Metadata-Version: 2.4
Name: aegi
Version: 0.1.3
Summary: AegiLabs security audit agent — runs locally, metered via your AegiLabs key.
Project-URL: Homepage, https://aegilabs.se
Author: AegiLabs
License: Proprietary
Keywords: agent,audit,pentest,sast,security
Requires-Python: >=3.11
Requires-Dist: claude-agent-sdk>=0.1.0
Description-Content-Type: text/markdown

# aegi — AegiLabs audit CLI

Runs the AegiLabs security-audit agent **on your machine**. Your code and
targets stay local; only the agent's model calls are routed through the
AegiLabs metering proxy using your issued key. Point it at a repo or a URL:

```bash
aegi ./path/to/repo          # static audit of a code repository
aegi http://localhost:3000   # authorized assessment of a live target
```

## Install

```bash
pipx install aegi
```

Prerequisite: the **Claude Code CLI** (`claude`) must be installed — the agent
drives it under the hood. `aegi` fails fast with a clear message if it's missing.

## Configure

You need the **Aegi key** we issued you. Easiest: just run `aegi` and paste the
key when prompted — it's stored in `~/.aegi/config.toml` and reused after that.
Or set it yourself:

```bash
export AEGI_KEY=aegi_live_...            # env var
# or ~/.aegi/config.toml:
#   key = "aegi_live_..."
# or per-run: aegi --key aegi_live_... ./repo
```

The proxy URL defaults to AegiLabs' — you don't set it. Precedence for both:
flag → env → `~/.aegi/config.toml`.

## What each mode does

| Target | Mode | Tools | Notes |
|---|---|---|---|
| a directory | **repo** | Read/Grep/Glob/Bash (read-only) | secrets, creds, vulnerable deps, injection/authz sinks |
| a URL | **url** | Bash | active assessment — prompts for authorization first (skip with `--yes`) |

Detection is automatic: an existing directory → repo; anything starting `http(s)://`
(or a bare `host:port` / `localhost:port`) → url.

## Output

Streams progress to the terminal, then writes (stem taken from `--out`, default `aegi-report`):

- **`aegi-report.pdf`** — the branded, client-ready report, compiled from the vendored
  AegiLabs Typst template (`report_assets/`). Requires `typst` on PATH
  (`winget install Typst.Typst`). Without it, an HTML fallback (`aegi-report.html`) is written instead.
- `aegi-report.data.json` — the structured findings (`report-data.json` schema); the only
  file you'd edit to tweak wording before sending.
- `aegi-report.transcript.md` — the raw agent transcript (audit trail).

Finally prints tokens used against your quota. Reports are Swedish by default (`--lang en` for English).

## Options

```
aegi <target> [--max-turns N] [--out report.pdf] [--lang sv|en] [--title T] [--key KEY] [--proxy URL] [--yes]
```

## Prerequisites

Run `aegi doctor` any time to check these and get the exact install command for
your OS (it flags what's required vs optional and whether your key is set).

- **Claude Code CLI** (`claude`) — the agent drives it.
- **Typst** (`typst`) — compiles the PDF. Optional; HTML fallback otherwise.
- **Scanners** (optional, repo mode) — `gitleaks`, `osv-scanner`, `semgrep`, `trufflehog`.
  Any that are on PATH are run and used to ground findings; install the ones you want.
- Python 3.11+.

## Notes / limits (v0)

- **URL scope is prompt-enforced, not sandboxed** — the agent is told to touch only
  the target host. Treat as a soft guard; only run against targets you're authorized
  to test. Hard scope enforcement is planned.
- **Repo mode** runs any installed deterministic scanners (gitleaks, osv-scanner,
  semgrep, trufflehog) and feeds their real output to the agent as ground truth, then
  the agent triages and writes the report. With none installed it falls back to a
  read-only LLM review (CVE claims are then memory-based — install scanners to ground them).
  Scanners are optional: install the ones you want and they're used automatically.
- Needs Python 3.11+ (uses stdlib `tomllib`).
