No description
  • Go 89.9%
  • HTML 9.4%
  • Dockerfile 0.4%
  • Makefile 0.3%
Find a file
Repository files (latest commit first)
Filename Latest commit message Latest commit date
James Luther 9431bc4158
Some checks failed
codecov/patch Patch coverage: N/A (not in PR context)
security-scan / security-scan (push) Failing after 20s
build-and-push / build (push) Successful in 2m28s
codecov/project 83.38% (No base report)
test / go (push) Successful in 4m26s
test / coverage-badge (push) Successful in 4m6s
Configure AI via env and UI instead of CLI flags
Keys passed as CLI flags leak into shell history and process arguments.
Move all AI configuration off the command line:

- internal/aiconfig.Manager holds the settings and the clients derived
  from them, seeded from VANTAGE_AI_* / VANTAGE_CHAT_* env at first boot
  and overridable at runtime from the UI. Changes persist to ai.json
  (mode 0600) in the data dir and take precedence over the environment.
- The adjudicator and asker hot-swap: the pipeline now takes a provider
  func, and the server consults the manager per request.
- Server GET/POST /api/config: status is secret-free (*_key_set
  booleans only); keys are never returned to the browser, and a blank
  key on save keeps the existing one.
- UI Settings tab to view status and edit the backends.
- serve loses the --ai-* / --chat-* flags; usage documents the env vars.
2026-10-08 12:05:52 -05:00
.forgejo/workflows Initial commit: intercepting proxy with AI finding adjudication 2026-10-08 10:28:02 -05:00
cmd/vantage Configure AI via env and UI instead of CLI flags 2026-10-08 12:05:52 -05:00
internal Configure AI via env and UI instead of CLI flags 2026-10-08 12:05:52 -05:00
.gitignore Initial commit: intercepting proxy with AI finding adjudication 2026-10-08 10:28:02 -05:00
.ojoignore Make the security scan clean 2026-10-08 10:33:16 -05:00
Dockerfile Initial commit: intercepting proxy with AI finding adjudication 2026-10-08 10:28:02 -05:00
go.mod Initial commit: intercepting proxy with AI finding adjudication 2026-10-08 10:28:02 -05:00
go.sum Initial commit: intercepting proxy with AI finding adjudication 2026-10-08 10:28:02 -05:00
Makefile Initial commit: intercepting proxy with AI finding adjudication 2026-10-08 10:28:02 -05:00
README.md Configure AI via env and UI instead of CLI flags 2026-10-08 12:05:52 -05:00

Vantage

Vantage is a dynamic application security testing (DAST) tool for web, mobile, and desktop applications — a modern take on Burp/ZAP with local AI. It is a single self-contained Go binary: an intercepting proxy, a flow store, and a local control UI, with no external services required.

Vantage decrypts and records traffic only for hosts you explicitly place in scope. Use it only against applications you are authorized to test.

Architecture

Everything is built on an intercepting proxy. Mobile and desktop coverage is a matter of pointing a device or app's traffic at Vantage's CA and proxy; the web active scanner (next milestone) replays the flows the proxy captures.

  • internal/ca — local certificate authority; mints a short-lived leaf per host, exports the root for installation on a device, emulator, or browser.
  • internal/scope — the interception allowlist. Out-of-scope HTTPS is tunneled byte-for-byte without decryption; interception is off by default.
  • internal/proxy — the proxy itself: plain HTTP and in-scope HTTPS are decrypted, recorded, and forwarded.
  • internal/flow — SQLite-backed store of request/response exchanges.
  • internal/server — local API and embedded web UI (flow inspector, scope management, repeater, CA download).
  • internal/decider — client for a System One model that adjudicates findings. Speaks the /v1/systemone wire format shared by a self-hosted Laya server (preferred, fine-tuned) and TypeSafe's Jev.
  • internal/ask — ask-your-traffic: answers natural-language questions about the captured flows and findings, grounded in the stores, via an OpenAI-compatible chat model (e.g. llama.cpp's llama-server).

Quick start

$ go build -o vantage ./cmd/vantage
$ ./vantage serve --scope '*.example.com'

This starts the proxy on :8080 and the control UI on http://127.0.0.1:8081. Install the root CA on the client you are testing:

$ ./vantage ca export > vantage-ca.pem        # or download it from the UI
$ ./vantage ca fingerprint                     # verify after install

Point the client's proxy at the machine running Vantage on port 8080, add the target hosts to scope (in the UI or via --scope), and flows appear in the UI.

Local AI (optional)

AI is configured in the Settings tab of the UI, or seeded from the environment at first boot. It is never configured on the command line, so keys never land in shell history or process arguments. Settings saved in the UI persist to ai.json (mode 0600) in the data dir and take precedence over the environment thereafter.

# Finding adjudication (cuts false positives): Laya preferred, Jev selectable.
VANTAGE_AI_BACKEND=laya VANTAGE_AI_URL=http://127.0.0.1:8000/v1/systemone \
# Ask-your-traffic: natural-language questions over captured flows/findings.
VANTAGE_CHAT_URL=http://127.0.0.1:8085/v1/chat/completions VANTAGE_CHAT_MODEL=local \
  ./vantage serve --scope '*.example.com'

Both are off until configured; detection still runs without them (findings stay candidates). The chat endpoint is any OpenAI-compatible server — point it somewhere other than Vantage's own :8080/:8081 ports. Full variable list: vantage serve with no AI env prints them in --help-style usage.

Development

$ make test      # race-enabled unit tests
$ make cover     # coverage summary
$ make vet       # go vet + gofmt check