Enternovate Open · Mhangani · v0.1.0
Ethical web security audit toolkit. Passive, black-box checks against OWASP-aligned expectations, scored 0-100, with reports your team and board can act on.
Most breaches start with a misconfiguration, not a sophisticated exploit: a missing HSTS header, a cookie without HttpOnly, a CORS policy that echoes any origin. Mhangani turns “is our site hardened?” into a repeatable, scored answer any team can run, before an attacker does. It checks HTTP security headers, TLS posture, cookies, CORS policy, and page content, and refuses to audit any host without a recorded authorization or an explicit scope file. It performs no exploitation, no payloads, no brute force, and no denial of service.
$ pip install git+https://github.com/enternovate/mhangani.git$ mhangani authorize https://example.com$ mhangani audit https://example.com --rate-delay 1 --respect-robots$ mhangani report --format md --out report.md$ mhangani baseline --set$ mhangani baseline --diff$ mhangani trend$ mhangani checklist
mhangani authorize <url> [--note N]Record authorization for a hostmhangani authorizations list|remove <url>Manage authorizationsmhangani audit <url> [--scope F] [--rate-delay S] [--respect-robots]Run the auditmhangani report [--format json|md|html|exec]Render the reportmhangani baseline [--set|--show|--clear|--diff]Manage the baselinemhangani trend [--limit N]Show the score trendmhangani checklist [--id ID] [--format md|json]Print the check cataloguemhangani history [--limit N]List previous auditsmhangani clearDelete stored auditsEvery variable is optional. The tool runs on defaults with no configuration.
MHANGANI_HOMENoData directory: audits, history, baseline, authorizations (default: ~/.mhangani)Xavani Agent drives Mhangani through the constellation MCP bundle (constellation-mcp), which exposes mhangani_* tools, and through the mhangani-audit skill. Ask Xavani to “audit our website” and the CLI runs locally with the authorization gate; findings can be exported to the Nyarhi knowledge graph for tracking.
Xavani Agent docsEvery audit requires a recorded authorization or an explicit scope file. Unauthorized targets are refused.
No exploitation, no payloads, no brute force, no denial of service. It only reads what a target serves to any visitor.
--rate-delay spaces requests and --respect-robots refuses paths that robots.txt disallows.
Audits, history, baselines and authorizations live in ~/.mhangani on your machine.