Open source agent security
agent-audit-kit
SAST scanner for AI agents. Full OWASP Agentic Top-10 + MCP Top-10.
SAST-style security scanner for agentic AI systems. Finds misconfigurations, hardcoded secrets, tool poisoning, rug pulls, trust-boundary violations and tainted data flows, plus MCP STDIO command injection (CVE-2026-30623), all at static-analysis time, before the agent reaches production. It runs fully offline: no account, no telemetry, no model in the loop.
Quickstart
Drop into any Python project. Outputs SARIF that GitHub Code Scanning understands natively. About 30 seconds.
pip install agent-audit-kit
agent-audit-kit scan ./your-agent-project --format sarif > agent-audit.sarifOr use the GitHub Action for CI-time scanning on every PR.
Rule catalogue
375 rules in total in the v0.6.15 rule bundle, across 14 categories. Every finding carries a severity, evidence, a file and line, and a remediation.
- MCP Configuration
- Supply Chain
- Tool Poisoning
- Secret Exposure
- Agent Config
- A2A Protocol
- Hook Injection
- Taint Analysis
- Transport Security
- Legal Compliance
- Trust Boundaries
- MCP Server Card
- Composition
- Agentic Skills
OWASP Agentic Top-10
Full 10/10 coverage: every category from ASI01 to ASI10 maps to at least one rule.
OWASP MCP Top-10
Full 10/10 coverage: every category from MCP01 to MCP10 maps to at least one rule, including the MCP STDIO command-injection rules for CVE-2026-30623.
Both mappings are generated from the live rule registry: OWASP Agentic coverage table (opens in a new tab) and OWASP MCP coverage table (opens in a new tab).
Compliance evidence
PDF and text evidence packs mapped to 14 frameworks. Every control row cites a real clause, and a row the scanner can't evidence says so instead of printing a tick.
What it catches
MCP STDIO command injection
AAK-STDIO-001 and its SDK-specific siblings flag MCP STDIO servers launched from caller- or network-controlled input, the class behind CVE-2026-30623. Caught in the code, before anything runs.
Tool-surface drift (rug pulls)
The pin command fingerprints a server's tools when you approve them. verify re-checks later and flags any tool that changed, appeared or disappeared since (AAK-RUGPULL-001 to 003).
Tool poisoning
Invisible Unicode and prompt injection hidden in tool and parameter descriptions, found in the config and source before an agent ever reads them.
Tainted tool parameters
Taint analysis that follows @tool parameters into shell, SQL, filesystem and network sinks.
Where it fits
Complementary, not integrated: AGT enforces policy at runtime, agent-audit-kit checks the design before deploy. An integration is on the agent-audit-kit roadmap, not shipped.
Listed as a GitHub Action. Drop it into any workflow; it writes SARIF for GitHub code scanning.
Use it in your CI today
Apache-2.0 licensed. Every CVE that becomes a rule is logged in a public CVE-to-rule ledger (opens in a new tab) with its measured latency, not a promised SLA. Star the repo to track new rule families as they ship.