- docs/architecture.md: full architecture spec (safety contract, topology, Tool API, data model, phasing). - docs/adr/0001-0011: decision records for the grilling outcomes. - Repo skeleton: Cargo workspace (crates/core), pnpm workspace (apps/desktop, packages/ui), Python workers package, OCI runtime placeholder, graph JSON Schema. - AGENTS.md, CONTEXT.md, THIRD_PARTY.md, README.md, LICENSE (AGPL-3.0). - GitHub issues #1-#14: phase epics plus Phase 1 tickets.
Prog-Prober
An open-source, Linux-hosted, local-first desktop workbench for analyzing untrusted binaries — static execution graphing, isolated dynamic execution, network sinkholing, and defense probing — under one agent-drivable interface.
Agent-first, human-steered. The primary consumer of the tool API is an LLM agent (via MCP); the human analyst steers through the UI.
Status: scaffold. The architecture is specified and tickets are open; no analysis pipeline is implemented yet.
Scope
- Primary target: Windows PE (x64). Secondary: ELF (x64).
- Host: Linux with
/dev/kvm. - Samples are authorized and analyzed offline.
Safety contract
These are hard requirements; see docs/architecture.md §3.
- Samples are read-only and content-addressed.
- Nothing untrusted ever executes on the host.
- Detonation only in a disposable sandbox.
- Egress is default-deny; only the sinkhole proxy is reachable.
- No host network-namespace sharing.
- Teardown is verified and attested per run.
- Explicit artifact retention policy.
Architecture at a glance
Electron shell → Rust progprober-core sidecar (Tool API + MCP + job queue +
case store) → Python analysis workers and a versioned progprober-runtime OCI
image driven by Podman. Full detail in docs/architecture.md.
Repository layout
crates/core/ Rust orchestrator daemon
apps/desktop/ Electron shell
packages/ui/ React renderer
workers/python/ Analysis workers (PyGhidra, capa, Speakeasy, Qiling)
docker/runtime/ progprober-runtime OCI image
schemas/ Graph JSON Schema
docs/architecture.md The specification
docs/adr/ Architecture decision records
CONTEXT.md Domain glossary
AGENTS.md Working notes for coding agents
Toolchain
- Rust (nightly), Node 22 + pnpm, Python 3.10+, Podman.
cargo build,pnpm install && pnpm build,python -m progprober_workers.
License
AGPL-3.0-or-later. Third-party components and their licenses are listed in
THIRD_PARTY.md.