The open-source, self-evolving, multi-model harness for security research.
Backed by Y Combinator · The Swiss Applied AI & Cybersecurity Research Lab
0.security ·
Documentation ·
FoxGuard
Security research, in your workspace
0 is an open-source, multi-model harness for investigating software security: read code, run tools, investigate findings and review proposed fixes. Built by the Swiss Applied AI & Cybersecurity Research Lab, it supports our public disclosures and upstream fixes.
Get started
Install on Apple Silicon macOS or x64/ARM64 Linux, then open 0:
curl -fsSL https://raw.githubusercontent.com/0sec-labs/0/main/install.sh | bash
export PATH="$HOME/.0/bin:$PATH"
0
Local web app development
From a source checkout with dependencies installed, run:
npm run dev
Open the local browser address printed by the launcher. The web app connects
to the local engine and supports onboarding, provider connections, conversations,
and approvals in the browser. Frontend changes reload automatically. The terminal
console remains available separately through 0.
Work locally, extend deliberately
- Describe an authorized repository and investigation goal in chat, or use
0 review ./authorized-repo for a source review.
- Review findings and proposed changes.
- Connect your tools through MCP and integrations.
/hackstore, or build and locally install an extension.
Community plugins run as local processes; review them before enabling.
Why 0?
Use the models you want. Bring the tools you need. Make the workflow your own. 0 brings security investigations and fixes into one terminal workspace, with focused agents and an extensible toolchain. The harness is open source and runs under your control.
Guides
- Quick start and installation
- Models and provider connections
- Console, sessions and agents
- Plugins and Hackstore publishing
- Scope and authorization
- GitHub Actions
- Troubleshooting
Status and safety
This is a research preview, not a guarantee of coverage or correctness. Review results and generated fixes before applying them. Tool making and evaluated self-improvement are research workflows.
Only test systems you own or are authorized to assess. The optional
scope plugin is disabled by default:
enable it explicitly with 0 plugin enable scope and configure your boundaries.
The default console uses YOLO mode; use 0 console --mode standard for
Contributing and license
Build and extend the harness with CONTRIBUTING.md. Report security issues through SECURITY.md. Licensed under MIT OR Apache-2.0.
Acknowledgments
Thanks to the teams behind OpenTUI, Bun and React for the interface stack, and Models.dev and LiteLLM for model metadata and pricing estimates. Thank you to everyone contributing code, reporting bugs and sharing ideas.