Open-source project
jd-opensource/JoySafeter avatar
jd-opensource/JoySafeter

JoySafeter: an AI agent platform for security work, not for chat

🚀 JoySafeter: An enterprise AI Agent Platform—Not just chatting. building、running、testing, and tracing autonomous Agent Teams with visual orchestration...

311 stars57 forksPythonApache-2.0

At a glance

What is it?
JoySafeter is an Apache-2.0 platform from JD Open Source for building, orchestrating and tracing security agent teams on LangGraph, with MCP tool integration and a sandboxed execution model. It is aimed at security teams that want autonomous APK analysis and penetration testing workflows, and it expects Python 3.12, Node.js 20 and a sandbox image to be in place before anything runs.
Who is it for?
Adopt JoySafeter if you have a security team that already runs MobSF, Nmap, Nuclei or Trivy and wants agent orchestration around them, plus the infrastructure to host PostgreSQL, Redis and the sandbox image. Do not adopt it if you want a chat interface, a managed service, or a single-binary install.
Can I use it commercially?
Yes. Apache-2.0 is a permissive licence: you can use, modify and sell software built on it, as long as you keep its copyright and licence notices.
Is it still maintained?
Yes. The repository last received commits 22 days ago.
What is it written in?
Mainly Python, according to GitHub's language statistics.

Answers come from the project's GitHub data, last synced on September 22, 2026, and from our analysis. They are not legal advice.

Editorial analysis

The problem JoySafeter targets: security scripts that do not adapt

Security automation usually means scripts. A scan runs, produces findings, and a human decides what to do next. The README frames the ceiling this way: scripts are brittle, single agents lack context, and complex scenarios require 2 to 3 engineers working in parallel. JoySafeter's answer is to replace the fixed playbook with agent teams that decide their next step from what they just found.

The two worked examples in the README are APK vulnerability analysis and penetration testing. In the APK case, a user uploads a file, an agent calls MobSF for static analysis, extracts risk signals such as permission abuse, hardcoded secrets and insecure network configuration, then deep-validates high-severity findings through Frida dynamic instrumentation before generating a report aligned to the OWASP Mobile Top 10. In the penetration testing case, the agent receives an authorized target URL and test requirements, runs autonomously, and the README states that if it discovers a login page it automatically triggers auth bypass testing.

That second behaviour is the actual differentiator. A fixed script cannot decide mid-run to test authentication because it found a form. The audience is therefore narrow and specific: security engineers and AppSec teams who already own these tools and want orchestration on top, not developers looking for a general-purpose agent framework.

How JoySafeter works: LangGraph, DeepAgents and MCP tools

The architecture visible in the README and the repository badges is layered. LangGraph 1.0 or later is the execution engine, described as graph-based workflows with full state management. On top of it sits DeepAgents v0.4, which provides the Manager-Worker multi-level collaboration model. Tools enter through the Model Context Protocol, with the README claiming 200+ integrated tools and naming Nmap, Nuclei and Trivy as pre-integrated examples. Skills are versioned, reusable capability units with progressive disclosure, and the README says there are 30+ pre-built skills covering penetration testing, document analysis and cloud security.

Memory is split into long-term and short-term, which the README describes as memory evolution for continuous learning across sessions. The front end offers two authoring modes: Rapid Mode, where you describe the agent team in natural language, and Deep Mode, which provides visual debugging and step-by-step observability. The repository is a Python backend with a Node front end, and the top level shows backend/, frontend/, deploy/, docs/, scripts/ and skills/ directories, so the skills are shipped as files rather than embedded in code.

The enterprise layer is multi-tenancy with role-based access control, an audit trail for execution tracing, SSO through GitHub, Google, Microsoft, OIDC providers (Keycloak, Authentik, GitLab) and JD SSO, and a per-user sandbox that the README describes as isolated code execution with zero state leakage. That sandbox is the part worth scrutinising: agent-generated code that touches live targets is exactly where isolation stops being a nice-to-have.

Installing JoySafeter and running a first agent

The README recommends the one-click launcher over manual setup. It is an interactive script, so run it from the repository root and answer the menu prompts.

bash
./deploy/quick-start.sh

The script asks you to choose a startup mode and lets you customise ports with conflict detection. The four modes are Docker Compose full stack (frontend, backend, PostgreSQL, Redis), local frontend only via `bun run dev`, local backend only via `uvicorn --reload`, and local frontend plus backend with middleware started automatically. All four support remote deployment, and the README notes that non-localhost deployments automatically update the frontend CSP whitelist through `NEXT_PUBLIC_CSP_CONNECT_SRC_EXTRA` in `frontend/.env`.

Two flags let you skip steps you have already done:

bash
./deploy/quick-start.sh --skip-env       # Skip .env file initialization
./deploy/quick-start.sh --skip-db-init   # Skip database initialization

Before any of this, check the versions the badges require: Python 3.12+, Node.js 20+, LangGraph 1.0+ and FastAPI 0.122+. The repository also ships INSTALL.md and INSTALL_CN.md, which is where the detailed prerequisites live; the README itself only sketches the modes.

For the penetration testing agent, the README gives a concrete sequence. Open the Workbench and create a new agent, enable DeepAgents mode and select penetration testing skills, then provide an authorized target URL and test requirements. The agent runs autonomously and you download the report when the run completes. There is one hard prerequisite the README calls out in a note: the sandbox image `swr.cn-north-4.myhuaweicloud.com/ddn-k8s/ghcr.io/jd-opensource/joysafeter-sandbox:latest` must be configured in Sandbox Settings. Without it, the agent has nowhere to execute.

Where JoySafeter stops being the right tool

The first limitation is infrastructure weight. JoySafeter is not a single binary or a CLI you install and point at a target. The full stack mode runs frontend, backend, PostgreSQL and Redis, and the autonomous cases additionally need a sandbox image pulled from a Huawei Cloud registry. If your environment cannot reach that registry, or you do not want to operate a database and a cache for an agent runner, this is the wrong shape of tool.

The second is scope. Despite the generic 'enterprise AI Agent Platform' framing in the repository description, every concrete example in the README is security work: APK analysis, penetration testing, vulnerability detection. The skills directory and the topic list point the same way. Teams looking for a general agent framework to build customer support or data pipelines will find the security-specific skills and tool integrations are the bulk of the value, and the rest is orchestration you could get from LangGraph directly.

The third is the autonomy claim itself. The README states the APK flow requires zero manual intervention and covers work that traditionally takes 2 to 3 security engineers. That is a strong claim and the README provides no benchmark, no accuracy figure and no false-positive rate. The penetration testing example carries a note about authorized targets, and the repository includes PENETRATION_TESTING_DISCLAIMER_CN.md, which tells you the maintainers are aware of the misuse surface. Treat the autonomous output as a draft that a human reviews, not as a report you ship unreviewed.

Finally, the documentation is uneven. The README is rich on modes and cases but the project does not document rollback, upgrade paths between v0.3.x and v1.0.0, or how skill versions are migrated. CHANGELOG.md exists at the top level, so that is where to look before upgrading.

JoySafeter compared with wiring agents together yourself

The honest alternative is not another platform; it is building on LangGraph directly, since JoySafeter is itself a LangGraph application. If you already have a team comfortable with graph-based agent code, the difference comes down to what JoySafeter adds on top: the visual builder, the MCP tool catalogue, the skill versioning, the multi-tenant sandbox and the audit trail.

A second alternative is staying with the tools themselves. MobSF, Nmap, Nuclei and Trivy all work without an agent layer, and the README's own comparison table admits the traditional approach is manual MobSF plus engineer review. If your volume is low, that manual path is cheaper than operating PostgreSQL, Redis and a sandbox image. JoySafeter pays off when the number of targets or APKs is high enough that the coordination work, not the scanning, is the bottleneck.

A third path is a hosted agent platform. The trade-off is the opposite of JoySafeter's: you avoid the deployment, but you lose the self-hosted sandbox isolation and the audit trail that the README positions as the enterprise story. For security work that touches client systems, keeping execution inside your own network is usually the deciding factor, and that is the case JoySafeter is built for.

Licence, maintenance and what an upgrade costs

JoySafeter is Apache-2.0, and the repository carries a THIRD_PARTY_LICENSES.md file at the top level. That matters more than usual here because the platform integrates third-party security tools and an MCP tool catalogue; the Apache-2.0 grant covers JoySafeter's own code, not the licences of everything it calls. Before shipping a product built on it, read THIRD_PARTY_LICENSES.md and check the terms of the individual tools you enable. This is a description of what the repository contains, not legal advice.

On maintenance, the last push was on 2026-09-09 and the repository is not archived. The release history shows v0.3.1 on 2026-04-08, v0.3.2 on 2026-04-13 and v1.0.0 on 2026-07-02. That is a real 1.0 milestone rather than a perpetual 0.x, and the gap between v0.3.2 and v1.0.0 is roughly eleven weeks, so the project does move.

The upgrade cost is the part to budget for. v1.0.0 pins LangGraph 1.0+ and DeepAgents v0.4, and the README does not describe a migration path from the 0.3 line. Because skills are versioned units and the sandbox is a separate image tag, an upgrade touches three things at once: the application, the skill definitions and the sandbox image. The `--skip-env` and `--skip-db-init` flags on the launcher suggest the maintainers expect repeat runs, but the README does not document rollback if a v1.0.0 upgrade goes wrong. Take a database snapshot yourself before you run it.

Editorial conclusion

Adopt JoySafeter if you have a security team that already runs MobSF, Nmap, Nuclei or Trivy and wants agent orchestration around them, plus the infrastructure to host PostgreSQL, Redis and the sandbox image. Do not adopt it if you want a chat interface, a managed service, or a single-binary install. Before committing, verify three things: that the sandbox image tag swr.cn-north-4.myhuaweicloud.com/ddn-k8s/ghcr.io/jd-opensource/joysafeter-sandbox:latest is reachable from your network, that your SSO provider is one of the listed ones, and that INSTALL.md's port assignments do not collide with what you already run.

Frequently asked questions

What is JoySafeter and who is it for?

It is an Apache-2.0 platform for building, orchestrating and running security agent teams, built on LangGraph with DeepAgents orchestration and MCP tool integration. It is aimed at security engineers and AppSec teams working on tasks such as APK vulnerability analysis and penetration testing.

How do I install JoySafeter?

The README recommends running ./deploy/quick-start.sh, an interactive script that offers four startup modes including a Docker Compose full stack with frontend, backend, PostgreSQL and Redis. It requires Python 3.12+ and Node.js 20+, and detailed prerequisites are in INSTALL.md.

Does JoySafeter need a sandbox to run agents?

For the penetration testing case, the README states that the sandbox image swr.cn-north-4.myhuaweicloud.com/ddn-k8s/ghcr.io/jd-opensource/joysafeter-sandbox:latest must be configured in Sandbox Settings. The platform also describes a multi-tenant sandbox for per-user isolated code execution.

Which security tools does JoySafeter integrate?

The README names Nmap, Nuclei and Trivy as pre-integrated tools and says more than 200 tools are available through the Model Context Protocol. The APK example also uses MobSF for static analysis and Frida for dynamic instrumentation.

Is JoySafeter actively maintained?

The repository is not archived and the last push was on 2026-09-09. The most recent release is v1.0.0, published on 2026-07-02, following v0.3.2 on 2026-04-13.

Official sources

  1. Issues
  2. jd-opensource/JoySafeter on GitHub
  3. License: Apache-2.0
  4. README
  5. Releases
Add this badge to your README

If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.

Add this badge to your README

markdown
[![Hysen Labs](https://hysenlabs.com/badge/jd-opensource-joysafeter.svg)](https://hysenlabs.com/projects/jd-opensource-joysafeter)