RASVS is a RAG stack for OWASP ASVS:
ingest the reference PDF into Milvus, answer with hybrid retrieval,
Cross-Encoder re-ranking, and LLM generation;
optional LLM-as-a-Judge for retrieval quality.
Documentation (EN)
·
Documentação (PT)
·
Prerequisites
·
Core features
- Node.js 20+ and dependencies from
rag/package.json - Docker and Docker Compose (to run Milvus)
- OpenAI API key for the agent, evaluation judge, and any paid models referenced in
rag/config.yaml
-
Hybrid search: Combines BM25 keyword search with semantic embedding similarity so both exact terms and context are captured.
-
Milvus vector store: Fast semantic search with partitions to isolate different ingestion strategies.
-
Conversational agent (LangChain): Uses search tools to reason over user questions and answer from retrieved sources.
-
Evaluation pipeline: Optional LLM-as-a-Judge scoring of retrieval quality and accuracy export.
-
Configurable ingestion: Chunking methods and embedding models are driven from
rag/config.yaml.
MIT License. LICENSE
Gabriel Ramos de Paula (@whosramoss)