Agent Audit
Pre-deploy security gate for any team building AI agents. Outputs SARIF reports compatible with GitHub Security tab.
Static security scanner for AI agent code with 72 rules mapped to the OWASP Agentic Top 10 (2026). Uses tool-boundary taint tracking, MCP configuration auditing, and semantic secret detection to catch prompt injection paths, unsafe tool inputs reaching subprocess/eval, and credential exposure before deployment. Reported validation (v0.19.0): 82.6% recall, 73.6% precision. Supports severity filtering and CI gating via --fail-on.
- Run before every agent deployment to detect prompt injection vulnerabilities
- Generate SARIF security reports for GitHub Security tab and compliance audits
- Validate agent codebases for taint flow from user input to tool execution
Pre-deploy security gate for any team building AI agents. Outputs SARIF reports compatible with GitHub Security tab.
Development teams deploying AI agents who need automated security validation before production.
https://github.com/HeadyZhang/agent-audit
By HeadyZhang
How to Get It
pip install agent-audit
Tip: Paste this into a Claude Code conversation. Verify command matches your Claude Code version.
After installing, paste this into Claude:
Help me run before every agent deployment to detect prompt injection vulnerabilities
Trust Signals Auto-scanned
Community Pulse Active
Discussed on Hacker News, Reddit
- Mischief Toy Store faces DHS audit after criticism of ICE — Reddit · 18805 pts
- Would Americans support hiring an additional 15,000 IRS agents purely to assigne — Reddit · 555 pts
- I built a CLI to audit custom LangChain @tool definitions for security flaws. — Reddit · 7 pts
3 mentions across 1 sources
Reviewer notes
Auto-scanned review. These are observations, not a security certification.
catalog_hygiene stale-eval refresh: Scored from trust signals (evidence-eval-v1): 193 GitHub stars; 15 contributors; last commit 6d ago; license MIT.
Things to check
- Recently discovered. Looks promising but has limited community feedback so far. We added it early so you can evaluate it before the crowd finds it.
How to evaluate tools before deploying →
Data shown here comes from public APIs and automated scanning. Reviewer notes reflect one person's experience. This is not a security certification or legal recommendation. Always evaluate tools according to your own organization's policies.
Evaluation
catalog_hygiene stale-eval refresh: Scored from trust signals (evidence-eval-v1): 193 GitHub stars; 15 contributors; last commit 6d ago; license MIT.