Start with one repository.
Use one finding class, follow the visual guide and AI agent setup guides for the tool you already trust, keep existing tests, and require review for every change.
OPEN SECURITY INTELLIGENCE • HUMAN + AGENT READY
Research 268K+ CVEs and 177 reviewed workflows in a fast human interface—or give AI agents the same bounded context through MCP.
Shared intelligence, deliberate action
Provenance and trust
security-recipes.ai is an open, self-hostable layer between security findings and governed action. It connects source-backed research to bounded workflows without becoming a scanner, ticketing system, deployment platform, or unrestricted mutation surface.
Recipes map one finding to a defined change boundary, permitted outputs, and explicit stop conditions.
02Agents can gather narrowly scoped evidence without inheriting broad human authority.
03Tests, evidence, rollback notes, and residual risk make every recommendation reviewable.
04The operator reviews the evidence, approves the change, or redirects the work to the right owner.
Adoption paths
Begin with a small, reviewable loop. Expand access only when the workflow produces consistent evidence and named owners can support it.
Use one finding class, follow the visual guide and AI agent setup guides for the tool you already trust, keep existing tests, and require review for every change.
Add scoped identities, an MCP gateway, named reviewers, audit evidence, and measurable promotion gates.
Define the review model and expand only when bounded workflows behave predictably.
Open the blueprint →Read-first delivery
Existing security systems produce findings. security-recipes.ai helps humans and agents understand them, select bounded workflows, gather the right context, and return evidence without replacing the systems teams already trust.
Scanner, advisory, repository, ticket, SIEM, or cloud-security evidence.
Reviewed recipes, CVE contracts, playbooks, proof, rollback, and stop conditions.
A reviewer-ready patch, evidence report, or triage note in the team’s own workflow.
Open, inspectable, self-hostable
Use the quick start for a bounded first workflow, or inspect the source, catalogs, and MCP implementation on GitHub.