
Argus is an offensive security tool: its Phase-2 agents actively attack a target. That power comes with responsibility.
Only run Argus against systems you own or are explicitly authorized to test. Attacking systems without permission is illegal in most jurisdictions. You are solely responsible for how you use this tool.
Argus is built for:
argus demo ships a bundled, self-contained vulnerable app so you can see
the full attack flow without touching anything you don't own.
--url). Target-controlled external links, form actions, API specs, and redirects are not followed out of scope.--url for an already-running, separately isolated target.If you find a security issue in Argus itself, please do not open a public issue. Instead, report it privately via GitHub Security Advisories on the repository. We aim to acknowledge reports within a few days.
The full, canonical version of this policy lives in SECURITY.md on GitHub — this page mirrors it.