Skip to content

Repository files navigation

Plexavo

GitHub stars License PyPI version Build status

See your cloud. Secure what matters.

Turn AWS configuration data into clear, actionable security intelligence.


Plexavo interactive scan demo

Note

Plexavo is built around a simple idea: security tooling should tell you what is wrong, why it matters, and what to do next, without requiring a dedicated security team.

Plexavo is an open-source cloud security tool that audits AWS accounts for real-world misconfigurations, using your own local AWS credentials the same way aws s3 ls does, so nothing about your account ever leaves your machine.

Each scan produces a 0–100 security score and a plain-English report: what's wrong, what an attacker would actually do with it, and the exact command to fix it.

Important

Detection is not AI. Plexavo's detections are pure Python/boto3; Claude only rewrites already-found findings for readability, and narration is fully optional. See Cost.

Tip

πŸ€– New: talk to Plexavo through Claude Code. No CLI flags, just ask "scan my AWS account with Plexavo" in a Claude Code session and get a conversational security briefing. See Using it from Claude Code.

✦ What it checks

32 checks across 6 categories, run against real AWS accounts:

Category What Plexavo looks for
IAM Privilege escalation paths, wildcard admin, cross-account trust, root usage, dormant credentials
Network Security groups and RDS instances exposed to the internet
Storage Public S3 buckets via ACLs, bucket policies, or missing Block Public Access; buckets with no access logging
Encryption Unencrypted EBS volumes, RDS instances, S3 buckets
Logging CloudTrail coverage and encryption, GuardDuty status
Usage Permissions granted but never used, roles nobody has assumed in 90+ days

See docs/*-TEST-MATRIX.md for how each check was verified.

Tip

Don't just trust the number. Plexavo keeps severity, confidence, and evidence as separate signals, so a low-confidence Critical does not read the same as a high-confidence Medium.

⚑ Installation

Every path below installs Plexavo into its own isolated environment.

macOS & Linux

curl -LsSf https://astral.sh/uv/install.sh | sh   # skip if you have uv
uv tool install plexavo

Prefer pipx? pipx install plexavo works the same way.

Windows

uv/pipx still work, but the PATH launcher is unsigned and Windows Smart App Control blocks it. Run Plexavo through Python instead:

Option 1, uv (recommended)

uv tool install plexavo
Set-ExecutionPolicy -Scope CurrentUser RemoteSigned
if (!(Test-Path $PROFILE)) { New-Item -ItemType File -Path $PROFILE -Force }
Add-Content $PROFILE 'function plexavo { & "$env:APPDATA\uv\tools\plexavo\Scripts\python.exe" -m plexavo @args }'

Open a new terminal. plexavo now works like it does on macOS/Linux, routed through uv's signed Python instead of the blocked launcher.

Option 2, plain venv

py -m venv plexavo-venv
.\plexavo-venv\Scripts\Activate.ps1
python -m pip install plexavo
python -m plexavo

Use python -m for everything here too. The venv's own pip.exe and plexavo.exe are unsigned as well, only python.exe is signed.

AI narration (optional)

Want each finding rewritten as a full narrative? Install "plexavo[ai]" instead of plexavo, and set ANTHROPIC_API_KEY. See Cost.

πŸš€ Using Plexavo

Run it with no arguments and it walks you through everything: picking an AWS profile, choosing HTML or PDF, then scanning and showing your score with every finding.

plexavo             # macOS/Linux, and Windows Option 1
python -m plexavo   # Windows Option 2
Plexavo interactive CLI

Running it on a schedule

Plexavo can also run unattended from cron or a GitHub Actions workflow, and flag a run when something regresses so you get notified without opening a report. See docs/automation.md.

Note

Think of a scan as a snapshot, not a finish line. Run it repeatedly to catch regressions as your infrastructure changes.

πŸ€– Using it from Claude Code

Using Claude Code? Install the plexavo-scan plugin, then just ask: "scan my AWS account for security issues using Plexavo." It relays exactly what Plexavo found, and never runs a state-changing AWS command without asking first.

/plugin marketplace add plexavo/Plexavo
/plugin install plexavo-scan@plexavo

Prefer not to add a marketplace? Save plexavo-scan/SKILL.md to ~/.claude/skills/plexavo-scan/SKILL.md (%USERPROFILE%\.claude\skills\plexavo-scan\SKILL.md on Windows) instead, same skill, just without automatic updates.

πŸ“Š The report

Reports are generated as HTML, PDF, or both. Every finding gets a free, template-based fix by default, no key, no cost. Full AI-written narration kicks in automatically once an ANTHROPIC_API_KEY is detected, see Cost.

Plexavo HTML report

πŸ’° Cost

Detection and the free templates always cost nothing. Live AI only runs with --explain, using your own ANTHROPIC_API_KEY in your own Anthropic account.

Plexavo never sees your key and never calls the API without it. A full scan with --explain typically costs a few cents.

Important

No hidden AI bill. If you don't provide an Anthropic API key, Plexavo does not make an AI API call.

🀝 Contributing

git clone https://github.com/plexavo/plexavo.git
cd plexavo
uv pip install -e .

See CONTRIBUTING.md for the pattern used to add a new check.

🧨 Break Plexavo

Think you can make Plexavo miss something, or give confusing guidance?

Report it β†’

Every confirmed, genuinely new finding gets fixed and shipped, and you get a permanent credit in the Hall of Bugs.

No bounty. Public credit only.

Tip

The best security tool is one that gets challenged. If you find a blind spot, break it, report it, and help make the next scan better.

πŸ” Security

Found a vulnerability in the tool itself, not a misconfiguration in your own AWS account (that's the tool working correctly)?

See SECURITY.md for a private reporting path.

πŸ“„ License

AGPL-3.0, see LICENSE.

Use, run, and modify it freely. If you run a modified version as a hosted service, you're required to publish those modifications too.


Plexavo Β· Open-source cloud security, built to be understood.

Scan. Understand. Fix. Repeat.

About

AWS Cloud Security Posture & Misconfiguration Assessment Engine

Topics

Resources

Contributing

Security policy

Stars

4 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages