Attack surface heatmap of a Python or JS Ts codebase, ranked top-down by the jev classifier on a fixed budget
Python
0
5 commits
updated Oct 2, 2026
Maps the attack surface of a backend codebase and flags likely vulnerabilities, down to the suspicious line, for about one cent per repo.
Try it without installing anything: https://franciscocarloserra.github.io/jev-attack-surface-analysis/ (read-only results on PyGoat and NodeGoat).

You give it a repo (Python, JavaScript or TypeScript) and a budget in dollars. You get:
eval, a shell or an outbound request);print_issues.py) that hands that list to an AI agent, with the
instruction to validate each issue, not to fix it.No LLM is involved. Plain Python reads the code; jev, a classifier that answers fixed questions with probabilities in under a second and at about $42 per billion input tokens, does all the judging.
Like a magnifying glass: it looks at the whole repo coarsely, then zooms into the suspicious parts only. At each level jev rates every item, and only the hot ones are opened at the next level.
repo
│
▼ 1. directories jev reads names only → drops tests, docs, migrations
│
▼ 2. files jev reads imports + signatures → exposure: none / low / medium / high
│
▼ 3. functions jev reads the code → does external input reach a dangerous operation?
│
▼ 4. lines jev picks one of the function's lines → where the vulnerability happens
│
▼
ranked issues ──► viewer / copy ──► your agent validates them
Tested only against two apps that are vulnerable on purpose (measured 2026-10-02):
| Repo | Language | Cost | Top issues found |
|---|---|---|---|
| PyGoat | Python / Django | $0.010 | SQL injection, eval, pickle.loads, SSRF |
| NodeGoat | JavaScript / Express | $0.007 | eval on request body, open redirect, SSRF, NoSQL $where injection |
You need a TypeSafe API key for jev.
python3 -m venv .venv && .venv/bin/pip install -r requirements.txt
export TYPESAFE_API_KEY=...
git clone --depth 1 https://github.com/adeyosemanputra/pygoat repos/pygoat
python3 viewer_server.py # open http://localhost:7801/heatmap_viewer.html
In the viewer pick the repo, set a budget (max $0.05 per run) and press Run analysis. From the shell instead:
.venv/bin/python attack_surface_scan.py repos/pygoat --budget 0.03
python3 print_issues.py examples/pygoat/scan_result.json --top 10
Every run is saved in examples/<repo>/runs/<run id>.json (with date, scanner version and
settings hash) and the latest one in examples/<repo>/scan_result.json.
Agents: see AGENTS.md for the commands and the result format.
| File | What it is |
|---|---|
attack_surface_scan.py | the scanner |
classification_levels.json | every setting: questions to jev, categories, thresholds, budget shares, languages |
heatmap_viewer.html + viewer_server.py | the viewer, and the small server that lets it start runs |
print_issues.py | issue list as text, for agents |
examples/ | saved runs |
classification_levels.json.languages in the same file (file extensions and
the parser's names for imports, functions and classes).extract_<unit> function in
attack_surface_scan.py, register it in UNIT_EXTRACTORS and add the level to the JSON.Python
51.7%
HTML
48.3%
Attack surface heatmap of a Python or JS Ts codebase, ranked top-down by the jev classifier on a fixed budget
Python
0
5 commits
updated Oct 2, 2026
Maps the attack surface of a backend codebase and flags likely vulnerabilities, down to the suspicious line, for about one cent per repo.
Try it without installing anything: https://franciscocarloserra.github.io/jev-attack-surface-analysis/ (read-only results on PyGoat and NodeGoat).

You give it a repo (Python, JavaScript or TypeScript) and a budget in dollars. You get:
eval, a shell or an outbound request);print_issues.py) that hands that list to an AI agent, with the
instruction to validate each issue, not to fix it.No LLM is involved. Plain Python reads the code; jev, a classifier that answers fixed questions with probabilities in under a second and at about $42 per billion input tokens, does all the judging.
Like a magnifying glass: it looks at the whole repo coarsely, then zooms into the suspicious parts only. At each level jev rates every item, and only the hot ones are opened at the next level.
repo
│
▼ 1. directories jev reads names only → drops tests, docs, migrations
│
▼ 2. files jev reads imports + signatures → exposure: none / low / medium / high
│
▼ 3. functions jev reads the code → does external input reach a dangerous operation?
│
▼ 4. lines jev picks one of the function's lines → where the vulnerability happens
│
▼
ranked issues ──► viewer / copy ──► your agent validates them
Tested only against two apps that are vulnerable on purpose (measured 2026-10-02):
| Repo | Language | Cost | Top issues found |
|---|---|---|---|
| PyGoat | Python / Django | $0.010 | SQL injection, eval, pickle.loads, SSRF |
| NodeGoat | JavaScript / Express | $0.007 | eval on request body, open redirect, SSRF, NoSQL $where injection |
You need a TypeSafe API key for jev.
python3 -m venv .venv && .venv/bin/pip install -r requirements.txt
export TYPESAFE_API_KEY=...
git clone --depth 1 https://github.com/adeyosemanputra/pygoat repos/pygoat
python3 viewer_server.py # open http://localhost:7801/heatmap_viewer.html
In the viewer pick the repo, set a budget (max $0.05 per run) and press Run analysis. From the shell instead:
.venv/bin/python attack_surface_scan.py repos/pygoat --budget 0.03
python3 print_issues.py examples/pygoat/scan_result.json --top 10
Every run is saved in examples/<repo>/runs/<run id>.json (with date, scanner version and
settings hash) and the latest one in examples/<repo>/scan_result.json.
Agents: see AGENTS.md for the commands and the result format.
| File | What it is |
|---|---|
attack_surface_scan.py | the scanner |
classification_levels.json | every setting: questions to jev, categories, thresholds, budget shares, languages |
heatmap_viewer.html + viewer_server.py | the viewer, and the small server that lets it start runs |
print_issues.py | issue list as text, for agents |
examples/ | saved runs |
classification_levels.json.languages in the same file (file extensions and
the parser's names for imports, functions and classes).extract_<unit> function in
attack_surface_scan.py, register it in UNIT_EXTRACTORS and add the level to the JSON.Python
51.7%
HTML
48.3%