-
-
Vulnerabilities Breakdown
-
Vulnerability Graph Analysis
-
ARGUS in Action
-
Argus Vulnerabilities Analysis
-
Agent Breakdown Analysis
-
Security Overview
-
Home Page
-
3D Sound Visualization
-
Qualitative Analysis
-
Audio Wave Form Analysis
-
Spectrogram Analysis
-
Technical Analysis
-
Technical & Numerical Analysis
-
Sound Manipulation Analysis
-
Review Score for Sound Analysis
Inspiration
Security review doesn't scale with how fast people ship code. Manual review is slow. Naive "throw the whole repo at an LLM" tools are slow, expensive, and easy to fool with irrelevant context. Meanwhile, as AI-generated and AI-edited audio gets harder to spot by ear, most "AI or not" detectors are opaque black boxes, you get a score with no explanation of why.
What it does
This is Argus. Paste a GitHub repo, pick a scan depth, and hit go. While it's running, you're watching real progress — it's cloning the repo, scanning every file with deterministic rules, and figuring out which of our eight specialized AI agents are actually worth running on this codebase. That last part matters: we don't send your whole repo to an LLM. We only route the files that show real risk signals to the agents built to catch that specific class of bug — so a scan stays fast and the AI review stays focused. You get a findings list, severities, and a PDF you can hand to a teammate.
Drop in a recording and we break it into four-second sections, pull out the DSP features — spectral shape, MFCCs, timing — and score each section. You can scrub through the waveform and spectrogram and see exactly where the signal looks off, instead of trusting a single opaque number. No AI model calls here at all — just interpretable signal processing, with room to plug in a trained model when you have one.
How we built it
ARGUS uses a React and Vite frontend with a Python FastAPI backend. The backend is organized around a staged analysis pipeline: repository preprocessing, security-signal detection, intelligent agent routing, vulnerability analysis, finding normalization, and report generation. We implemented deterministic security rules for fast detection of common vulnerabilities and integrated Google Gemini for deeper contextual analysis. Specialized agents focus on different security domains rather than sending an entire repository to a single model. The frontend provides real-time scan progress, severity summaries, agent routing information, detailed findings, and audio-forensics visualizations. We deployed the frontend with Vercel and the backend with Render.
Challenges we ran into
One of our biggest challenges was making agentic analysis practical without requiring excessive computation or API usage. Running multiple agents sequentially could make scans unnecessarily slow, so we designed preprocessing and routing to analyze only the files and security domains that are relevant to a repository. We also ended up getting a runtime of under 3 seconds and we were incredibly happy until we realized our agents analyzed nothing. It was definitely an interesting turning point.
Accomplishments that we're proud of
We are proud of building ARGUS as a complete end-to-end security analysis platform rather than simply a collection of vulnerability detectors. The system combines traditional rule-based analysis with specialized AI agents and intelligently determines which analysis paths are relevant to a repository. We also built a polished dashboard that turns complex security analysis into actionable findings and added an audio-forensics capability that expands ARGUS beyond traditional source-code security. Most importantly, we built the system as a working application with a real API, frontend, reporting pipeline, GitHub integration, and cloud deployment.
What we learned
We learned that effective AI security tooling requires more than simply giving code to an LLM. Preprocessing, routing, deterministic checks, structured outputs, deduplication, and careful orchestration are critical for making agentic systems useful, fast, and consistent. We also gained practical experience integrating AI into a traditional software architecture, designing security-analysis pipelines, handling asynchronous workflows, and deploying a full-stack application to the cloud.
What's next for ARGUS
Our next goal is to evolve ARGUS from a hackathon prototype into a more comprehensive security engineering platform. We want to add deeper repository-wide data-flow analysis, dependency and supply-chain security, historical vulnerability tracking, stronger verification of AI-generated findings, and automated remediation suggestions. We would also like to use stronger LLMs so that we are able to expand upon the analysis of the project as well as create a pay wall system to have unlimited usage of these LLMs.
Log in or sign up for Devpost to join the conversation.