{"_id":"@araskova/cerberus","_rev":"3-c224ab052b9e695d70d76c6b8371cf6f","name":"@araskova/cerberus","dist-tags":{"latest":"0.2.0"},"versions":{"0.1.0":{"name":"@araskova/cerberus","version":"0.1.0","keywords":["security","skills","skillbook","agent","llm","rust","terminal","appsec","cerberus","araskova"],"author":{"name":"Araskova Labs"},"license":"UNLICENSED","_id":"@araskova/cerberus@0.1.0","maintainers":[{"name":"anvinpshibu","email":"victor.von.doom.prime@gmail.com"}],"bin":{"cerberus":"bin/cerberus.js"},"dist":{"shasum":"b003ed6f1d06b8e57df3008ce7f12194ffcebfce","tarball":"https://registry.npmjs.org/@araskova/cerberus/-/cerberus-0.1.0.tgz","fileCount":44,"integrity":"sha512-e+iusgjd4RIwtbXavsUPkN1ITmE2u+ZbpLg/Ro0UcLXUgTjNrYQWlBmBTz8xh4u+mTu+DB4vEn5o063ye5IeRA==","signatures":[{"sig":"MEUCICiePIMX/zxsG4K0U1wlmIEwofy2jtWjqXcSlCFdcnxXAiEAx3xQ5ZR49FycD/u70/mIuVMlTe8FNQmFgh0jYIaXZBQ=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":183420},"type":"commonjs","engines":{"node":">=18.0.0"},"gitHead":"498c1325a09d6cf3153e7e6399d31acd5c0cb71a","private":false,"scripts":{"dev":"cargo run -p cerberus-cli -- skill list","build":"cargo build --release --workspace","check":"cargo check --workspace","doctor":"cargo run -p cerberus-cli -- doctor","postinstall":"cargo build --release || true","prepublishOnly":"cargo test --workspace && cargo build --release"},"_npmUser":{"name":"anvinpshibu","email":"victor.von.doom.prime@gmail.com"},"_npmVersion":"11.17.0","description":"Cerberus — Universal Security Skill Book & Specification Engine for AI Agents by Araskova Labs.","directories":{},"_nodeVersion":"24.19.0","_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/cerberus_0.1.0_1786528855680_0.39495852459876146","host":"s3://npm-registry-packages-npm-production"}},"0.1.1":{"name":"@araskova/cerberus","version":"0.1.1","keywords":["security","skills","skillbook","agent","llm","rust","terminal","appsec","cerberus","araskova"],"author":{"name":"Araskova Labs"},"license":"SEE LICENSE IN LICENSE","_id":"@araskova/cerberus@0.1.1","maintainers":[{"name":"anvinpshibu","email":"victor.von.doom.prime@gmail.com"}],"bin":{"cerberus":"bin/cerberus.js"},"dist":{"shasum":"5f02fb80012a05e259a2908e4e26efd2a7231e4c","tarball":"https://registry.npmjs.org/@araskova/cerberus/-/cerberus-0.1.1.tgz","fileCount":44,"integrity":"sha512-/CBT6vrGinjvHmfqdrZ35jPz3E1CW1xdWp6SAfgvPEyzh9OF5G8y+o7MbJonaZBLZnq5BrEXNx2alIXC19NoVw==","signatures":[{"sig":"MEUCIQC9Oe5e0iutAcHr3dF5uiiRf73h7ADycxhXxGOTS79S+wIgWh5eAS7zl6yTXQo6AxmZwy6KMHQQYe6RHPbOVK+spRA=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":184749},"type":"commonjs","engines":{"node":">=18.0.0"},"gitHead":"b08b4b58436296f065c196b062c34dc9399bfeee","private":false,"scripts":{"dev":"cargo run -p cerberus-cli -- skill list","build":"cargo build --release --workspace","check":"cargo check --workspace","doctor":"cargo run -p cerberus-cli -- doctor","postinstall":"cargo build --release || true","prepublishOnly":"cargo test --workspace && cargo build --release"},"_npmUser":{"name":"anvinpshibu","email":"victor.von.doom.prime@gmail.com"},"_npmVersion":"11.17.0","description":"Cerberus — Universal Security Skill Book & Specification Engine for AI Agents by Araskova Labs.","directories":{},"_nodeVersion":"24.19.0","_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/cerberus_0.1.1_1786529094213_0.7822888315926544","host":"s3://npm-registry-packages-npm-production"}},"0.2.0":{"name":"@araskova/cerberus","version":"0.2.0","description":"Cerberus — Universal Security Skill Book & Specification Engine for AI Agents by Araskova Labs.","author":{"name":"Araskova Labs"},"license":"SEE LICENSE IN LICENSE","private":false,"type":"commonjs","bin":{"cerberus":"bin/cerberus.js"},"scripts":{"build":"cargo build --release --workspace","check":"cargo check --workspace","dev":"cargo run -p cerberus-cli -- skill list","doctor":"cargo run -p cerberus-cli -- doctor","postinstall":"cargo build --release || true","prepublishOnly":"cargo test --workspace && cargo build --release"},"keywords":["security","skills","skillbook","agent","llm","rust","terminal","appsec","cerberus","araskova"],"engines":{"node":">=18.0.0"},"gitHead":"2f8ed71c0c17ce95ad2a77b4da63764d4e4e0354","_id":"@araskova/cerberus@0.2.0","_nodeVersion":"24.19.0","_npmVersion":"11.17.0","dist":{"integrity":"sha512-QbDJfknZhHYOxQJcYpUXiw9gWgR5/YzYdtfRxxjJYiuCiUefL33ASIKRjI47GHpvvg8kKqdHqTu0Qo0AdqghRQ==","shasum":"2bfe40c3e780ed0f6ba3069db3622457cea5aac9","tarball":"https://registry.npmjs.org/@araskova/cerberus/-/cerberus-0.2.0.tgz","fileCount":49,"unpackedSize":198648,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIQDgaNPEfzMiuPTwR4mpBSBYmEdtgy7bjC4QNv33gH747AIgXiUoWimzfF+88NUM59w2blCcCX77z4hPBAd0fe0Z+uk="}]},"_npmUser":{"name":"anvinpshibu","email":"victor.von.doom.prime@gmail.com"},"directories":{},"maintainers":[{"name":"anvinpshibu","email":"victor.von.doom.prime@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/cerberus_0.2.0_1786530291965_0.9477833127381787"},"_hasShrinkwrap":false}},"time":{"created":"2026-08-12T10:00:55.394Z","modified":"2026-08-12T10:24:52.334Z","0.1.0":"2026-08-12T10:00:55.851Z","0.1.1":"2026-08-12T10:04:54.365Z","0.2.0":"2026-08-12T10:24:52.151Z"},"author":{"name":"Araskova Labs"},"license":"SEE LICENSE IN LICENSE","keywords":["security","skills","skillbook","agent","llm","rust","terminal","appsec","cerberus","araskova"],"description":"Cerberus — Universal Security Skill Book & Specification Engine for AI Agents by Araskova Labs.","maintainers":[{"name":"anvinpshibu","email":"victor.von.doom.prime@gmail.com"}],"readme":"<div align=\"center\">\n\n# 🛡️ Cerberus — Universal Security Skill Book & AI Guardrail Engine\n\n[![NPM Version](https://img.shields.io/npm/v/@araskova/cerberus?style=for-the-badge&color=7C3AED&labelColor=0F172A)](https://www.npmjs.com/package/@araskova/cerberus)\n[![License](https://img.shields.io/badge/License-Araskova_Source_Available-06B6D4?style=for-the-badge&labelColor=0F172A)](https://www.araskova.com/products/cerberus)\n[![Product Page](https://img.shields.io/badge/Official_Product_Page-Araskova.com-10B981?style=for-the-badge&labelColor=0F172A)](https://www.araskova.com/products/cerberus)\n\n**Developed by Araskova Labs**  \n*The Autonomous AppSec Guardrail & Security Skill Specification Engine for AI Coding Agents and Enterprise DevSecOps.*\n\n[🌐 Official Product Page](https://www.araskova.com/products/cerberus) • [📚 Documentation](https://www.araskova.com/products/cerberus) • [📦 NPM Package](https://www.npmjs.com/package/@araskova/cerberus)\n\n---\n\n</div>\n\n## 👁️ Executive Overview\n\n**Cerberus** is an enterprise-grade security framework engineered by **Araskova Labs** to transform how AI Coding Assistants (Claude, Antigravity, Cursor, and custom LLM agents) interact with application security. \n\nInstead of relying on black-box security tools or unconstrained AI prompts, Cerberus introduces the **Universal Security Skill Book Specification**:\n\n```text\n┌─────────────────────────┐     ┌─────────────────────────┐     ┌─────────────────────────┐\n│  Query Skill Catalog    │ ──> │   Policy Guardrail Gate │ ──> │   Controlled Execution  │\n│  (14 Governed Skills)   │     │ (Strict Risk Level Evaluator) │  │  (Native Scanners + LLM)│\n└─────────────────────────┘     └─────────────────────────┘     └─────────────────────────┘\n                                             │\n                                             ▼\n                                ┌─────────────────────────┐\n                                │ Audit Evidence Logger   │\n                                │ (.cerberus/skill_audit) │\n                                └─────────────────────────┘\n```\n\n### Key Pillars & Enterprise Capabilities\n\n- **Universal Security Skill Book Specification**: Standardized JSON manifests (`skills/`) defining security actions across Reconnaissance, Code Auditing, Vulnerability Testing, Exploit Validation, Malware Hunting, and AI Remediation.\n- **Deterministic Policy Guardrail Gateways**: Every security action evaluates against strict policy risk levels (`Passive`, `ActiveSafe`, `Intrusive`, `ExploitValidation`, `Forbidden`) prior to execution, preventing destructive operations.\n- **Native Security Scanners**: Includes high-performance native Rust engines for OSV dependency vulnerability lookup, cloud infrastructure auditing (AWS/Terraform IAM & Security Groups), secret grep, prompt-injection detection, and heuristic malware/backdoor threat hunting.\n- **AI Auto-Remediation & Code Review**: Integrates directly with LLM providers (`cerberus-llm`) to generate Git patch files (`.patch`), rewrite overly permissive IAM policies to least-privilege, synthesize edge WAF rules, and provide interactive line-by-line AI security code reviews (`cerberus review --diff`).\n- **Native Model Context Protocol (MCP) Server**: Implements stdio MCP server support, allowing AI agents to query and execute Cerberus skills directly as native tools.\n- **Automated Penetration Test Reporting**: Compiles execution evidence logs into professional Markdown audit reports (`cerberus report generate`).\n\n---\n\n## ⚡ Quick Start & Installation\n\n### Option A: Global Installation via NPM (Recommended)\n\nInstall `@araskova/cerberus` globally from NPM:\n\n```bash\nnpm install -g @araskova/cerberus\n```\n\nOnce installed, use `cerberus` anywhere in your terminal:\n\n```bash\n# View the Cyberpunk Terminal Boot UI\ncerberus banner\n\n# List all 14 governed security skills\ncerberus skill list\n\n# Conduct an AI Security Review on unstaged git changes\ncerberus review --diff\n```\n\n### Option B: Local Project Installation\n\nAdd Cerberus as a dev dependency to your project:\n\n```bash\nnpm install --save-dev @araskova/cerberus\n```\n\nRun via `npx`:\n```bash\nnpx cerberus skill list\n```\n\n### Option C: Build from Source (Cargo)\n\nRequirements: **Rust 1.75+** and **Node.js 18+**.\n\n```bash\ngit clone https://github.com/ARASKOVA-labs/Cerberus.git\ncd Cerberus\ncargo install --path crates/cerberus-cli\n```\n\n---\n\n## 🛠️ Complete CLI Command Reference\n\n| Command | Description | Usage Example |\n| :--- | :--- | :--- |\n| `cerberus banner` | Displays the interactive cyberpunk terminal boot animation & status | `cerberus banner` |\n| `cerberus doctor` | Checks runtime health, loaded skill counts, and policy engines | `cerberus doctor` |\n| `cerberus skill list` | Lists all 14 available security skills with category and action IDs | `cerberus skill list` |\n| `cerberus skill show <id>` | Inspects the full JSON specification for a specific skill | `cerberus skill show secret-scanner` |\n| `cerberus skill run` | Governs and executes a specific skill action | `cerberus skill run --skill cloud-config-audit --action scan-configs --args .` |\n| `cerberus skill validate <path>`| Validates a custom skill JSON file schema | `cerberus skill validate custom-skill.json` |\n| `cerberus review` | Interactive AI Security Reviewer on file or unstaged `git diff` | `cerberus review --diff` |\n| `cerberus report generate` | Compiles `.cerberus/skill_audit.json` into `cerberus_report.md` | `cerberus report generate` |\n| `cerberus mcp` | Starts the Model Context Protocol stdio server for AI agents | `cerberus mcp` |\n| `cerberus export` | Exports the skill book catalog as JSON or Markdown | `cerberus export --format json` |\n\n---\n\n## 📚 Skill Book Catalog (14 Governed Skills)\n\nCerberus ships with 14 pre-loaded, governed security skills:\n\n- **Code Audit**: `secret-scanner` (API keys, RSA keys, JWT tokens)\n- **Reconnaissance**: `repo-architecture-map` (Tech stack, API route mapping)\n- **Vulnerability Testing**:\n  - `cloud-config-audit` (Terraform/AWS IAM wildcards & 0.0.0.0/0 ingress)\n  - `dependency-and-secret-audit` (Google OSV API CVE lookup for package.json & Cargo.lock)\n  - `jwt-audit` & `jwt-security-auditor` (`alg: none` bypasses & weak signatures)\n  - `llm-threat-scanner` (Prompt injection & jailbreak detection)\n  - `malware-threat-hunt` (Reverse shells, cryptominers, eval obfuscation)\n  - `network-infrastructure-pentest` (Port probing)\n  - `web-misconfig-review` (HTTP response security headers)\n- **Exploit Validation**: `sqli-verification` (SQL injection validation & parameterized queries)\n- **Remediation & Defense**:\n  - `auto-remediation` (AI Git `.patch` generation)\n  - `iam-policy-optimizer` (Least-privilege cloud IAM policy re-writing)\n  - `waf-rule-generator` (ModSecurity / AWS WAF rule generation)\n\n---\n\n## 🔗 Official Links & Resources\n\n- **Official Product Page**: [https://www.araskova.com/products/cerberus](https://www.araskova.com/products/cerberus)\n- **NPM Package**: [https://www.npmjs.com/package/@araskova/cerberus](https://www.npmjs.com/package/@araskova/cerberus)\n- **GitHub Repository**: [https://github.com/ARASKOVA-labs/Cerberus](https://github.com/ARASKOVA-labs/Cerberus)\n\n---\n\n## 🛡️ License\n\nAraskova Source Available & Open Contribution License. Proprietary & Confidential — **Araskova Labs**. All Rights Reserved.\n","readmeFilename":"README.md"}