BillyOutlast a197e50988 Scaffold Prog-Prober: spec, ADRs, and Phase 1 tracker
- docs/architecture.md: full architecture spec (safety contract, topology,
  Tool API, data model, phasing).
- docs/adr/0001-0011: decision records for the grilling outcomes.
- Repo skeleton: Cargo workspace (crates/core), pnpm workspace
  (apps/desktop, packages/ui), Python workers package, OCI runtime
  placeholder, graph JSON Schema.
- AGENTS.md, CONTEXT.md, THIRD_PARTY.md, README.md, LICENSE (AGPL-3.0).
- GitHub issues #1-#14: phase epics plus Phase 1 tickets.
2026-09-19 17:50:23 -04:00

Prog-Prober

An open-source, Linux-hosted, local-first desktop workbench for analyzing untrusted binaries — static execution graphing, isolated dynamic execution, network sinkholing, and defense probing — under one agent-drivable interface.

Agent-first, human-steered. The primary consumer of the tool API is an LLM agent (via MCP); the human analyst steers through the UI.

Status: scaffold. The architecture is specified and tickets are open; no analysis pipeline is implemented yet.

Scope

  • Primary target: Windows PE (x64). Secondary: ELF (x64).
  • Host: Linux with /dev/kvm.
  • Samples are authorized and analyzed offline.

Safety contract

These are hard requirements; see docs/architecture.md §3.

  1. Samples are read-only and content-addressed.
  2. Nothing untrusted ever executes on the host.
  3. Detonation only in a disposable sandbox.
  4. Egress is default-deny; only the sinkhole proxy is reachable.
  5. No host network-namespace sharing.
  6. Teardown is verified and attested per run.
  7. Explicit artifact retention policy.

Architecture at a glance

Electron shell → Rust progprober-core sidecar (Tool API + MCP + job queue + case store) → Python analysis workers and a versioned progprober-runtime OCI image driven by Podman. Full detail in docs/architecture.md.

Repository layout

crates/core/          Rust orchestrator daemon
apps/desktop/         Electron shell
packages/ui/          React renderer
workers/python/       Analysis workers (PyGhidra, capa, Speakeasy, Qiling)
docker/runtime/       progprober-runtime OCI image
schemas/              Graph JSON Schema
docs/architecture.md  The specification
docs/adr/             Architecture decision records
CONTEXT.md            Domain glossary
AGENTS.md             Working notes for coding agents

Toolchain

  • Rust (nightly), Node 22 + pnpm, Python 3.10+, Podman.
  • cargo build, pnpm install && pnpm build, python -m progprober_workers.

License

AGPL-3.0-or-later. Third-party components and their licenses are listed in THIRD_PARTY.md.

S
Description
No description provided
Readme AGPL-3.0
195 KiB
Languages
Shell 64.3%
JavaScript 23%
Dockerfile 5.1%
Rust 3.4%
TypeScript 2.5%
Other 1.7%