— Open-Source AI Security Agents

Hunt Every Exposure.Keep a Human Holding the Leash.

The Hounds is an open-source pack of AI security agents that runs on your Tenable data. They find the unknown, prioritize by real exposure, and propose every change for your approval — grounded in real queries, never guesses.

41
In the pack
353K+
Downloads of navi-pro on PyPI
2M+
Assets in largest tested accounts
17
Claude skills driving automation

Built by the author of navi — 353K+ installs. Independent and open-source.

Built on Tenable. Grounded in your data. Reproducible by design. Most AI agents guess. The Hounds don't — every answer and action is a real, reproducible tool call against your data. Ask the same question twice, get the same answer. No hallucinated finding, no fabricated asset.

Listed on the Tenable CyberAgents Exchange

Verified open-source agent pack for Tenable Exposure Management

View listing →

— The Atlas Ownership Map

See the surface. Shrink the work.

Two views. One goal: turn tens of thousands of findings into a handful of owned paths.

Ownership graph threads view — routes and paths threaded to team owners

Who owns what — at a glance.

Every route and path threaded to its owner, with the gaps called out: unowned, under-owned, and ownerless risk. From the Atlas Ownership Map.

Ownership Sankey diagram — surface flowing to owners, unassigned risk highlighted

Follow the risk to a human.

Routes and paths flow to the owners on the hook for them — and the ownerless risk stands out immediately. Nothing gets fixed until someone owns it.

— The Pack

The Hounds pack crest

41 agents. One pack.

KEV, attack paths, identity, certificates, post-quantum crypto, AI, IoT, software, ownership, remediation — and the orchestrator that ties them together.

See all 41 →

— Why Trust the Hounds

Built for security teams who need answers, not estimates.

Agents propose. You approve.

Every tag and score change is gated behind human confirmation. Nothing runs autonomously until you arm it.

Real queries, not estimates.

Every answer comes from a real query against your local data — or the hounds tell you they can't answer.

Honest about blind spots.

Uncredentialed hosts and stale data get called out, not hidden.

— The Problem

Beat vulnerability fatigue: the mountain becomes a short, owned list.

Teams don't burn out because they can't find vulnerabilities — they burn out because there are too many, with no way to separate signal from noise.

CVE reduction funnel: 413 CVE line-items → 365 findings → 53 unique fixes → 6 owned apps

Real output from a reference run: 413 CVE line-items 53 unique fixes 6 owned apps. 98.5% fewer things to track — and one Chrome patch cleared 90 CVEs in a single action.

🎯

Rank, don't dump

Correlated risk floats the critical few to the top, so the long tail stops screaming for equal attention.

🧭

Your slice only

Ownership means each person sees just their assets — a handful to act on, not the whole estate's mountain.

🧹

Kill the noise

Duplicate and ephemeral assets get cleaned up, so you stop re-triaging the same ghost host ten times over.

— The Closed Loop

From a scan result to a verified fix — and back.

Most tools stop at step 2. The Hounds run the whole loop — discover, prioritize, assign, deliver, remediate, verify, report — and every step keeps a human in control.

01
🔍
Discover
Find exposures across the estate
02
🎯
Prioritize
Rank by real, correlated risk
03
🧭
Assign
Route each finding to its owner
Atlas
04
📧
Deliver
Email the owner their tasks + links
Gabriel
05
🔧
Remediate
Track every fix to verified closure
Amarok
06
Verify
Confirm the tag / fix landed
07
📈
Report
Trend it; is exposure shrinking?

Every step is gated — nothing tags, emails, or changes anything in your tenant until you approve it.

— You Hold the Leash

One pack, three levels of autonomy.

Turn the dial from fully governed to fully autonomous — the same grounded, non-destructive guarantees run across all three.

🔒

Governed

the engine (repo)

Self-hosted repo. The navi CLI runs deterministic agents — every write is proposed and confirmed. Maximum control, data local, near-zero tokens.

🤝

Assisted

skills + MCP (artifact)

Claude drives inside a structured console over the MCPs — conversational, but guided by 17 skills. Great for exploration and triage.

🚀

Autonomous

navi-mcp + the harness

Prompt an outcome and Claude plans and acts across the whole pack over the navi MCP — grounded by the Hounds harness. One prompt, whole estate.

— The Payoff

Less noise. Faster fixes. Real accountability.

One page

The whole estate's exposure, ranked — the morning read that replaces fifteen tool logins.

Every finding

gets an owner and a route to a human, so nothing rots unassigned.

Right inbox

Each team gets only their tasks, with the fix one click away in Tenable.

Provable

Gated, logged, and verified — you can show what changed and whether it stuck.

— Open Source

Free. Open. Yours to run.

Install the navi CLI and start hunting exposures in your own environment today.

$pip install navi-pro

— Why not just use native agentic AI?

Open-source, not a black box.

Every query, every prompt, every decision is in the repo. Read it, fork it, audit it.

Your vulnerability data stays local.

The pack runs against your local navi database. Nothing is sent to a third-party cloud.

Grounded and gated — it tells you when it can't answer.

Queries are forced against real data. If the answer isn't there, the hound says so.