BrowseFull catalogOutcomesSolve a specific problemRolesStack by teamTrustFilter by risk tier
← Back to the Claude Observatory

Agent Audit

Skill Security Usable
Works inClaude Code
Usable Scanned — metadata only

Pre-deploy security gate for any team building AI agents. Outputs SARIF reports compatible with GitHub Security tab.

Static security scanner for AI agent code with 72 rules mapped to the OWASP Agentic Top 10 (2026). Uses tool-boundary taint tracking, MCP configuration auditing, and semantic secret detection to catch prompt injection paths, unsafe tool inputs reaching subprocess/eval, and credential exposure before deployment. Reported validation (v0.19.0): 82.6% recall, 73.6% precision. Supports severity filtering and CI gating via --fail-on.

207 starsMIT (commercial OK)FreeQuick setup
Usable rating — This tool is functional but has notable gaps. Review the evaluation notes below before deploying.

Pre-deploy security gate for any team building AI agents. Outputs SARIF reports compatible with GitHub Security tab.

Development teams deploying AI agents who need automated security validation before production.

Claude Code Claude Cowork Claude Chat

https://github.com/HeadyZhang/agent-audit

By HeadyZhang

How to Get It

Option 1: Claude Desktop App (Code Mode)Click the + button next to the prompt box → PluginsAdd plugin. Search and click Install. Skills work in Claude Code only.
Option 2: Paste into Claude CodeCopy the command below and paste it into your conversation. Claude will install it.
Command
pip install agent-audit

Tip: Paste this into a Claude Code conversation. Verify command matches your Claude Code version.

First thing to try

After installing, paste this into Claude:

Help me run before every agent deployment to detect prompt injection vulnerabilities
PrerequisitesPython (installed from PyPI via pip).CostFree

Trust Signals Auto-scanned

Stars207Contributors15Last updated2026-07-04LicenseMIT (OK for commercial use)Known CVEsNone foundSources: GitHub Advisory Database + OSV.dev · Scanned 2026-08-13 · scanner vattempted-no-data

Community Pulse Active

Discussed on Hacker News, Reddit

3 mentions across 1 sources

Reviewer notes

Auto-scanned review. These are observations, not a security certification.

catalog_hygiene stale-eval refresh: Scored from trust signals (evidence-eval-v1): 193 GitHub stars; 15 contributors; last commit 6d ago; license MIT.

Things to check

  • Recently discovered. Looks promising but has limited community feedback so far. We added it early so you can evaluate it before the crowd finds it.

How to evaluate tools before deploying →

Data shown here comes from public APIs and automated scanning. Reviewer notes reflect one person's experience. This is not a security certification or legal recommendation. Always evaluate tools according to your own organization's policies.

Evaluation

Ease of Use
3/5
Versatility
3/5
Reliability
4/5
Security
4/5
Overall score3.40 / 5.00 UsableEvaluatedJul 2026
catalog_hygiene stale-eval refresh: Scored from trust signals (evidence-eval-v1): 193 GitHub stars; 15 contributors; last commit 6d ago; license MIT.

← Back to the Claude Observatory

Rolling Claude out in your org? Let's talk.

Start a conversation →