AionUi
Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!
Crawler Summary
Multi-agent cybersecurity intelligence and dynamic vulnerability triage using CrewAI, Groq, Exa, NVD, CISA KEV, and Streamlit. Multi-Agent Cybersecurity Intelligence & Dynamic Threat Triage System A Python cybersecurity project that combines installed-software vulnerability discovery, threat-intelligence enrichment, multi-agent analysis, and dynamic risk prioritization in a Streamlit dashboard. It supports two workflows: - **Manual CVE analysis:** provide a CVE ID to investigate its vulnerability details, threat evidence, and risk. - **Autom Capability contract not published. No trust telemetry is available yet. Last updated 10/9/2026.
Freshness
Last checked 10/9/2026
Best For
cybersecurity-threat-triage is best for crewai, multi-agent workflows where OpenClaw compatibility matters.
Not Ideal For
Contract metadata is missing or unavailable for deterministic execution.
Evidence Sources Checked
editorial-content, GITHUB REPOS, runtime-metrics, public facts pack
Multi-agent cybersecurity intelligence and dynamic vulnerability triage using CrewAI, Groq, Exa, NVD, CISA KEV, and Streamlit. Multi-Agent Cybersecurity Intelligence & Dynamic Threat Triage System A Python cybersecurity project that combines installed-software vulnerability discovery, threat-intelligence enrichment, multi-agent analysis, and dynamic risk prioritization in a Streamlit dashboard. It supports two workflows: - **Manual CVE analysis:** provide a CVE ID to investigate its vulnerability details, threat evidence, and risk. - **Autom
Public facts
4
Change events
1
Artifacts
0
Freshness
Oct 9, 2026
Capability contract not published. No trust telemetry is available yet. Last updated 10/9/2026.
Trust score
Unknown
Compatibility
OpenClaw
Freshness
Oct 9, 2026
Vendor
Nakshatragupta826 Ctrl
Artifacts
0
Benchmarks
0
Last release
Unpublished
Key links, install path, and a quick operational read before the deeper crawl record.
Summary
Capability contract not published. No trust telemetry is available yet. Last updated 10/9/2026.
Setup snapshot
Setup complexity is LOW. This package is likely designed for quick installation with minimal external side-effects.
Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data.
Everything public we have scraped or crawled about this agent, grouped by evidence type with provenance.
Vendor
Nakshatragupta826 Ctrl
Protocol compatibility
OpenClaw
Handshake status
UNKNOWN
Crawlable docs
6 indexed pages on the official domain
Merged public release, docs, artifact, benchmark, pricing, and trust refresh events.
Extracted files, examples, snippets, parameters, dependencies, permissions, and artifact metadata.
Extracted files
0
Examples
6
Snippets
0
Languages
python
text
CVE ID entered by user
|
v
Vulnerability details and threat evidence
|
v
Threat Intelligence Analyst
|
v
Risk Assessment Agent
|
v
Reflection Agent
|
v
Dynamic risk fusion and priority
|
v
SQLite database and dashboardtext
Windows installed-software inventory
|
v
Normalize product name and version
|
v
Map to vendor/product identifiers
|
v
Compare installed version with NVD affected-version configurations
|
v
Only matching CVEs proceed to deeper triage
|
v
Threat evidence + agents + risk fusion
|
v
Save results and show dashboard activitytext
final-system/ ├── dashboard.py ├── scanner.py ├── pipeline.py ├── risk_fusion.py ├── config.py ├── db.py ├── agents.py ├── crew.py ├── requirements.txt ├── tools/ │ ├── product_normalizer.py │ ├── software_inventory.py │ └── vulnerability_discovery.py ├── .env.example ├── .gitignore └── README.md
powershell
git clone https://github.com/<your-github-username>/<your-repository-name>.git cd <your-repository-name>
powershell
py -3.11 -m venv .venv .\.venv\Scripts\Activate.ps1
powershell
.\.venv\Scripts\python.exe --version
Full documentation captured from public sources, including the complete README when available.
Docs source
GITHUB REPOS
Editorial quality
ready
Multi-agent cybersecurity intelligence and dynamic vulnerability triage using CrewAI, Groq, Exa, NVD, CISA KEV, and Streamlit. Multi-Agent Cybersecurity Intelligence & Dynamic Threat Triage System A Python cybersecurity project that combines installed-software vulnerability discovery, threat-intelligence enrichment, multi-agent analysis, and dynamic risk prioritization in a Streamlit dashboard. It supports two workflows: - **Manual CVE analysis:** provide a CVE ID to investigate its vulnerability details, threat evidence, and risk. - **Autom
A Python cybersecurity project that combines installed-software vulnerability discovery, threat-intelligence enrichment, multi-agent analysis, and dynamic risk prioritization in a Streamlit dashboard.
It supports two workflows:
Status: Core workflows have been implemented and tested in the development environment. Detection depends on product coverage, the freshness and completeness of local vulnerability feeds, upstream data quality, and availability of external services. This is an educational/defensive project, not a replacement for a commercial vulnerability-management platform.
CVE ID entered by user
|
v
Vulnerability details and threat evidence
|
v
Threat Intelligence Analyst
|
v
Risk Assessment Agent
|
v
Reflection Agent
|
v
Dynamic risk fusion and priority
|
v
SQLite database and dashboard
Manual mode answers: “Given this CVE, what is its current threat context and risk?”
Windows installed-software inventory
|
v
Normalize product name and version
|
v
Map to vendor/product identifiers
|
v
Compare installed version with NVD affected-version configurations
|
v
Only matching CVEs proceed to deeper triage
|
v
Threat evidence + agents + risk fusion
|
v
Save results and show dashboard activity
Automatic mode answers: “Given the software installed on this endpoint, which known vulnerabilities may affect those versions?”
A result such as 0 new CVE(s) triaged means that the scan did not add any new matching CVEs to triage during that pass. It does not prove that the machine is free of all vulnerabilities; coverage and feed limitations apply.
Main modules in the current development setup include:
final-system/
├── dashboard.py
├── scanner.py
├── pipeline.py
├── risk_fusion.py
├── config.py
├── db.py
├── agents.py
├── crew.py
├── requirements.txt
├── tools/
│ ├── product_normalizer.py
│ ├── software_inventory.py
│ └── vulnerability_discovery.py
├── .env.example
├── .gitignore
└── README.md
Adjust this diagram if the files in your repository differ.
The dashboard or analysis components may run elsewhere, but installed-software discovery is Windows-specific.
Replace the placeholders with your GitHub username and repository name:
git clone https://github.com/<your-github-username>/<your-repository-name>.git
cd <your-repository-name>
py -3.11 -m venv .venv
.\.venv\Scripts\Activate.ps1
If PowerShell blocks activation, use the virtual environment's Python directly:
.\.venv\Scripts\python.exe --version
python -m pip install --upgrade pip
pip install -r requirements.txt
If .env.example is included, create a local .env:
Copy-Item .env.example .env
The development setup uses these variables:
GROQ_API_KEY=your_groq_api_key
EXA_API_KEY=your_exa_api_key
Use real values only in your local .env. Never commit .env, API keys, tokens, or credentials. If a secret was ever committed, revoke or rotate it; deleting it in a later commit does not remove it from Git history.
If config.py or an integration requires other variables, add their names (never their values) to .env.example and document them.
The scanner uses local NVD JSON feeds for version-aware matching. The development setup used compressed feeds for 2025 and 2026. Obtain the required feeds from the official source and place them at the paths expected by tools/vulnerability_discovery.py.
Official source: NVD Data Feeds
Large feed files are intentionally excluded from Git. Check tools/vulnerability_discovery.py for the exact filenames and paths expected by your local code.
From the repository root:
streamlit run dashboard.py
Open the local URL printed by Streamlit, usually http://localhost:8501.
Scheduled automatic scanning requires the dashboard session to remain active.
python scanner.py --once
This runs a single installed-software scan using the configured local feeds and integrations.
The risk-fusion module combines a vulnerability's base CVSS score with dynamic signals, including exploit maturity and the age of threat evidence. The current implementation applies evidence-age decay, caps the fused score at 10, and maps the result to a priority band.
The fused score is a project-specific prioritization aid; it is not an official CVSS score. Check risk_fusion.py for the current weights and P0–P3 thresholds.
The development evaluation used a labelled set of 40 CVEs and reported:
| Metric | Result | |---|---:| | Accuracy | 87.5% | | Precision | 85.7% | | Recall | 90.0% | | F1 score | 87.8% |
These figures describe that particular evaluation set and its labels; they are not a guarantee of real-world detection performance. If publishing these metrics, document the dataset selection, labelling method, test script, and limitations.
Check that the application and version appear in inventory, the product is supported by tools/product_normalizer.py, the expected NVD feeds are present, and the CVE's affected-version configuration includes the installed version. A CVE can exist in NVD without affecting the installed version.
Check that .env exists, its variable names match config.py, and the credentials are valid. Never paste keys into issues, screenshots, or public logs.
Check the filenames and paths expected by tools/vulnerability_discovery.py, then download the feeds from the official NVD source.
Stop Streamlit with Ctrl+C in the terminal and restart:
streamlit run dashboard.py
Issues and pull requests are welcome. Do not include secrets, personal data, or sensitive endpoint details in reports. Provide reproducible test cases with environment-specific details redacted.
No license has been selected yet. Until a license is added, assume the repository is all rights reserved by default. Before publishing publicly, choose a license and add a LICENSE file. MIT is a common permissive choice for student projects, but only use it if you have the right to license all included code and assets.
Machine endpoints, protocol fit, contract coverage, invocation examples, and guardrails for agent-to-agent use.
Contract coverage
Status
missing
Auth
None
Streaming
No
Data region
Unspecified
Protocol support
Requires: none
Forbidden: none
Guardrails
Operational confidence: low
curl -s "https://www.xpersona.co/api/v1/agents/crewai-nakshatragupta826-ctrl-cybersecurity-threat-triage/snapshot"
curl -s "https://www.xpersona.co/api/v1/agents/crewai-nakshatragupta826-ctrl-cybersecurity-threat-triage/contract"
curl -s "https://www.xpersona.co/api/v1/agents/crewai-nakshatragupta826-ctrl-cybersecurity-threat-triage/trust"
Trust and runtime signals, benchmark suites, failure patterns, and practical risk constraints.
Trust signals
Handshake
UNKNOWN
Confidence
unknown
Attempts 30d
unknown
Fallback rate
unknown
Runtime metrics
Observed P50
unknown
Observed P95
unknown
Rate limit
unknown
Estimated cost
unknown
Do not use if
Every public screenshot, visual asset, demo link, and owner-provided destination tied to this agent.
Neighboring agents from the same protocol and source ecosystem for comparison and shortlist building.
Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!
AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents
AI productivity studio with smart chat, autonomous agents, and 300+ assistants.
The Frontend for Agents & Generative UI. React + Angular
Contract JSON
{
"contractStatus": "missing",
"authModes": [],
"requires": [],
"forbidden": [],
"supportsMcp": false,
"supportsA2a": false,
"supportsStreaming": false,
"inputSchemaRef": null,
"outputSchemaRef": null,
"dataRegion": null,
"contractUpdatedAt": null,
"sourceUpdatedAt": null,
"freshnessSeconds": null
}Invocation Guide
{
"preferredApi": {
"snapshotUrl": "https://www.xpersona.co/api/v1/agents/crewai-nakshatragupta826-ctrl-cybersecurity-threat-triage/snapshot",
"contractUrl": "https://www.xpersona.co/api/v1/agents/crewai-nakshatragupta826-ctrl-cybersecurity-threat-triage/contract",
"trustUrl": "https://www.xpersona.co/api/v1/agents/crewai-nakshatragupta826-ctrl-cybersecurity-threat-triage/trust"
},
"curlExamples": [
"curl -s \"https://www.xpersona.co/api/v1/agents/crewai-nakshatragupta826-ctrl-cybersecurity-threat-triage/snapshot\"",
"curl -s \"https://www.xpersona.co/api/v1/agents/crewai-nakshatragupta826-ctrl-cybersecurity-threat-triage/contract\"",
"curl -s \"https://www.xpersona.co/api/v1/agents/crewai-nakshatragupta826-ctrl-cybersecurity-threat-triage/trust\""
],
"jsonRequestTemplate": {
"query": "summarize this repo",
"constraints": {
"maxLatencyMs": 2000,
"protocolPreference": [
"OPENCLEW"
]
}
},
"jsonResponseTemplate": {
"ok": true,
"result": {
"summary": "...",
"confidence": 0.9
},
"meta": {
"source": "GITHUB_REPOS",
"generatedAt": "2026-10-09T19:31:01.264Z"
}
},
"retryPolicy": {
"maxAttempts": 3,
"backoffMs": [
500,
1500,
3500
],
"retryableConditions": [
"HTTP_429",
"HTTP_503",
"NETWORK_TIMEOUT"
]
}
}Trust JSON
{
"status": "unavailable",
"handshakeStatus": "UNKNOWN",
"verificationFreshnessHours": null,
"reputationScore": null,
"p95LatencyMs": null,
"successRate30d": null,
"fallbackRate": null,
"attempts30d": null,
"trustUpdatedAt": null,
"trustConfidence": "unknown",
"sourceUpdatedAt": null,
"freshnessSeconds": null
}Capability Matrix
{
"rows": [
{
"key": "OPENCLEW",
"type": "protocol",
"support": "unknown",
"confidenceSource": "profile",
"notes": "Listed on profile"
},
{
"key": "crewai",
"type": "capability",
"support": "supported",
"confidenceSource": "profile",
"notes": "Declared in agent profile metadata"
},
{
"key": "multi-agent",
"type": "capability",
"support": "supported",
"confidenceSource": "profile",
"notes": "Declared in agent profile metadata"
}
],
"flattenedTokens": "protocol:OPENCLEW|unknown|profile capability:crewai|supported|profile capability:multi-agent|supported|profile"
}Facts JSON
[
{
"factKey": "vendor",
"category": "vendor",
"label": "Vendor",
"value": "Nakshatragupta826 Ctrl",
"href": "https://github.com/nakshatragupta826-ctrl/cybersecurity-threat-triage",
"sourceUrl": "https://github.com/nakshatragupta826-ctrl/cybersecurity-threat-triage",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-09T10:46:31.318Z",
"isPublic": true
},
{
"factKey": "protocols",
"category": "compatibility",
"label": "Protocol compatibility",
"value": "OpenClaw",
"href": "https://www.xpersona.co/api/v1/agents/crewai-nakshatragupta826-ctrl-cybersecurity-threat-triage/contract",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/crewai-nakshatragupta826-ctrl-cybersecurity-threat-triage/contract",
"sourceType": "contract",
"confidence": "medium",
"observedAt": "2026-10-09T10:46:31.318Z",
"isPublic": true
},
{
"factKey": "docs_crawl",
"category": "integration",
"label": "Crawlable docs",
"value": "6 indexed pages on the official domain",
"href": "https://github.com/login?return_to=https%3A%2F%2Fgithub.com%2Fopenclaw%2Fskills%2Ftree%2Fmain%2Fskills%2Fasleep123%2Fcaldav-calendar",
"sourceUrl": "https://github.com/login?return_to=https%3A%2F%2Fgithub.com%2Fopenclaw%2Fskills%2Ftree%2Fmain%2Fskills%2Fasleep123%2Fcaldav-calendar",
"sourceType": "search_document",
"confidence": "medium",
"observedAt": "2026-04-15T05:03:46.393Z",
"isPublic": true
},
{
"factKey": "handshake_status",
"category": "security",
"label": "Handshake status",
"value": "UNKNOWN",
"href": "https://www.xpersona.co/api/v1/agents/crewai-nakshatragupta826-ctrl-cybersecurity-threat-triage/trust",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/crewai-nakshatragupta826-ctrl-cybersecurity-threat-triage/trust",
"sourceType": "trust",
"confidence": "medium",
"observedAt": null,
"isPublic": true
}
]Change Events JSON
[
{
"eventType": "docs_update",
"title": "Docs refreshed: Sign in to GitHub · GitHub",
"description": "Fresh crawlable documentation was indexed for the official domain.",
"href": "https://github.com/login?return_to=https%3A%2F%2Fgithub.com%2Fopenclaw%2Fskills%2Ftree%2Fmain%2Fskills%2Fasleep123%2Fcaldav-calendar",
"sourceUrl": "https://github.com/login?return_to=https%3A%2F%2Fgithub.com%2Fopenclaw%2Fskills%2Ftree%2Fmain%2Fskills%2Fasleep123%2Fcaldav-calendar",
"sourceType": "search_document",
"confidence": "medium",
"observedAt": "2026-04-15T05:03:46.393Z",
"isPublic": true
}
]Sponsored
Ads related to cybersecurity-threat-triage and adjacent AI workflows.