See your cloud. Secure what matters.
Turn AWS configuration data into clear, actionable security intelligence.
Note
Plexavo is built around a simple idea: security tooling should tell you what is wrong, why it matters, and what to do next, without requiring a dedicated security team.
Plexavo is an open-source cloud security tool that audits AWS accounts
for real-world misconfigurations, using your own local AWS credentials
the same way aws s3 ls does, so nothing about your account ever
leaves your machine.
Each scan produces a 0β100 security score and a plain-English report: what's wrong, what an attacker would actually do with it, and the exact command to fix it.
Important
Detection is not AI. Plexavo's detections are pure Python/boto3; Claude only rewrites already-found findings for readability, and narration is fully optional. See Cost.
Tip
π€ New: talk to Plexavo through Claude Code. No CLI flags, just ask "scan my AWS account with Plexavo" in a Claude Code session and get a conversational security briefing. See Using it from Claude Code.
32 checks across 6 categories, run against real AWS accounts:
| Category | What Plexavo looks for |
|---|---|
| IAM | Privilege escalation paths, wildcard admin, cross-account trust, root usage, dormant credentials |
| Network | Security groups and RDS instances exposed to the internet |
| Storage | Public S3 buckets via ACLs, bucket policies, or missing Block Public Access; buckets with no access logging |
| Encryption | Unencrypted EBS volumes, RDS instances, S3 buckets |
| Logging | CloudTrail coverage and encryption, GuardDuty status |
| Usage | Permissions granted but never used, roles nobody has assumed in 90+ days |
See docs/*-TEST-MATRIX.md for how each check was verified.
Tip
Don't just trust the number. Plexavo keeps severity, confidence, and evidence as separate signals, so a low-confidence Critical does not read the same as a high-confidence Medium.
Every path below installs Plexavo into its own isolated environment.
curl -LsSf https://astral.sh/uv/install.sh | sh # skip if you have uv
uv tool install plexavoPrefer pipx? pipx install plexavo works the
same way.
uv/pipx still work, but the PATH launcher is unsigned and Windows
Smart App Control blocks it. Run Plexavo through Python instead:
Option 1, uv (recommended)
uv tool install plexavo
Set-ExecutionPolicy -Scope CurrentUser RemoteSigned
if (!(Test-Path $PROFILE)) { New-Item -ItemType File -Path $PROFILE -Force }
Add-Content $PROFILE 'function plexavo { & "$env:APPDATA\uv\tools\plexavo\Scripts\python.exe" -m plexavo @args }'Open a new terminal. plexavo now works like it does on macOS/Linux,
routed through uv's signed Python instead of the blocked launcher.
Option 2, plain venv
py -m venv plexavo-venv
.\plexavo-venv\Scripts\Activate.ps1
python -m pip install plexavo
python -m plexavoUse python -m for everything here too. The venv's own pip.exe and
plexavo.exe are unsigned as well, only python.exe is signed.
Want each finding rewritten as a full narrative? Install "plexavo[ai]"
instead of plexavo, and set ANTHROPIC_API_KEY. See Cost.
Run it with no arguments and it walks you through everything: picking an AWS profile, choosing HTML or PDF, then scanning and showing your score with every finding.
plexavo # macOS/Linux, and Windows Option 1
python -m plexavo # Windows Option 2Plexavo can also run unattended from cron or a GitHub Actions workflow,
and flag a run when something regresses so you get notified without
opening a report. See docs/automation.md.
Note
Think of a scan as a snapshot, not a finish line. Run it repeatedly to catch regressions as your infrastructure changes.
Using Claude Code? Install the
plexavo-scan plugin, then just ask: "scan my AWS account for security
issues using Plexavo." It relays exactly what Plexavo found, and never
runs a state-changing AWS command without asking first.
/plugin marketplace add plexavo/Plexavo
/plugin install plexavo-scan@plexavo
Prefer not to add a marketplace? Save
plexavo-scan/SKILL.md
to ~/.claude/skills/plexavo-scan/SKILL.md
(%USERPROFILE%\.claude\skills\plexavo-scan\SKILL.md on Windows) instead,
same skill, just without automatic updates.
Reports are generated as HTML, PDF, or both. Every finding gets a free,
template-based fix by default, no key, no cost. Full AI-written
narration kicks in automatically once an ANTHROPIC_API_KEY is
detected, see Cost.
Detection and the free templates always cost nothing. Live AI only runs
with --explain, using your own ANTHROPIC_API_KEY in your own
Anthropic account.
Plexavo never sees your key and never calls the API without it. A full
scan with --explain typically costs a few cents.
Important
No hidden AI bill. If you don't provide an Anthropic API key, Plexavo does not make an AI API call.
git clone https://github.com/plexavo/plexavo.git
cd plexavo
uv pip install -e .See CONTRIBUTING.md for the pattern used to add a
new check.
Think you can make Plexavo miss something, or give confusing guidance?
Every confirmed, genuinely new finding gets fixed and shipped, and you get a permanent credit in the Hall of Bugs.
No bounty. Public credit only.
Tip
The best security tool is one that gets challenged. If you find a blind spot, break it, report it, and help make the next scan better.
Found a vulnerability in the tool itself, not a misconfiguration in your own AWS account (that's the tool working correctly)?
See SECURITY.md for a private reporting path.
AGPL-3.0, see LICENSE.
Use, run, and modify it freely. If you run a modified version as a hosted service, you're required to publish those modifications too.
Plexavo Β· Open-source cloud security, built to be understood.
Scan. Understand. Fix. Repeat.


