The full upstream README, mirrored here for reference. Install config, tool schemas, adoption signals, and an original overview live on the Emfirge listing page.
Give your AI a read-only map of AWS. Trace attack paths, test a security fix on a cloned graph, and see the result before touching production.
Most cloud tools hand you a list and ask you to trust the recommendation. Emfirge builds a connected graph of your account, forks it in memory, applies the proposed security change, re-runs the rules, and shows what got safer—or riskier.
| 🕸️ See the path | 🎯 Find the chokepoint | 🧪 Rehearse the fix | 💬 Stay in your AI |
|---|---|---|---|
| Internet → compute → IAM → data | Prioritize what breaks the most attack paths | No write access. No production mutation. | Claude, Cursor, Kiro, Cline, Continue, Codex |
~20 AWS service types · 58 graph-aware rules · 17 rule families · 7 MCP tools
Then ask your assistant:
No role yet? Say “help me set up Emfirge.” You will get a one-click CloudFormation link for a read-only IAM role.
Try it now with no setup: use demo role
arn:aws:iam::194722410583:role/EmfirgeReadOnlyinus-east-1.
Free: 5 scans per AWS account per day. No signup. No API key.
| Tool | Answer |
|---|---|
emfirge_scan | What does my AWS risk look like? |
emfirge_get_findings | What is wrong and how do I fix it? |
emfirge_attack_paths | How could an attacker reach my data? |
emfirge_verify_fix | What changes if I apply this security fix? |
emfirge_simulate_breach | What happens after this resource is compromised? |
emfirge_check_compliance | Which CIS AWS 1.5 or SOC 2 controls fail? |
emfirge_setup_help | How do I create the read-only role? |
The score, findings, attack paths, and fix verification come from deterministic graph analysis—not an LLM guessing what might happen. Your AI explains the evidence; Emfirge produces it.
Emfirge proves the simulated security delta against your latest scan; it does not yet prove application connectivity. Some graph-derived labels may also remain visible in strict mode. See How it works and Privacy for the exact boundaries.
Quickstart · How the fork works · MCP tools · Privacy · Security · Self-hosting · Contributing
Fork the graph. Follow the path. Prove the security delta.