{"slug": "jev-for-vulnerability-and-attack-surface-analysis", "title": "Jev for Vulnerability and Attack Surface Analysis", "summary": "A new open-source tool called jev maps the attack surface of Python, JavaScript and TypeScript codebases and flags likely vulnerabilities down to the exact line for about one cent per repository, using a classifier that answers fixed questions with probabilities in under a second at roughly $42 per billion input tokens. Tested only against two deliberately vulnerable apps on 2026-10-02, jev scanned PyGoat (Python/Django) for $0.010 and NodeGoat (JavaScript/Express) for $0.007, surfacing issues including SQL injection, eval, pickle.loads, SSRF, open redirect and NoSQL $where injection. The tool requires a TypeSafe API key, caps each run at $0.05, and hands its ranked issue list to an AI agent with instructions to validate rather than fix each finding.", "body_md": "Maps the attack surface of a backend codebase and flags likely vulnerabilities, down to the suspicious line, for about one cent per repo.\n\n**Try it without installing anything:** [https://franciscocarloserra.github.io/jev-attack-surface-analysis/](https://franciscocarloserra.github.io/jev-attack-surface-analysis/)\n(read-only results on PyGoat and NodeGoat).\n\nYou give it a repo (Python, JavaScript or TypeScript) and a budget in dollars. You get:\n\n- a **map** of the codebase, one block per file, colored by how suspicious it is;\n- a **ranked list of potential vulnerabilities** , each pointing to the exact line\n(e.g. user input reaching SQL,`eval` , a shell or an outbound request);\n- a **copy button** (or`print_issues.py` ) that hands that list to an AI agent, with the\ninstruction to*validate* each issue, not to fix it.\n\nNo LLM is involved. Plain Python reads the code; **jev**, a classifier that answers fixed\nquestions with probabilities in under a second and at about $42 per billion input tokens,\ndoes all the judging.\n\nLike a magnifying glass: it looks at the whole repo coarsely, then zooms into the suspicious parts only. At each level jev rates every item, and only the hot ones are opened at the next level.\n\n```\nrepo\n │\n ▼  1. directories   jev reads names only            → drops tests, docs, migrations\n │\n ▼  2. files         jev reads imports + signatures  → exposure: none / low / medium / high\n │\n ▼  3. functions     jev reads the code              → does external input reach a dangerous operation?\n │\n ▼  4. lines         jev picks one of the function's lines → where the vulnerability happens\n │\n ▼\nranked issues ──► viewer / copy ──► your agent validates them\n```\n\n- **Heat** (0 to 1): how suspicious an item is, computed from jev's probabilities.\n- **Budget** : each level gets a share; what one level does not spend passes to the next.\nThe hottest items go first, so if money runs out, what is left out is the least suspicious.\n\nTested only against two apps that are vulnerable on purpose (measured 2026-10-02):\n\n| Repo | Language | Cost | Top issues found | \n|---|---|---|---|\n| [PyGoat](https://github.com/adeyosemanputra/pygoat) | Python / Django | $0.010 | SQL injection, `eval` ,`pickle.loads` , SSRF | \n| [NodeGoat](https://github.com/OWASP/NodeGoat) | JavaScript / Express | $0.007 | `eval` on request body, open redirect, SSRF, NoSQL`$where` injection | \n\nYou need a TypeSafe API key for jev.\n\n```\npython3 -m venv .venv && .venv/bin/pip install -r requirements.txt\nexport TYPESAFE_API_KEY=...\ngit clone --depth 1 https://github.com/adeyosemanputra/pygoat repos/pygoat\n\npython3 viewer_server.py        # open http://localhost:7801/heatmap_viewer.html\n```\n\nIn the viewer pick the repo, set a budget (max $0.05 per run) and press **Run analysis**.\nFrom the shell instead:\n\n```\n.venv/bin/python attack_surface_scan.py repos/pygoat --budget 0.03\npython3 print_issues.py examples/pygoat/scan_result.json --top 10\n```\n\nEvery run is saved in `examples/<repo>/runs/<run id>.json` (with date, scanner version and\nsettings hash) and the latest one in `examples/<repo>/scan_result.json`.\nAgents: see `AGENTS.md` for the commands and the result format.\n\n| File | What it is | \n|---|---|\n| `attack_surface_scan.py` | the scanner | \n| `classification_levels.json` | every setting: questions to jev, categories, thresholds, budget shares, languages | \n| `heatmap_viewer.html` +`viewer_server.py` | the viewer, and the small server that lets it start runs | \n| `print_issues.py` | issue list as text, for agents | \n| `examples/` | saved runs | \n\n- **Ask different questions** or change thresholds: edit`classification_levels.json` .\n- **Add a language** : add an entry to`languages` in the same file (file extensions and\nthe parser's names for imports, functions and classes).\n- **Add a level** (e.g. HTTP routes): write one`extract_<unit>` function in`attack_surface_scan.py` , register it in`UNIT_EXTRACTORS` and add the level to the JSON.\n\n- It ranks candidates for review; it does not prove a vulnerability exists.\n- Each function is judged on its own, so a flaw spread across several functions can be missed.", "url": "https://wpnews.pro/news/jev-for-vulnerability-and-attack-surface-analysis", "canonical_source": "https://github.com/franciscocarloserra/jev-attack-surface-analysis", "published_at": "2026-10-02 11:20:16+00:00", "updated_at": "2026-10-02 11:36:30.403485+00:00", "lang": "en", "topics": ["ai-agents", "ai-tools", "developer-tools", "ai-safety"], "entities": ["jev", "PyGoat", "NodeGoat", "OWASP", "TypeSafe", "Python", "JavaScript", "Django"], "also_reported_by": [], "alternates": {"html": "https://wpnews.pro/news/jev-for-vulnerability-and-attack-surface-analysis", "markdown": "https://wpnews.pro/news/jev-for-vulnerability-and-attack-surface-analysis.md", "text": "https://wpnews.pro/news/jev-for-vulnerability-and-attack-surface-analysis.txt", "jsonld": "https://wpnews.pro/news/jev-for-vulnerability-and-attack-surface-analysis.jsonld"}}