
Product
Introducing Socket Scanning for VS Code Marketplace Extensions
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.
RedScope AI - security-focused AI CLI for penetration testing, asset reconnaissance, threat tracing, and red-team orchestration
Which RedScope do you like? The open source one is the best.
A reverse-engineered / decompiled source restoration of the RedScope AI CLI tool. The main project path, documentation, and install examples now use RedScope branding; legacy CLI aliases are compatibility-only.
我们将会在五一期间进行整个代码仓库�?lint 规范�? 这个期间提交�?PR 可能会有非常多的冲突, 所以大的功能请尽量在这之前提交�? 文档在这�? 支持投稿 PR | 留影文档在这里 | Discord 群组
| 特�? | 说明 | 文档 |
|---|---|---|
| *RedScope 群控技�? | Pipe IPC 多实例协作:同机 main/sub 自动编排 + LAN 跨机器零配置发现与通讯,/pipes 选择面板 + Shift+↓ 交互 + 消息广播路由 | Pipe IPC / LAN |
| ACP 协议一等一支持 | 支持接入 Zed、Cursor �?IDE,支持会话恢复、Skills、权限桥�? | 文档 |
| Remote Control 私有部署 | Docker 自托管远程界�? 可以手机上看 CC | 文档 |
| Langfuse 监控 | 企业�?Agent 监控, 可以清晰看到每次 agent loop 细节, 可以一键转化为数据�? | 文档 |
| Web Search | 内置网页搜索工具, 支持 bing �?brave 搜索 | 文档 |
| Poor Mode | 穷鬼模式,关闭记忆提取和键入建议,大幅度减少并发请�? | /poor 可以开�? |
| Channels 频道通知 | MCP 服务器推送外部消息到会话(飞�?Slack/Discord/微信等),--channels plugin:name@marketplace 启用 | 文档 |
| 自定义模型供应商 | OpenAI/Anthropic/Gemini/Grok 兼容 (/login) | 文档 |
| Voice Mode | 语音输入,支持豆包语言输入(/voice doubao�? | 文档 |
| Computer Use | 屏幕截图、键鼠控�? | 文档 |
| Chrome Use | 浏览器自动化、表单填写、数据抓�? | 自托管 原生版 |
| Sentry | 企业级错误追�? | 文档 |
| GrowthBook | 企业级特性开�? | 文档 |
| /dream 记忆整理 | 自动整理和优化记忆文�? | 文档 |
不用克隆仓库, �?NPM 下载�? 直接使用
npm i -g redscope
# bun 安装比较多问�? 推荐 npm �?# bun i -g redscope
# bun pm -g trust redscope @redscope-ai/mcp-chrome-bridge
redscope # �?nodejs 打开 redscope ai
redscope-bun # �?bun 形态打开
redscope update # 更新到最新版�?REDSCOPE_BRIDGE_BASE_URL=https://your-rcs-host.example/ REDSCOPE_BRIDGE_OAUTH_TOKEN=test-my-key redscope --remote-control # 我们有自部署的远程控�?```
> **安装/更新失败�?* �?`npm rm -g redscope` 清理旧版本,�?`npm i -g redscope@latest`。仍失败则指定版本号:`npm i -g redscope@<版本�?`
## �?快速开�?源码�?
### ⚙️ 环境要求
一定要最新版本的 bun �? 不然一堆奇奇怪怪的 BUG!!! bun upgrade!!!
- 📦 [Bun](https://bun.sh/) >= 1.3.11
**安装 Bun�?*
```bash
# Linux �?macOS
curl -fsSL https://bun.sh/install | bash
# Windows (PowerShell)
powershell -c "irm bun.sh/install.ps1 | iex"
*安装后的操作�?
让当前终端识�?bun 命令
安装脚本会把 ~/.bun/bin 写入对应�?shell 配置文件。macOS 默认 zsh 环境通常会看到:
Added "~/.bun/bin" to $PATH in "~/.zshrc"
可以按安装脚本提示重启当�?shell�?
exec /bin/zsh
如果你使�?bash,重新加�?bash 配置�?
source ~/.bashrc
Windows PowerShell 用户关闭并重新打开 PowerShell 即可�?
验证 Bun 是否可用
bun --help
bun --version
*如果已经安装�?Bun,更新到最新版�?
bun upgrade
curl -fsSL https://bun.sh/install | bash、bun --help、bun --version、bun upgradepackage.json 的目录�?cd /path/to/redscope-ai
bun install
# Build the current checkout
bun run build
# Link once for local development so the terminal can run redscope
npm link --ignore-scripts
# Start RedScope AI from the terminal
redscope
# Optional Bun entrypoint
redscope-bun
# Source debug runner
bun run dev
构建采用 code splitting 多文件打包(build.ts),产物输出�?dist/ 目录(入�?dist/cli.js + �?450 �?chunk 文件)�?
构建出的版本 bun �?node 都可以启�? �?publish 到私有源可以直接启动
如果遇到 bug 请直接提一�?issues, 我们优先解决
First interactive redscope launch opens setup before the REPL. Choose Configure RedScope separately to enter API/provider details immediately, or choose Reuse existing Claude config. The same setup is available later with /login.
需要填写的字段�?
| 📌 字段 | 📝 说明 | 💡 示例 |
|---|---|---|
| Base URL | API 服务地址 | https://api.example.com/v1 |
| API Key | 认证密钥 | sk-xxx |
| Haiku Model | 快速模�?ID | claude-haiku-4-5-20251001 |
| Sonnet Model | 均衡模型 ID | claude-sonnet-4-6 |
| Opus Model | 高性能模型 ID | claude-opus-4-6 |
ℹ️ 支持所�?Anthropic API 兼容服务(如 OpenRouter、AWS Bedrock 代理等),只要接口兼�?Messages API 即可�?
所有功能开关通过 FEATURE_<FLAG_NAME>=1 环境变量启用,例如:
FEATURE_BUDDY=1 FEATURE_FORK_SUBAGENT=1 bun run dev
�?Feature 的详细说明见 docs/features/ 目录,欢迎投稿补充�?
TUI (REPL) 模式需要真实终端,无法直接通过 VS Code launch 启动调试。使�?attach 模式�?
终端启动 inspect 服务�?
bun run dev:inspect
会输出类�?ws://localhost:8888/xxxxxxxx 的地址�?2. **VS Code 附着调试�?*�?
src/ 文件中打断点我们新加了一�?teach-me skills, 通过问答式引导帮你理解这个项目的任何模块�?调整 sigma skill 而来)
# �?REPL 中直接输�?/teach-me RedScope AI 架构
/teach-me React Ink 终端渲染 --level beginner
/teach-me Tool 系统 --resume
--resume 从上次进度继�?学习进度保存�?.claude/skills/teach-me/ 目录下,支持跨主题学习者档案�?
docs/ 目录,欢迎投�?PR本项目仅供学习研究用途。RedScope AI 的所有权利归 Anthropic 所有�?
FAQs
RedScope AI - security-focused AI CLI for penetration testing, asset reconnaissance, threat tracing, and red-team orchestration
The npm package redscope receives a total of 0 weekly downloads. As such, redscope popularity was classified as not popular.
We found that redscope demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.

Research
/Security News
Socket uncovered two malicious VS Code themes in a GlassWorm-linked cluster with thousands of installs across VS Code Marketplace and Open VSX.

Security News
/Company News
Capital One is partnering with Socket to proactively secure its open source supply chain.