π£ Call for Feedback β We Want to Hear From You
If you found thresher and are poking around, we genuinely want your take.
A bit of context
We built this to scratch our own itch β we wanted a tool that could tear into an OSS
dependency and give us real signal before we trusted it. After a while we thought:
others probably want this too. So we opened it up.
A few honest admissions:
- We're not full-time security practitioners. We've done our homework, but we've
definitely missed things.
- It's a WIP. The security model is intentional and layered, but no tool catches
everything β and we say so in the README.
- The ASCII shark is bad. AI tried. It failed. We kept it. π¦
Where we'd love your input
Security model β Does the VM isolation + 3-layer network + zero-sudo approach
hold up under scrutiny? Are there escape vectors we haven't thought about?
Scanner coverage β We're running 22 tools. What's missing? What's redundant?
What would you swap out?
AI analyst prompts β The 8 personas are only as good as their instructions.
If you've poked at the prompts, we'd love critique.
False positive / false negative rate β Have you run it against something?
What did it catch? What did it miss? What was noise?
Anything else β Love it, hate it, indifferent, think the whole approach is
wrong-headed β all of it is useful to us.
How to respond
Drop a comment here, open a separate issue with a specific finding, or PR if
you've got something concrete. No format required β raw thoughts are fine.
Thanks for taking a look. π
π£ Call for Feedback β We Want to Hear From You
If you found thresher and are poking around, we genuinely want your take.
A bit of context
We built this to scratch our own itch β we wanted a tool that could tear into an OSS
dependency and give us real signal before we trusted it. After a while we thought:
others probably want this too. So we opened it up.
A few honest admissions:
definitely missed things.
everything β and we say so in the README.
Where we'd love your input
Security model β Does the VM isolation + 3-layer network + zero-sudo approach
hold up under scrutiny? Are there escape vectors we haven't thought about?
Scanner coverage β We're running 22 tools. What's missing? What's redundant?
What would you swap out?
AI analyst prompts β The 8 personas are only as good as their instructions.
If you've poked at the prompts, we'd love critique.
False positive / false negative rate β Have you run it against something?
What did it catch? What did it miss? What was noise?
Anything else β Love it, hate it, indifferent, think the whole approach is
wrong-headed β all of it is useful to us.
How to respond
Drop a comment here, open a separate issue with a specific finding, or PR if
you've got something concrete. No format required β raw thoughts are fine.
Thanks for taking a look. π