrow identity and access management (IAM) profile on one approved asset: the IAM service of one AWS account, the IAM service of one Azure subscription, or four specific IAM checks for one GCP project. Other services and accounts are outside the run, and a passed check is not a certification.Prowler 是一款廣泛使用的開源雲端安全評估工具。它呼叫雲端服務商的 API、執行內建檢查,並記下檢查名稱、受影響的資源、哪裡不符合,以及怎麼修正。上游的 Prowler 能涵蓋許多服務與合規框架。我們把它放進本程式,是因為它能幫你很快找出需要注意的身分與權限設定。這裡每次只對一個核准資產執行範圍很窄的身分與存取管理(IAM)檢查:一個 AWS 帳號的 IAM 服務、一個 Azure 訂用帳戶的 IAM 服務,或一個 GCP 專案的四項指定 IAM 檢查。其他服務與帳號不在這次檢查範圍內,單一檢查通過也不代表取得認證。

GitHub repositoryGitHub 專案 Uses, limits and versions →用途、限制與版本 →

ScoutSuite

7.8k
Cloud configuration雲端設定

ScoutSuite, from NCC Group, is a widely used open-source tool that reads cloud configuration through provider APIs and flags settings its rules consider risky. Each result keeps the rule, the affected items, and why they deserve review. Upstream, it supports several cloud providers and produces its own report. We include it in this app because it helps you quickly find AWS identity and access settings worth a closer look, as a second view beside Prowler. Here it runs only the AWS identity and access management (IAM) rules for one approved account; other providers and other AWS services are outside the run. A setting becomes a finding only when a rule flags it, so collected configuration alone is not a vulnerability.ScoutSuite 來自 NCC Group,是一款廣泛使用的開源工具。它透過雲端服務商的 API 讀取設定,用自己的規則標出有風險的設定,每筆結果都保留規則、受影響的項目,以及值得檢視的原因。上游的 ScoutSuite 支援多家雲端服務商,也有自己的報告。我們把它放進本程式,是因為它能幫你很快找出值得再看一眼的 AWS 身分與存取設定,也能和 Prowler 互相對照。這裡只對一個核准帳號執行 AWS 身分與存取管理(IAM)規則,其他雲端服務商與其他 AWS 服務都不在範圍內。設定要被規則標出才會成為報告裡的問題,只是收集到設定並不代表有弱點。

GitHub repositoryGitHub 專案 Uses, limits and versions →用途、限制與版本 →

Cloudsplaining

2.2k
IAM analysisIAM 分析

Cloudsplaining, from Salesforce, is an open-source tool that checks AWS identity and access management (IAM) policies for permissions broader than the work needs, which breaks the principle of least privilege. It reads an account's authorization details, finds actions allowed without a resource limit, and sorts risky ones into categories such as privilege escalation, data exfiltration, resource exposure, and infrastructure modification, naming the policy and the actions. We include it in this app because it helps you quickly find overly broad permissions and see which actions to review. Here it analyzes one approved AWS account. A flagged action is evidence for review: it does not decide whether the business needs the permission, change the policy, or prove someone can use it now.Cloudsplaining 來自 Salesforce,是一款開源工具,專門檢查 AWS 身分與存取管理(IAM)政策是否給了超過工作所需的權限,也就是有沒有違反「最小權限」原則。它讀取帳號的授權細節,找出沒有限定資源範圍的動作,再把有風險的動作分成權限提升、資料外洩、資源曝露與更動基礎設施等類別,並指出是哪一份政策、哪些動作。我們把它放進本程式,是因為它能幫你很快找出過寬的權限,看清該檢視哪些動作。這裡只分析一個核准的 AWS 帳號。被標出的動作是供你審閱的證據:它不判斷業務是否需要這項權限、不修改政策,也不能證明現在真的有人用得到。

GitHub repositoryGitHub 專案 Uses, limits and versions →用途、限制與版本 →

CloudQuery

6.5k
Cloud inventory雲端盤點

CloudQuery is a widely used open-source tool that copies data from cloud provider APIs into structured tables you can query and compare later. A source plugin reads the cloud service and a destination plugin writes each row, so every collection comes out in the same shape. We include it in this app because it helps you quickly see which identities and permission policies exist in an approved AWS account, which gives the security checks context. Here it collects one fixed set of identity and access management (IAM) tables: the account, users, groups, roles, policies, password policies, and credential reports. These rows are inventory: they describe what exists, stay separate from security findings, and do not cover every AWS service.CloudQuery 是一款廣泛使用的開源工具,會把雲端服務商 API 提供的資料整理成結構化表格,方便你之後查詢與比對。它用來源外掛讀取雲端服務,再用目的地外掛寫下每一列資料,所以每次收集到的格式都一致。我們把它放進本程式,是因為它能幫你很快看清一個核准的 AWS 帳號裡有哪些身分與權限政策,讓安全檢查的結果更容易對照。這裡只收集一組固定的身分與存取管理(IAM)表格:帳號、使用者、群組、角色、政策、密碼政策與憑證報告。這些資料屬於盤點,只說明目前有什麼,會和安全問題分開列出,也不涵蓋所有 AWS 服務。

GitHub repositoryGitHub 專案 Uses, limits and versions →用途、限制與版本 →

Steampipe

8.0k
Cloud inventory雲端盤點

Steampipe, maintained by Turbot, is a widely used open-source tool that turns cloud APIs into SQL tables. SQL is the standard database query language, and each provider plugin decides which services and columns you can read. We include it in this app because it helps you quickly list the identity and access management (IAM) users in one approved AWS account, so you can compare that list with what the security checks report. Here it runs one fixed query of the IAM user table. The rows are inventory: they name the users found and do not judge whether any user is a risk. This app does not run Steampipe's ready-made security benchmarks or accept SQL you write.Steampipe 由 Turbot 維護,是一款廣泛使用的開源工具,能把雲端 API 變成 SQL 資料表。SQL 是查詢資料庫的標準語言,而每個服務商外掛決定你能讀到哪些服務與欄位。我們把它放進本程式,是因為它能幫你很快列出一個核准 AWS 帳號裡的身分與存取管理(IAM)使用者,再拿這份名單對照安全檢查的結果。這裡只執行一個固定的 IAM 使用者查詢。查到的資料屬於盤點:只列出找到的使用者,不判斷哪個使用者有風險。本程式也不執行 Steampipe 現成的安全基準檢查,也不接受你自己寫的 SQL。

GitHub repositoryGitHub 專案 Uses, limits and versions →用途、限制與版本 →

ScubaGear

2.7k
M365 configurationM365 設定

ScubaGear, from CISA, the U.S. Cybersecurity and Infrastructure Security Agency, is an open-source tool that compares a Microsoft 365 tenant, an organization's Microsoft 365 environment, with CISA's Secure Cloud Business Applications (SCuBA) baselines: written expectations for a secure configuration. Upstream, it also covers other Microsoft 365 products. We include it in this app because it helps you quickly find Microsoft Entra ID settings that fall short of this guidance; Entra ID is the tenant's sign-in and identity directory. Here it checks the Entra ID baseline for one authorized tenant in Microsoft's commercial cloud. Exchange, SharePoint, and other workloads are outside the check. A pass is not a compliance certification, and checks that could not be evaluated stay visible instead of counting as passes.ScubaGear 來自美國網路安全暨基礎設施安全局(CISA),是一款開源工具,會把 Microsoft 365 租戶(也就是組織的 Microsoft 365 環境)的設定,和 CISA 的 Secure Cloud Business Applications(SCuBA)基準比較;這些基準是以書面寫下的安全設定要求。上游也涵蓋其他 Microsoft 365 產品。我們把它放進本程式,是因為它能幫你很快找出不符合這份基準的 Microsoft Entra ID 設定;Entra ID 是租戶的登入與身分目錄。這裡只為一個已授權、位於 Microsoft 商業雲端的租戶檢查 Entra ID 基準,Exchange、SharePoint 與其他工作負載不在範圍內。通過不等於合規認證,沒能評估的項目也會照樣列出,不算通過。

GitHub repositoryGitHub 專案 Uses, limits and versions →用途、限制與版本 →

Maester

1.1k
M365 configurationM365 設定

Maester is an open-source test framework for Microsoft 365 security configuration, written in PowerShell, Microsoft's scripting language. Each test states the setting a secure tenant should have and records whether yours matches. We include it in this app because it helps you quickly find Microsoft Entra ID settings that do not meet those expectations; Entra ID is the tenant's sign-in and identity directory. Here it runs a fixed set of Entra tests for one authorized tenant and skips long-running tests, preview tests, and tests that need other services. Exchange Online and scripts you supply are outside the run. A skipped test is never shown as a pass, and a test that needs human judgment is listed for your review.Maester 是一套開源的測試框架,用 PowerShell(Microsoft 的腳本語言)寫成,專門檢查 Microsoft 365 的安全設定。每一項測試都寫明安全的租戶應有的設定,並記錄你的租戶是否符合。我們把它放進本程式,是因為它能幫你很快找出不符合這些要求的 Microsoft Entra ID 設定;Entra ID 是租戶的登入與身分目錄。這裡對一個已授權的租戶執行一組固定的 Entra 測試,並略過耗時很長的測試、預覽測試,以及需要連到其他服務的測試;Exchange Online 和你自己提供的腳本都不在範圍內。被略過的測試絕不會顯示成通過,需要人來判斷的測試會列出來供你審閱。

GitHub repositoryGitHub 專案 Uses, limits and versions →用途、限制與版本 →

Kubernetes

2

Kubescape

11.8k
Manifest configurationManifest 設定

Kubescape is a widely used open-source tool for checking the configuration of Kubernetes, the system many teams use to run containers. It reads YAML and JSON files as Kubernetes resources and compares them with a fixed hardening checklist, the NSA framework based on U.S. NSA and CISA guidance, so each result names the resource and the control that failed. Upstream Kubescape can also scan live clusters and container images. We include it in this app because it helps you quickly find risky settings in the Kubernetes files you select. Here it checks only that saved snapshot, offline. It does not connect to a running cluster, cannot tell whether the files match what is deployed, and does not scan container packages.Kubescape 是一套廣泛使用的開源工具,用來檢查 Kubernetes(許多團隊用來運行容器的系統)的設定。它把 YAML 與 JSON 檔案讀成 Kubernetes 資源,再對照一份固定的強化檢查清單,也就是根據美國 NSA 與 CISA 指引整理的 NSA 框架,所以每筆結果都會指出是哪個資源、哪一項控制沒有通過。上游的 Kubescape 也能掃描運作中的叢集與容器映像。我們把它放進本程式,是因為它能幫你很快找出所選 Kubernetes 設定檔裡有風險的設定。這裡只離線檢查那份已儲存的快照,不連到運作中的叢集,無法判斷檔案是否與實際部署一致,也不掃描容器套件。

GitHub repositoryGitHub 專案 Uses, limits and versions →用途、限制與版本 →

kube-bench

8.2k
Node configuration節點設定

kube-bench is a widely used open-source tool from Aqua Security that checks Kubernetes nodes, the machines that run workloads, against the CIS Kubernetes Benchmark: the Center for Internet Security's published checklist of secure settings. It compares configuration files and running-process facts with each check and marks it pass, fail, or warn; a warning means the check needs information or judgment that automation cannot supply. Upstream kube-bench runs on a live node and can also check the control plane. We include it in this app because it helps you quickly find node settings that miss this checklist. Here it uses only a saved export of node facts and the node checks. It does not log in to a live host or run the control-plane checks.kube-bench 是 Aqua Security 維護、廣泛使用的開源工具,依照 CIS Kubernetes Benchmark 檢查 Kubernetes 節點,也就是實際運行工作負載的機器;CIS Benchmark 是網際網路安全中心(CIS)公開的安全設定檢查清單。它拿設定檔與執行中程序的資訊逐項比對,標成通過、失敗或警告;警告代表這項檢查需要自動化無法提供的資訊或判斷。上游的 kube-bench 會在運作中的節點上執行,也能檢查控制平面。我們把它放進本程式,是因為它能幫你很快找出不符合這份清單的節點設定。這裡只使用你匯出的節點資訊與節點檢查項目,不會登入運作中的主機,也不執行控制平面檢查。

GitHub repositoryGitHub 專案 Uses, limits and versions →用途、限制與版本 →

AI workflows, models and MCP AI 工作流程、模型與 MCP

3

Agentic Radar

1.1k
Offline inventory離線盤點

Agentic Radar is an open-source tool that reads AI agent projects and maps how their pieces connect. You choose one of the supported frameworks (LangGraph, CrewAI, n8n, OpenAI Agents, or AutoGen), and its parser lists the agents, tools, and MCP servers and the links between them. An MCP server is an outside tool reached through the Model Context Protocol, a standard way for an AI app to call other tools. Upstream Agentic Radar also offers broader risk analysis. We include it in this app because it helps you quickly understand what an AI agent project contains before you review it. Here it only inventories one saved copy of the project. It does not run the workflow, contact a model, or report security problems.Agentic Radar 是一套開源工具,會閱讀由 AI 代理組成的專案,整理出各個部分如何相連。你先選定一個受支援的框架(LangGraph、CrewAI、n8n、OpenAI Agents 或 AutoGen),它的解析器就會列出代理、工具、MCP 伺服器,以及它們之間的連線。MCP 伺服器是透過 Model Context Protocol 接上的外部工具,這個協定讓 AI 應用程式能呼叫其他工具。上游的 Agentic Radar 還有更廣的風險分析。我們把它放進本程式,是因為它能幫你在審閱之前,很快看懂一個 AI 代理專案裡有哪些元件。這裡只盤點一份已儲存的專案副本,不執行工作流程、不連線到模型,也不會回報安全問題。

GitHub repositoryGitHub 專案 Uses, limits and versions →用途、限制與版本 →

Garak

9.4k
Model behavior checks模型行為檢查

Garak is NVIDIA's widely used open-source vulnerability scanner for large language models (LLMs). It sends crafted prompts, called probes, and detectors judge the replies. The probes used here are “Do Anything Now” instructions that try to talk a model out of its rules, and prompts that try to make it output terminal escape codes. Upstream Garak has many more probes. We include it in this app because it helps you quickly see how one approved model responds to these fixed tests. You start this optional check yourself: it sends 54 prompts to one approved OpenAI-compatible HTTPS chat API and model. A clean result covers only these prompts. The provider may charge, and your API key is used once and never saved with the scan or report.Garak 是 NVIDIA 維護、廣泛使用的開源大型語言模型(LLM)弱點掃描工具。它送出稱為「探測」的特製提示,再用偵測器判斷模型的回覆。這裡使用的探測包括「Do Anything Now」這類試圖讓模型拋開自身規則的指示,以及試圖讓模型輸出終端機跳脫碼的提示;上游的 Garak 還有更多探測。我們把它放進本程式,是因為它能幫你很快看出一個核准的模型如何回應這組固定測試。這項選用檢查要由你自己啟動,只對一個核准、相容 OpenAI 格式的 HTTPS 聊天 API 與模型送出 54 個提示。沒有發現問題,也只代表這些提示沒有引出問題。服務商可能會收費;你輸入的 API 金鑰只用於這一次檢查,不會存進掃描紀錄或報告。

GitHub repositoryGitHub 專案 Uses, limits and versions →用途、限制與版本 →

MCP Armor

123
MCP configurationMCP 設定

MCP Armor is an open-source tool for checking Model Context Protocol (MCP) configuration, the file that tells an AI app which outside tools to connect to. Two of its checks read that file: one looks for keys and other secrets written into it, the other flags tool commands and permissions broader than needed. The report leaves out the matched secret. Upstream, it can also contact the configured servers and run tests that use a model. We include it in this app because it helps you quickly find exposed keys and overly broad tool permissions in the configuration you select. Here it reads only that file from the saved project; it does not start or contact an MCP server, load a model, or show what a running server enforces.MCP Armor 是一套開源工具,用來檢查 MCP 設定檔。MCP(Model Context Protocol)是 AI 應用程式連接外部工具的協定,設定檔則寫明要連哪些工具。它有兩項檢查直接讀取這個檔案:一項找出寫在檔案裡的金鑰等機密,另一項依上游規則標出範圍過大的工具指令與權限;比對到的機密內容不會寫進報告。上游的 MCP Armor 還能連上設定裡的伺服器,並執行需要模型的測試。我們把它放進本程式,是因為它能幫你很快找出你選定的那份設定裡外露的金鑰與過大的工具權限。這裡只讀取已儲存專案中的那一個檔案,不啟動也不連線任何 MCP 伺服器、不載入模型,也無法顯示運作中的伺服器實際執行的權限控管。

GitHub repositoryGitHub 專案 Uses, limits and versions →用途、限制與版本 →

Pinned upstream rule sources 固定的上游規則來源

GitHub stars checked October 4, 2026 (UTC) through the GitHub API. Counts change over time. Exact pinned versions and source revisions live in the engine catalog. GitHub 星星數於 2026 年 10 月 4 日(UTC)透過 GitHub API 查詢,數字會隨時間變動;精確固定版本與原始碼 revision 請以引擎目錄為準。

Garak stops itselfGarak 自己會停

You can leave this check off. Nothing is sent until you agree.這個檢查可以不做。你還沒同意之前,什麼都不會送出去。

  1. Give consent

    You name one OpenAI-compatible HTTPS chat URL and the model, and you accept the charges.

  2. Garak run

    The fixed DAN and ANSI prompts go out one by one, no faster than once a second.

  3. Then it stops

    It stops at ten minutes or 64 tries. Each try asks for at most 150 tokens.

  • 54 prompts ready
  • waiting for a yes
  • one prompt at a time
TLS stays on, and a redirect is refused. The API key is used once and does not go into the report.
  1. 先同意

    你指定一個 HTTPS 的 OpenAI 相容聊天網址和模型,也要先同意可能的費用。

  2. Garak 執行

    固定的 DAN 和 ANSI 一個一個送,最快也要隔一秒。

  3. 到點就停

    十分鐘到了就停,重試也算進 64 次。每次最多要 150 個 token。

  • 這組有 54 個
  • 等你點頭
  • 現在只送一個
TLS 維持開著,不接受重新導向。API 金鑰只用一次,不會寫進報告。

The product layer 產品報告層

The scanners stay upstream. The answer becomes yours. 掃描器維持上游原意,答案整理成你的工作視圖。

Thin adapters and output converters connect upstream scanners to one standardized report. The shared report layer handles organization, deduplication, prioritization, and plain-language guidance while preserving original evidence. 薄層轉接器與輸出轉換器,把上游掃描器串接到一份標準化報告。共用報告層負責整理、去重、排序與白話說明,同時保留原始證據。

  • Every requested asset gets one clear status.每個選定資產都有一個清楚狀態。
  • Highest-priority problems and practical next actions come first.優先呈現最重要問題與實際可行的下一步。
  • Completed sibling results survive an independent tool failure.個別工具失敗時,其他已完成結果仍會保留。
  • Original engine, rule ID, severity, evidence, and remediation stay available.原始引擎、規則 ID、嚴重度、證據與修正建議都能查看。
  • Not-tested work and coverage gaps remain visible.未測試項目與涵蓋缺口會清楚保留。
FIRST LAYER 第一層 What matters first · affected assets · impact · next action · verification 優先項目 · 受影響資產 · 可能影響 · 下一步 · 驗證方式
ASSET COVERAGE 資產涵蓋範圍 Problems found · no problems in completed checks · incomplete · not tested 發現問題 · 已完成檢查未發現問題 · 未完成 · 未測試
TECHNICAL DETAIL 技術細節 Upstream identity · versions · raw evidence references · execution outcomes 上游識別 · 版本 · 原始證據參照 · 執行結果

What remains beside the findings. 問題之外還留下什麼。

Evidence stays saved證據跟著檔案走

Engine output is gathered into one report, with the urgent problems first.引擎輸出會收成一份報告,急的問題排在前面。

  1. Engine output

    Each engine's output is converted to one common format.

  2. One report

    Each problem names the affected asset before the raw tool output.

  3. HTML file

    Save writes a local file in the app language, English or Traditional Chinese.

  4. Original evidence

    The engine's original evidence stays. Normalization does not delete it.

  • report is together
  • evidence kept
  • raw output comes last
What was not tested stays visible, and it is not a pass. Services, ports, and installed software are inventory, not security problems.
  1. 引擎輸出

    每個引擎的輸出,先轉成同一種格式。

  2. 一份報告

    每個問題先寫受影響的資產,原始工具輸出放後面。

  3. HTML 檔

    儲存會在本機寫一份檔,語言跟程式一樣,英文或繁體中文。

  4. 原始證據

    引擎原來的證據還在,正規化不會把它刪掉。

  • 報告收好了
  • 證據留著
  • 原始輸出放後面
沒測到的部分留在畫面上,不會顯示成通過。服務、連接埠和已安裝的軟體是盤點,不算安全問題。

Pinned upstream engines, reviewable changes. 上游引擎精確固定,每次變更都可供審查。

Staying current starts with an offline proposal, not an automatic update. Each proposed change preserves a clear human decision point. 維持更新從離線提案開始,不會自動套用;每項變更都保留清楚的人工決策點。

  • Every engine is pinned to an exact upstream revision with a recorded digest; it is never floating.每個引擎都固定到明確的上游修訂版並記錄摘要值,不會追隨浮動版本。
  • The product can produce an offline adapter refresh proposal that states what changed, what was verified, the risk, and whether it may become a pull request.產品可為 adapter 產生離線更新提案,清楚交代變更內容、已驗證項目、風險,以及是否允許進入 pull request。
  • The deterministic path is the default. The optional AI path must be selected explicitly, and every byte a model wrote is attributed with before and after digests for human review.預設採用可重現的確定性流程;AI 流程必須明確選用,模型寫入的每個位元組都會標示變更前後的摘要值,供人員審閱。
  • Whoever runs it decides whether to send the change back to the project. The tool prints commands for a person to run and never executes them.執行者決定是否把變更送回專案;工具只列出可由人員執行的指令,絕不代為執行。
  • Deliberately pinned engines and experimental integrations are refused with a reason, not silently skipped.刻意維持固定版本的引擎與實驗性整合會明確拒絕並說明原因,不會悄悄略過。

Start with the assets. Let the product choose the checks. 從資產開始,讓產品選擇適用檢查。

Download the Linux, macOS and Windows stable release, or let Claude Code or Codex install it for you. Review the exact scan scope, start once, and read the final report. 下載 Linux、macOS、Windows 正式版,或讓 Claude Code/Codex 幫你安裝。確認精確掃描範圍、啟動一次,再閱讀最終報告。