AI product Open source

cynative

Cynative is an open-source framework and CLI for building security agents with live, read-only access to code, cloud, and runtime infrastructure. It reasons across GitHub, GitLab, AWS, GCP, Azure, and Kubernetes as one system, using frontier models to investigate questions such as exposed resources, privilege escalation paths, infrastructure drift, and leaked credentials.

View repository Visit site Mentioned in 1 video ↓

Overview

For each investigation, Cynative generates and runs code in an ephemeral sandbox, queries APIs in parallel, cross-checks findings against live evidence, and traces findings to their origins. Its action gate resolves each call to the required IAM actions and applies a read-only policy before attaching credentials; the video also describes an auditable JSONL log of tool calls. Agents are defined as Markdown files containing a description and prompt, and can run interactively, non-interactively, or with piped findings. The project is distributed as a single open-source binary and supports configuring the model provider and model through environment variables.

What cynative is used for

1 use taken from transcripts — each links to the moment in the video.

  • Investigates infrastructure questions across source control, cloud, and Kubernetes as a unified read-only system. It runs API queries in ephemeral sandboxes, cross-checks findings against live evidence, and records tool calls in an auditable JSONL log.

Videos mentioning cynative

1 in the library.