The full upstream README, mirrored here for reference. Install config, tool schemas, adoption signals, and an original overview live on the Voyager Net listing page.
Voyager's network organ — a safe, read-only, authorized audit of one host or domain you own, so an AI agent can find the falle in your infra and describe the fix.
Voyager penetrates the web (@dir-ai/voyager), the repo
(@dir-ai/voyager-repo), and — here — networks. This is the sense: it finds
problems. Applying fixes ("the hands") is a separate, consent-gated organ, by
design — an AI must never mutate live infrastructure on its own.
ipaddr.js) and any non-public address — loopback, private,
link-local, CGNAT, NAT64, IPv4-mapped IPv6, metadata — is refused.+all (anyone may send) and DMARC p=none (no enforcement) are findings,
not just presence checks. All target-controlled records are injection-framed.connect() with real
states (open / closed / filtered / unreachable — an OS timeout reads as
filtered, not closed), no SYN tricks, no payloads, no range/CIDR sweeps.PING) and reports the service as exposed
only if it answers without asking for credentials. Honest scope: this and the
TLS/HTTP inspectors DO send bytes (a ClientHello, a GET /, a protocol hello) —
the audit is active-but-safe (no writes, no mutation, no exploit), not purely
passive, and it runs only against the host you authorized.max-age, unsafe-inline/wildcard — not just presence), clickjacking
protection, per-cookie Secure/HttpOnly (each cookie evaluated on its own),
CORS wildcard and the dangerous credentials-with-origin case, version-leak,
and HTTP→HTTPS redirect. All pinned to the vetted IP.Findings that name a detected service+version suggest checking it against a CVE feed — voyager-net detects the version; CVE matching stays a lookup, and CVE probing (Nuclei &c.) is out of scope — that is active testing, a separate, more-gated capability, not a read-only sense.
Each finding carries a severity, confidence, and a described fix — e.g.
"certificate expires in 6d → renew and automate ACME", "mysql reachable publicly →
restrict to a private network", "no DMARC → publish v=DMARC1; p=quarantine".
--authorized (CLI) / authorized:true
(MCP) it refuses. You assert you own / may test the target.0 clean · 1 high/critical finding(s) · 2 tool error / not authorized.Scanning infrastructure you do not own or have explicit permission to test may be illegal in your jurisdiction. This tool is for auditing your own systems.
Tool: scan_host — same audit, fail-closed (authorized defaults off).
Wrap Prowler/Steampipe (cloud config), Trivy (CVE), Hubble (flow) under the same trust contract; attack-path correlation; drift (IaC declared ↔ actual). Then — separately and consent-gated — the remediation "hands".
MIT