AI Skill Hub 强烈推荐:raptor Agent工作流 是一款优质的Agent工作流。已获得 2.5k 颗 GitHub Star,AI 综合评分 8.2 分,在同类工具中表现稳健。如果你正在寻找可靠的Agent工作流解决方案,这是一个值得深入了解的选择。
基于Claude的开源AI安全工作流框架,支持攻防安全自动化任务编排。将代码转化为通用安全工具,适合安全研究人员、渗透测试人员和DevSecOps工程师进行自动化安全检测和防御。
raptor Agent工作流 是一套完整的 AI Agent 自动化工作流方案。通过可视化的节点编排,将复杂的多步骤任务拆解为清晰的自动化流程,实现全程无人值守的智能处理。支持与数百种外部服务和 API 无缝集成,适合构建数据处理管线、业务自动化和 AI 辅助决策系统。
基于Claude的开源AI安全工作流框架,支持攻防安全自动化任务编排。将代码转化为通用安全工具,适合安全研究人员、渗透测试人员和DevSecOps工程师进行自动化安全检测和防御。
raptor Agent工作流 是一套完整的 AI Agent 自动化工作流方案。通过可视化的节点编排,将复杂的多步骤任务拆解为清晰的自动化流程,实现全程无人值守的智能处理。支持与数百种外部服务和 API 无缝集成,适合构建数据处理管线、业务自动化和 AI 辅助决策系统。
# 方式一:pip 安装(推荐)
pip install raptor
# 方式二:虚拟环境安装(推荐生产环境)
python -m venv .venv
source .venv/bin/activate # Windows: .venv\Scripts\activate
pip install raptor
# 方式三:从源码安装(获取最新功能)
git clone https://github.com/gadievron/raptor
cd raptor
pip install -e .
# 验证安装
python -c "import raptor; print('安装成功')"
# 命令行使用
raptor --help
# 基本用法
raptor input_file -o output_file
# Python 代码中调用
import raptor
# 示例
result = raptor.process("input")
print(result)
# raptor 配置文件示例(config.yml) app: name: "raptor" debug: false log_level: "INFO" # 运行时指定配置文件 raptor --config config.yml # 或通过环境变量配置 export RAPTOR_API_KEY="your-key" export RAPTOR_OUTPUT_DIR="./output"
╔═══════════════════════════════════════════════════════════════════════════╗
║ ║
║ ██████╗ █████╗ ██████╗ ████████╗ ██████╗ ██████╗ ║
║ ██╔══██╗██╔══██╗██╔══██╗╚══██╔══╝██╔═══██╗██╔══██╗ ║
║ ██████╔╝███████║██████╔╝ ██║ ██║ ██║██████╔╝ ║
║ ██╔══██╗██╔══██║██╔═══╝ ██║ ██║ ██║██╔══██╗ ║
║ ██║ ██║██║ ██║██║ ██║ ╚██████╔╝██║ ██║ ║
║ ╚═╝ ╚═╝╚═╝ ╚═╝╚═╝ ╚═╝ ╚═════╝ ╚═╝ ╚═╝ ║
║ ║
║ Autonomous Offensive/Defensive Research Framework ║
║ Based on Claude Code (v3.1.0) ║
║ ║
║ Gadi Evron, Daniel Cuthbert, Thomas Dullien (Halvar Flake) ║
║ Michael Bargury, John Cartwright ║
║ ║
╚═══════════════════════════════════════════════════════════════════════════╝
⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⢀⣠⣤⣤⣀⣀
⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⣾⣿⣿⠿⠿⠟
⠀⠀⠀⠀⠀⠀⠀⠀⢀⣀⣀⣀⣀⣀⣀⣤⣴⣶⣶⣶⣤⣿⡿⠁⠀⠀⠀
⣀⠤⠴⠒⠒⠛⠛⠛⠛⠛⠿⢿⣿⣿⣿⣿⣿⣿⣿⣿⣿⠟⠁⠀⠀⠀⠀
⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠉⠛⣿⣿⣿⡟⠻⢿⡀⠀⠀⠀⠀⠀
⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⢀⣾⢿⣿⠟⠀⠸⣊⡽⠀⠀⠀⠀⠀
⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⢸⡇⣿⡁⠀⠀⠀⠉⠁⠀⠀⠀⠀⠀
⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠈⠻⠿⣿⣧⠀ Get them bugs.....⠀⠀⠀⠀⠀
<a href="https://github.com/gadievron/raptor/actions/workflows/github-code-scanning/codeql"><img src="https://github.com/gadievron/raptor/actions/workflows/github-code-scanning/codeql/badge.svg"></a>
Authors: Gadi Evron, Daniel Cuthbert, Thomas Dullien (Halvar Flake), Michael Bargury, John Cartwright (@gadievron, @danielcuthbert, @thomasdullien, @mbrg, @grokjc)
Licence: MIT, see LICENSE. Note that CodeQL has its own licence and does not permit commercial use.
Repository: https://github.com/gadievron/raptor
---
python3 engine/semgrep/tools/cache-packs.py list ```
Once populated, the scanner resolves pack IDs to local files and no network call happens. Without the cache, RAPTOR will attempt to fetch registry packs from semgrep.dev at scan time; if offline, it drops uncached packs gracefully and runs with custom rules only.
CodeQL needs network access only during initial setup to download the CLI and query packs. Once installed it runs offline.
---
pip install semgrep) for static analysis. CodeQL is optional but recommended.For the analysis dispatch layer (the LLM that analyses individual findings), Claude Code itself handles everything by default -- no extra API keys needed. If you want multi-model analysis (e.g. Claude + GPT + Gemini), you will need API keys for each provider. See Using a different LLM below.
pip install -r requirements.txt
pip install semgrep
```bash
npm install -g @anthropic-ai/claude-code
Using containers is a common security practice to restrict agents from accessing areas of your filesystem you don't want them to, as well as limiting the blast radius of any malicious code that may execute (e.g via supply-chain attack). The image is large (around 6 GB). It starts from the Microsoft Python 3.12 devcontainer and adds static analysis, fuzzing, and browser automation tooling.
You can pull down a pre-built image:
docker pull danielcuthbert/raptor:latest
or build it locally using the included Dockerfile:
docker build -f .devcontainer/Dockerfile -t raptor:latest .
The image expects the RAPTOR framework (this repo) to be mounted into /workspaces/raptor on startup. You can optionally mount a target folder for local analysis.
To start the container:
docker run -it \
-v "$(pwd):/workspaces/raptor" \
raptor:latest
To mount a target folder as well:
docker run -it \
-v "$(pwd):/workspaces/raptor" \
-v "/path/to/target-folder:/workspaces/target" \
raptor:latest
Add --privileged if you need the rr deterministic debugger.
VS Code devcontainers are also supported. To mount a target folder, add it to the mounts section of .devcontainer/devcontainer.json:
"mounts": [
// ...existing entries...
"source=/path/to/target-folder,target=/workspaces/target,type=bind,consistency=cached"
]
Then open the repo in VS Code — it will prompt you to reopen in the container:
cd /path/to/raptor
code .
Either way, once you're inside the container, run raptor to get started.
---
Start by creating a project so all your runs land in one place:
/project create myapp --target /path/to/code # create a project first
/project use myapp # set it as active
/understand --map # map the attack surface
/agentic --threat-model --validate # map, model, scan, validate
/project findings # review everything in one place
For a compiled artefact, the equivalent starting point is:
/binary investigate /path/to/binary # build the evidence-backed binary map
/binary graph <run-dir> --edges --json # query the persisted graph
/binary trace-parser <run-dir> # collect runtime parser evidence
/binary harness <run-dir> # draft a harness only when the boundary is explicit
/understand builds a context map of entry points, trust boundaries, and sinks before a line of scanning happens. /agentic then runs Semgrep and CodeQL, deduplicates findings, and dispatches each one for validation using the exploitation-validator methodology:
With --threat-model, RAPTOR runs the map first, creates threat-model.json and THREAT_MODEL.md if the project does not already have them, then feeds a compact version into /understand, autonomous analysis, and /validate. Existing project threat models are preserved unless you pass --threat-model-refresh; stale fallback maps are refused unless you explicitly pass --threat-model-use-stale. It also turns mapped unchecked flows into candidate SARIF so scanner misses do not kill the run. It is operator-owned context, not magic proof: findings still need code evidence or oracle-backed confirmation. See docs/threat-model.md.
Findings that clear validation get exploit PoCs and patches generated. A cross-finding analysis runs at the end to find shared root causes and attack chains.
/validate runs this same pipeline as a standalone step if you already have findings from a previous scan.
For a compiled artefact, /binary <path> now runs an evidence-first investigation rather than dumping a pile of raw reverse-engineering artefacts on the operator. Underneath it still builds the SHA-256-bound manifest, evidence ledger, context map, checklist and SQLite graph from file metadata, imports and radare2 xrefs. Mach-O apps also get slice inventory, bundle metadata and Objective-C / Swift class selectors; high-value pseudocode is persisted rather than disappearing inside the run. PE DLL exports, Windows driver dispatchers and Linux kernel-module ioctl handlers are handled as their own ingress candidates too, with PE architecture read from the COFF header rather than guessed. The investigation layer then queries that graph, ranks external ingress before generic sink leads, discovers declared helper/sibling binaries, and writes a compact report split into facts, structural inferences and unproven hypotheses. Frida observations, fuzz crash witnesses, explicit Z3 checks and binary diffs can then add stronger evidence later. RAPTOR also keeps the internal call graph needed to recover bounded ingress-to-parser candidates, so an app callback can be narrowed to the internal function that actually calls XML_Parse, d2i_X509, jpeg_read_header or another real parser surface without pretending that is taint proof. /binary trace-parser <run-dir> is the explicit dynamic follow-on: it runs the narrow Frida parser trace, then refreshes the same context map, handoff, graph and investigation report in place. /binary investigate --active maps first and only launches a real fuzz campaign when a concrete harness boundary exists; app, DLL and driver targets get a harness or snapshot step instead. /binary harness writes an evidence-backed harness spec for the chosen ingress and only emits candidate source when the ABI or IOCTL contract is explicit. It does not blag its way from “memcpy exists” to “this is exploitable”: imports, selectors and call edges stay candidates until something mechanical proves more. See docs/binary-analysis.md.
---
RAPTOR has a two-layer Z3 integration (pip install z3-solver). It is optional. Everything works without it, but the results are better with it.
Dataflow pre-screening (CodeQL)
When CodeQL produces a path result, the path constraints are checked for satisfiability before any LLM call is made. Paths that are provably unreachable get dropped immediately. For paths that are reachable, Z3 produces concrete candidate inputs that go into the analysis prompt, so the LLM has something specific to reason about rather than abstract patterns.
One-gadget constraint analysis (binary feasibility)
During binary exploit feasibility assessment, Z3 checks whether a one-gadget's register and memory constraints are satisfiable against the concrete crash state. Gadgets are ranked by actual reachability rather than heuristics, so you spend time on gadgets that can actually work.
Z3 is pre-installed in the devcontainer. For manual installs: pip install z3-solver.
---
RAPTOR's custom rules under engine/semgrep/rules/ are fully local and run without network access.
For registry packs (p/security-audit, p/owasp-top-ten, etc.), the cache directory ships empty. A cache tool (engine/semgrep/tools/cache-packs.py) handles population:
```bash
export PATH="$PATH:$PWD/bin"
创新的安全工作流框架,融合AI能力与安全实践,具有较强的实用价值和技术深度,社区活跃度良好。
该工具使用 NOASSERTION 协议,商用场景请仔细阅读协议条款,必要时咨询法律意见。
AI Skill Hub 为第三方内容聚合平台,本页面信息基于公开数据整理,不对工具功能和质量作任何法律背书。
建议在沙箱或测试环境中充分验证后,再部署至生产环境,并做好必要的安全评估。
📄 NOASSERTION — 请查阅原始协议条款了解具体使用限制。
总体来看,raptor Agent工作流 是一款质量优秀的Agent工作流,在同类工具中具备一定竞争力。AI Skill Hub 将持续追踪其更新动态,建议收藏备用,结合自身场景选择合适时机引入使用。
| 原始名称 | raptor |
| 原始描述 | 开源AI工作流:Raptor turns Claude Code into a general-purpose AI offensive/defensive security 。⭐2.5k · Python |
| Topics | 安全工作流AI自动化攻防工具代码生成 |
| GitHub | https://github.com/gadievron/raptor |
| License | NOASSERTION |
| 语言 | Python |
收录时间:2026-05-16 · 更新时间:2026-05-19 · License:NOASSERTION · AI Skill Hub 不对第三方内容的准确性作法律背书。
选择 Agent 类型,复制安装指令后粘贴到对应客户端