HeadyZhang/agent-audit

Static security scanner for LLM agents — prompt injection, MCP config auditing, taint analysis. 49 rules mapped to OWASP Agentic Top 10 (2026). Works with LangChain, CrewAI, AutoGen.

51
/ 100
Established

This tool helps AI agent developers, security engineers, and teams managing AI agent servers find security vulnerabilities in their AI agent code before deployment. It takes your agent's code, configuration files, and even live agent server configurations as input and produces a detailed security report, flagging issues like prompt injection, leaked secrets, and unsafe tool usage. This allows those building and securing AI systems to proactively identify and fix potential risks.

104 stars. Available on PyPI.

Use this if you are developing AI agents with frameworks like LangChain or AutoGen, are a security engineer reviewing AI agent code, or manage MCP servers and need to validate their security configuration.

Not ideal if you are working with traditional software applications or chatbots without agentic capabilities, as its focus is specifically on the unique security challenges of AI agents.

AI-agent-development AI-security-auditing prompt-injection-prevention LLM-security AI-operations-risk
Maintenance 10 / 25
Adoption 9 / 25
Maturity 20 / 25
Community 12 / 25

How are scores calculated?

Stars

104

Forks

11

Language

Python

License

MIT

Last pushed

Mar 11, 2026

Commits (30d)

0

Dependencies

6

Get this data via API

curl "https://pt-edge.onrender.com/api/v1/quality/agents/HeadyZhang/agent-audit"

Open to everyone — 100 requests/day, no key needed. Get a free key for 1,000/day.