0sec-labs/0

A cybersecurity harness for full-stack LLM-driven penetration testing. Find and fix vulnerabilities autonomously, 24/7. [RESEARCH PREVIEW]

TypeScript

134

1,450 commits

updated Sep 28, 2026

See the code

See what people are saying

README

Software already builds software. Now it can secure itself, too.

0security

The open-source, self-evolving, multi-model harness for security research.
The Swiss Applied AI & Cybersecurity Research Lab
0.security · Documentation · FoxGuard

License: MIT OR Apache-2.0 Latest release Status: research preview

Zero studies, finds, fixes, reports, and improves.

The harness behind our research breakthroughs.

Find novel vulnerabilities in the deepest layers of software. Explore our public disclosures and upstream fixes, including research in the Linux kernel.

Get started

Docs for your agent

Copy this prompt into your coding agent:

Set up the 0.security harness using https://0.security/harness/setup.md and read https://0.security/llms.txt for the documentation index. Confirm my targets and scope before testing, and ask before changing files.

Quick install

curl -fsSL https://raw.githubusercontent.com/0sec-labs/0/main/install.sh | bash
0

Bring your model access and configure connections in the terminal. Run locally or through the CLI in CI/CD, inspect findings and verification results, and export reports as JSON, Markdown or SARIF.

Setup guide · Research workflows · Documentation

Built for security research

  • Open research. Benchmark-led agent design and A/B-tested attack strategies, with public findings that others can inspect.
  • Extensible tools. Use the in-house security linter, connect your own tools, and let agents write and run tools for the investigation.
  • Adaptive agents. Delegate focused investigations to subagents with fresh context and bounded budgets, then collect their findings. See the agent loop and worker monitoring.
  • Multi-model harness. Bring the models you prefer into one security workflow. Combine deterministic steps with adaptive investigations.
  • Evaluated self-improvement. Propose changes, evaluate them, and select better versions for future runs. Learn more about the improvement plane.

Available on 0.security

Optimized Model Routing: The best LLM for each step

The managed service adds model routing, non-public frontier cyber models, a purpose-built attack runtime and a curated offensive toolchain. These hosted capabilities are separate from running the open-source harness with your own model access. Explore 0.security.

Make software secure itself.

The world's best security should belong to everyone. Software already writes itself; we believe it should secure itself, too. Our goal is security that finds and fixes vulnerabilities as software changes, so people can focus on what they want to create.

Research comes first. Public disclosures, upstream fixes and reproducible results let people check our work. Open tools let them question it, extend it and build something better. Self-securing software is the future we're working toward.

Read our manifesto · Explore our research

Status

This is a research preview. Coverage and verification depth vary by workflow; inspect the evidence and review generated fixes before applying them. Tool making and evaluated self-improvement are developing research workflows. Only test systems you own or are authorized to assess.

Contributing

Read CONTRIBUTING.md to build and extend the harness. Report security issues through SECURITY.md.

License

MIT OR Apache-2.0.

ai-security
application-security
autonomous-agents
binary-analysis
cve
cybersecurity
devsecops
fuzzing
llm-agents
llm-security
mcp
owasp
penetration-testing
prompt-injection
red-team
sast
security
security-research
security-tools
vulnerability-scanner

0sec-labs/0

A cybersecurity harness for full-stack LLM-driven penetration testing. Find and fix vulnerabilities autonomously, 24/7. [RESEARCH PREVIEW]

TypeScript

134

1,450 commits

updated Sep 28, 2026

See the code

See what people are saying

README

Software already builds software. Now it can secure itself, too.

0security

The open-source, self-evolving, multi-model harness for security research.
The Swiss Applied AI & Cybersecurity Research Lab
0.security · Documentation · FoxGuard

License: MIT OR Apache-2.0 Latest release Status: research preview

Zero studies, finds, fixes, reports, and improves.

The harness behind our research breakthroughs.

Find novel vulnerabilities in the deepest layers of software. Explore our public disclosures and upstream fixes, including research in the Linux kernel.

Get started

Docs for your agent

Copy this prompt into your coding agent:

Set up the 0.security harness using https://0.security/harness/setup.md and read https://0.security/llms.txt for the documentation index. Confirm my targets and scope before testing, and ask before changing files.

Quick install

curl -fsSL https://raw.githubusercontent.com/0sec-labs/0/main/install.sh | bash
0

Bring your model access and configure connections in the terminal. Run locally or through the CLI in CI/CD, inspect findings and verification results, and export reports as JSON, Markdown or SARIF.

Setup guide · Research workflows · Documentation

Built for security research

  • Open research. Benchmark-led agent design and A/B-tested attack strategies, with public findings that others can inspect.
  • Extensible tools. Use the in-house security linter, connect your own tools, and let agents write and run tools for the investigation.
  • Adaptive agents. Delegate focused investigations to subagents with fresh context and bounded budgets, then collect their findings. See the agent loop and worker monitoring.
  • Multi-model harness. Bring the models you prefer into one security workflow. Combine deterministic steps with adaptive investigations.
  • Evaluated self-improvement. Propose changes, evaluate them, and select better versions for future runs. Learn more about the improvement plane.

Available on 0.security

Optimized Model Routing: The best LLM for each step

The managed service adds model routing, non-public frontier cyber models, a purpose-built attack runtime and a curated offensive toolchain. These hosted capabilities are separate from running the open-source harness with your own model access. Explore 0.security.

Make software secure itself.

The world's best security should belong to everyone. Software already writes itself; we believe it should secure itself, too. Our goal is security that finds and fixes vulnerabilities as software changes, so people can focus on what they want to create.

Research comes first. Public disclosures, upstream fixes and reproducible results let people check our work. Open tools let them question it, extend it and build something better. Self-securing software is the future we're working toward.

Read our manifesto · Explore our research

Status

This is a research preview. Coverage and verification depth vary by workflow; inspect the evidence and review generated fixes before applying them. Tool making and evaluated self-improvement are developing research workflows. Only test systems you own or are authorized to assess.

Contributing

Read CONTRIBUTING.md to build and extend the harness. Report security issues through SECURITY.md.

License

MIT OR Apache-2.0.

ai-security
application-security
autonomous-agents
binary-analysis
cve
cybersecurity
devsecops
fuzzing
llm-agents
llm-security
mcp
owasp
penetration-testing
prompt-injection
red-team
sast
security
security-research
security-tools
vulnerability-scanner

Languages

TypeScript

73.5%

Python

21.9%

Rust

2.5%