Runners
Runners are tenant-scoped agents that execute security tooling and push normalized results back into ExposureX.
Supported tools
semgrepfor SASTgitleaksfor secretstrivyfor SCA, filesystem, IaC and container checksnucleifor DAST/templates and safe re-verification- recon wrappers such as
subfinder,dnsx,naabu,httpx, andkatanawhen installed
Command lifecycle
- Runner sends heartbeat.
- Runner polls
/api/v1/agent/commands. - Runner acknowledges, starts, completes, or fails the command.
- Runner pushes CTIS/SARIF findings and assets.