The internet is being vibe coded

Argus — see what your app can reach

Everyonecan shipnow.

prompt

make an ordering site for my taco truck. warm, simple, pickup orders.

lakeviewtacos.example
MenuMy ordersSign in

Tacos, fast.

Order for pickup →
“Best al pastor in town. Ordered twice this week.”
Live · 41 orders today

Untested:
has anyone tried to break it?

Security didn’t get the memo.

AI made building software possible for millions of people. Argus shows what each part of your app can reach, learns what you meant to allow, and catches the moment reality changes. Then it proves it, fixes it, and checks that the fix holds.

The story of a $100 website

01The $100 website

The $100 website

  1. He needed a website, not a security department.
  2. It looked finished.
  3. It shipped.
  4. No one had tried to break it.
  5. So Argus tries first.

Lakeview Tacos, Ann Arbor. A University of Michigan student built the ordering site for $100. Both of them did something reasonable.

Invoice№ 0001

Lakeview Tacos — ordering website

Design + build
$100.00
Hosting
free tier
Security review
—

Total$100.00

Paid — thank you! M., UMich ’27

lakeviewtacos.example
MenuMy ordersSign in

Tacos, fast.

Order for pickup →
“Best al pastor in town. Ordered twice this week.”
Live
Skip the walkthrough

02How Argus works

Find.Prove.Fix.Verify.

Watch Argus work on Lakeview Tacos from start to finish. Every screen below is the product doing its job, on sample data.

01 Find

Five specialists. One sandbox. All at once.

You give Argus your app’s URL and, if you like, its GitHub repo. It opens isolated browser sessions and sends five specialist agents at your app in parallel, each looking for a different way things go wrong.

  • Authorized targets only
  • Runs in an isolated sandbox
sandbox · sbx_7f3a · isolated
lakeviewtacos.example
MenuMy ordersSign in

Tacos, fast.

Order for pickup →
“Best al pastor in town. Ordered twice this week.”
Authorized target
  1. 01Injection agentCan form input reach the database?Queued
  2. 02XSS / Browser agentCan visitor text run as code?Queued
  3. 03Auth / Access agentCan one customer see another’s data?Queued
  4. 04Request / API agentDoes the API trust bad requests?Queued
  5. 05Config / Exposure agentIs anything left exposed?Queued
  1. verify target lakeviewtacos.example · owner confirmed
  2. spawn 5 isolated browser sessions
  3. map 23 routes · 38 inputs · 9 endpoints
  4. auth reproduction succeeded · capturing replay
  5. done 1 finding · 1 note · 3 pass

02 Prove

A finding without proof is just another alert.

The Auth agent didn’t just flag a risk. It reproduced the problem in the sandbox with a test account and saved the replay, so you can watch what happened instead of trusting a red badge.

lakeviewtacos.example/signin Replay

Finding · INC-0042 · replay bb_session_29c1

High Broken access control

Affected route

GET /api/orders/:id

→ 200 OK expected 404

{ "id": 1042,
  "customer": "Customer B",
  "address": "12•• ▇▇▇▇" }

In plain English

Any signed-in customer could open another customer’s order, including their name and address.

03 Fix

From evidence to a fix you can review.

With your repo connected, Argus traces the replay to the line responsible and proposes a pull request with a regression test. Nothing merges until you approve it.

  • Repo access you grant
  • Proposes PRs. You approve.
server/routes/orders.tsline 3 returns any order
  1. 1export async function getOrder(req, res) {
  2. 2 const order = await db.orders.find(req.params.id);
  3. + if (!order || order.customerId !== req.user.id) {
  4. + return res.status(404).end();
  5. + }
  6. 3 return res.json(order);
  7. 4}
Open

Enforce order ownership on GET /api/orders/:id

#12 · argus-agent wants to merge 1 commit into main

  • Regression test added: fails before, passes after
  • Existing tests pass in the sandbox
  • Waiting for your review
You stay the merge button.

04 Verify

Detection without proof is noise. A patch without verification is hope.

Argus replays the original test against the patched sandbox, then replays a normal customer doing the normal thing. Both have to pass before anything is called fixed.

Requirement 1 · replay the finding

Customer A → GET /api/orders/1042

Queued

Attack blocked

Requirement 2 · the real customer path

Customer A → GET /api/orders/1041

Queued

Legitimate flow passes

Verification pending

  1. Found
  2. Proven
  3. Fixed
  4. Verified

05 Keep watching

Then it keeps watching.

Every deploy re-tests what changed. Every fixed issue gets re-checked so it stays fixed. And you don’t have to live in a dashboard to know.

lakeviewtacos.exampleWatching

  • Today 2:14 pmINC-0042 · broken access controlVerified · closed
  • Today 2:15 pmConfig note · 2 missing headersFix suggested
  • Next deployRe-test what changedScheduled
  • Sunday 9:00Weekly summary via RelayScheduled

03Five agents, one mission

Five specialists.Each one looks somewhere different.

Hover, tap or arrow through them to see where each agent looks on Lakeview Tacos.

lakeviewtacos.example · inspected
MenuMy ordersSign inAuth agent: sign-in, sessions, “My orders”

Tacos, fast.

Order for pickup →
“Best al pastor in town. Ordered twice this week.”
NetworkGET /api/orders/1041 200POST /api/checkout 201
Headerscontent-security-policy —x-powered-by express

Checks whether one signed-in customer can see or change things that belong to someone else, and whether sessions behave.

Technically
Session handling · broken access control · IDOR
On Lakeview Tacos
Reproduced: a test customer could open another customer’s order.

04Scout · Argus on your desktop

Security leavesthe dashboard.

Scout lives in your pointer. Summon it, ask it something out loud, and give it exactly as much control as you want. You can always see what it’s doing, and stop it instantly.

05Relay · Argus in your pocket

The owner isn’t at a desk.

Lunch rush doesn’t stop for a security dashboard. Through Relay, a messenger built for agents, the owner talks to their Argus agent the way they’d text a friend: ask for status, trigger a re-check after a deploy, approve a fix between orders.

  1. Sun 9:00Weekly summary arrives
  2. Mon 9:58Owner checks in between prep
  3. 10:42New checkout goes live
  4. 10:44“Check it again”
  5. 11:05Evidence + proposed fix
  6. 11:31Approved from the truck
Argus · Lakeview Tacos agent online · via Relay
  1. Sun 9:00Argus: Weekly summary3 checks run · 0 open findings. Last week’s order-privacy fix is still verified.

Security shouldn’t require becoming a security professional.

06For builders

Built for the peopleshipping now.

  1. a.The next company might start at a hackathon.
  2. b.The next storefront might be built from a prompt.
  3. c.Security should be there before either can afford a security team.

07Live coordination

One shared state.Everyone sees it change.

Argus’s agents and people don’t pass messages and hope. They read and write one live state: incidents, who owns which task, evidence, approvals, verification. It’s built on SpacetimeDB.

  • Injection
  • XSS
  • Auth
  • API
  • Config
  • Owner
  • Dev
  • 7 clients · subscribed

Owner · phone

INC-0042

Order privacy · access control

Investigating

  • T-17 owned by auth-agent
  • Evidence replay · 0:08
  • Fix PR #12
  • Approval owner

SpacetimeDB · argus module

  1. → claim_task(T-17)

    identity: auth-agent

    ✓ committed · 7 subscribers updated

  2. → claim_task(T-17)

    identity: api-agent

    ✕ rejected · already claimed by auth-agent

  3. → attach_evidence(INC-0042, replay)

    identity: auth-agent

    ✓ committed · evidence row inserted

  4. → propose_fix(INC-0042, pr 12)

    identity: argus-agent

    ✓ committed

  5. → approve_fix(INC-0042)

    identity: owner (via Relay)

    ✓ committed

  6. → record_verification(INC-0042, passed)

    identity: verify-agent

    ✓ committed · incident verified

Developer · dashboard

INC-0042

Order privacy · access control

Investigating

  • T-17 owned by auth-agent
  • Evidence replay · 0:08
  • Fix PR #12
  • Approval owner

Illustrative sequence. Names simplified.

01

Reducers are transactions.

claim_task runs inside the database, atomically. Two agents can’t own the same task: one commits, the other is told why.

02

Clients subscribe.

The phone, the dashboard and every agent subscribe to the rows they care about. When a transaction commits, all of them update.

03

Every call has an identity.

Reducers know who is calling, human or agent, so authorization lives right next to the data it protects.

Rust module · simplified
#[spacetimedb::reducer]
fn claim_task(ctx: &ReducerContext, id: u64) -> Result<(), String> {
    let mut task = ctx.db.task().id().find(id)
        .ok_or("no such task")?;
    if task.owner.is_some() {
        return Err("already claimed".into());
    }
    task.owner = Some(ctx.sender);
    ctx.db.task().id().update(task);
    Ok(())
}

08Under the hood

Every integrationcarries a step of the story.

  1. 01

    Browserbase

    Isolated browsers for every agent

    Each agent tests in its own cloud browser session, away from your machine and your customers. Successful reproductions are saved as session replays: the evidence you watched in Prove.

    • Find
    • Prove
    • Verify
  2. 02

    SpacetimeDB

    The live state everyone shares

    Incidents, task claims, evidence and approvals live in one database with transactional server-side reducers. Agents, the dashboard and Relay subscribe and update together.

    • Find
    • Fix
    • Verify
    • Relay
  3. 03

    Relay

    Your agent, in your messages

    The owner talks to their Argus agent from their phone: status checks, re-tests after a deploy, weekly summaries and approvals, without opening a dashboard.

    • Keep watching
    • Relay
  4. 04

    GitHub

    Where fixes become reviewable

    With repo access you grant, Argus traces evidence to code and proposes pull requests with regression tests. Merging stays with you.

    • Fix
    • Verify

You learned to ship with AI.Now ship like someone’s trying to break it.

  • Authorized targets only
  • Isolated sandbox
  • Nothing merges without you