Skip to main content

Open source agent security

agent-audit-kit

SAST scanner for AI agents. Full OWASP Agentic Top-10 + MCP Top-10.

SAST-style security scanner for agentic AI systems. Finds misconfigurations, hardcoded secrets, tool poisoning, rug pulls, trust-boundary violations and tainted data flows, plus MCP STDIO command injection (CVE-2026-30623), all at static-analysis time, before the agent reaches production. It runs fully offline: no account, no telemetry, no model in the loop.

13stars0forks375rules in totalv0.6.15released 2026-10-03

Quickstart

Drop into any Python project. Outputs SARIF that GitHub Code Scanning understands natively. About 30 seconds.

bash
pip install agent-audit-kit
agent-audit-kit scan ./your-agent-project --format sarif > agent-audit.sarif

Or use the GitHub Action for CI-time scanning on every PR.

Rule catalogue

375 rules in total in the v0.6.15 rule bundle, across 14 categories. Every finding carries a severity, evidence, a file and line, and a remediation.

  • MCP Configuration
  • Supply Chain
  • Tool Poisoning
  • Secret Exposure
  • Agent Config
  • A2A Protocol
  • Hook Injection
  • Taint Analysis
  • Transport Security
  • Legal Compliance
  • Trust Boundaries
  • MCP Server Card
  • Composition
  • Agentic Skills
ASI01-ASI10

OWASP Agentic Top-10

Full 10/10 coverage: every category from ASI01 to ASI10 maps to at least one rule.

MCP01-MCP10

OWASP MCP Top-10

Full 10/10 coverage: every category from MCP01 to MCP10 maps to at least one rule, including the MCP STDIO command-injection rules for CVE-2026-30623.

Both mappings are generated from the live rule registry: OWASP Agentic coverage table (opens in a new tab) and OWASP MCP coverage table (opens in a new tab).

report --framework

Compliance evidence

PDF and text evidence packs mapped to 14 frameworks. Every control row cites a real clause, and a row the scanner can't evidence says so instead of printing a tick.

EU AI Act (Art. 15, 50, 55)SOC 2ISO 27001ISO 42001HIPAANIST AI RMFNSA MCP CSISingapore Agentic AIIndia DPDPAlabama HB 351Tennessee SB 1580Colorado SB 26-189

What it catches

MCP STDIO command injection

AAK-STDIO-001 and its SDK-specific siblings flag MCP STDIO servers launched from caller- or network-controlled input, the class behind CVE-2026-30623. Caught in the code, before anything runs.

Tool-surface drift (rug pulls)

The pin command fingerprints a server's tools when you approve them. verify re-checks later and flags any tool that changed, appeared or disappeared since (AAK-RUGPULL-001 to 003).

Tool poisoning

Invisible Unicode and prompt injection hidden in tool and parameter descriptions, found in the config and source before an agent ever reads them.

Tainted tool parameters

Taint analysis that follows @tool parameters into shell, SQL, filesystem and network sinks.

Where it fits

Microsoft Agent Governance Toolkit (opens in a new tab)

Complementary, not integrated: AGT enforces policy at runtime, agent-audit-kit checks the design before deploy. An integration is on the agent-audit-kit roadmap, not shipped.

GitHub Marketplace: agent-audit-kit listing (opens in a new tab)

Listed as a GitHub Action. Drop it into any workflow; it writes SARIF for GitHub code scanning.

Use it in your CI today

Apache-2.0 licensed. Every CVE that becomes a rule is logged in a public CVE-to-rule ledger (opens in a new tab) with its measured latency, not a promised SLA. Star the repo to track new rule families as they ship.

Want it customised for your stack? Agent Security Audit: 2 weeks, $4,950. Custom rule pack + audit-trail review + prioritized playbook.