Skip to main content

agent-audit

一键审计本机 AI Agent 环境:供应链投毒 / 密钥暴露 / 端口暴露 / MCP server 体检。 运行时零依赖,全程只读,Windows 优先(同时支持 Linux/macOS)。

为什么需要它(2026 实战背景)

  • ClawHavoc 供应链投毒:800+ 恶意 skill 泛滥(2026-02 顶峰);Snyk 审计 ClawHub 3984 技能中 13.4% 含严重安全问题,36.8% 有漏洞。市场导入 skill 拥有与用户同等的执行权限(terminal / file / web)。
  • 端口暴露:OpenClaw 默认监听 0.0.0.0:18789,国家应急中心通报 85% 实例暴露公网;ComfyUI 1000+ 暴露实例被组僵尸网络挖矿。
  • 窃密木马:Vidar 变种专偷 agent 配置目录(token / private key)。
  • 依赖投毒:2026-03 LiteLLM / Axios / Apifox / Trivy 投毒波及多个 agent 应用。
  • MCP 攻击面:MCP 已成 agent 连接工具数据的事实标准,远程 / 无鉴权 / 未知名 npm 包 MCP server 是新入口(对照 OWASP MCP Security Guide)。

快速开始

pip install agent-env-audit     # PyPI(发行版即将上线;import 包名为 agent_audit)
# 或从源码安装
pip install git+https://github.com/mo9652962-ai/agent-audit.git
# 或免安装直接跑
git clone https://github.com/mo9652962-ai/agent-audit.git && cd agent-audit
PYTHONPATH=src python -m agent_audit

agent-audit                     # 默认审计 Hermes 环境 + 当前工作区
agent-audit --checks ports,mcp  # 只跑指定检查
agent-audit --skills-dir ~/agents/skills --config-dir ~/agents

或安装为命令行工具:

pip install .            # 或 pipx install .
agent-audit --version

全部检查均为只读操作(netstat / 文件读取 / icacls 查询 / git ls-files),不会修改任何配置。

7 项检查

# 检查项 内容 判定标准
1 端口暴露 全部 TCP 监听 socket 严禁 0.0.0.0 通配;agent 端口(18789/8188/1042)暴露 = critical
2 Skill 来源分类 市场导入(@ 前缀)vs 官方/自建 数量盘点 + 风险提示(决定性证据在下一项)
3 外发端点白名单 skill 代码里的所有 URL ✅ 全部官方 API/本地回环;❌ 未知域名、IP 直连、内网穿透隧道、短链接
4 凭据权限与明文 .env 权限(icacls/chmod)+ 记忆/配置文件明文密钥 .env 仅当前用户可读;MEMORY.md 命中真实 key = high
5 Git 泄漏 .env / config.yaml 是否被追踪 + .gitignore 规则 被 auto-sync 提交 = critical
6 依赖漏洞 uv audit / pip-audit(自动回退) 无已知漏洞;工具缺失给出安装指引
7 MCP Server 审计 对照 OWASP MCP Security Guide 全部本地/官方、带鉴权、闲置已禁用

判定哲学:不要只数 skill 数量——外发端点白名单才是决定性证据(数量多 ≠ 有问题,端点全白名单 = 安全)。

报告

输出 Markdown + JSON 双格式到 agent-audit-reports/:

  • 审计完成标准表:6 条来自实战的验证标准,逐条 ✅/❌
  • 详细发现:严重度 / 证据 / 修复建议,每条发现都带可执行的修复命令
  • 修复优先级清单:critical → medium 排序
  • JSON 报告含全部结构化细节(监听列表、端点分类计数、MCP 逐 server 判定)

退出码:0 通过 / 1 存在 ≥ 阈值的发现(默认 high,可作 CI 门禁)/ 2 参数错误。

# CI 门禁用法
python -m agent_audit --severity-threshold high || exit 1

配置文件(可选)

# audit.toml
[paths]
skills_dirs = ["C:/Users/me/AppData/Local/hermes/skills"]
config_dirs = ["C:/Users/me/AppData/Local/hermes"]
workspaces  = ["D:/my-vault"]
mcp_configs = ["C:/Users/me/AppData/Local/hermes/config.yaml"]

[ports]
watch   = { 18789 = "OpenClaw 网关", 8188 = "ComfyUI" }
system_noise = [135, 445]

[endpoints]
whitelist = ["api.my-company.com"]
python -m agent_audit -c audit.toml

默认路径自动探测:Hermes(%LOCALAPPDATA%/hermes,非 Windows 为 ~/.hermes)、Claude Desktop(%APPDATA%/Claude);--skills-dir / --config-dir / --mcp-config / --workspace 可多次指定,叠加在配置文件之后。

文档

设计原则

  • 零运行时依赖:安全审计工具自己先做好供应链(PyYAML 可选,缺失时自动降级解析)。
  • 全程只读:只查询、不修改;修复动作以命令形式写在报告里,由人决定是否执行。
  • Windows 优先:icacls / netstat / tasklist 一等公民——大部分 agent 安全工具默认 Linux,Windows 用户的 agent 环境没人管。
  • 证据导向:每条发现附带证据(文件:行号、URL、ACL)与修复命令,不吓唬人。

Roadmap

  • skill-vetter 集成:skill 安装前审查
  • --fix 模式:一键收紧权限 / 改监听(带确认)
  • OWASP Agentic AI Top 10 完整映射
  • GitHub Action:PR 时自动跑依赖 + git 泄漏检查

License

MIT

Release files for agent-env-audit 0.1.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for agent-env-audit 0.1.0
File Size Uploaded
agent_env_audit-0.1.0.tar.gz 32.4 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for agent-env-audit 0.1.0
File Interpreter ABI Platform
agent_env_audit-0.1.0-py3-none-any.whl Python 3 none any Details

Total release size: 65.8 kB

Release files / agent_env_audit-0.1.0.tar.gz

Download URL agent_env_audit-0.1.0.tar.gz
Size 32.4 kB
Tags Source
SHA-256 checksum
How to use checksums
47a2692e3bbc8672371ebb7fae26a4e754f89473925f74375ad9d67e1ba1857d
BLAKE2b-256 checksum
How to use checksums
026915b05fc7d296e822f057b07edf58f204e6f83f2c71b1c309488a6425c40b
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 29, 2026.

Transparency log

Release files / agent_env_audit-0.1.0-py3-none-any.whl

Download URL agent_env_audit-0.1.0-py3-none-any.whl
Size 33.4 kB
Tags Python 3
SHA-256 checksum
How to use checksums
ad2e6966f06a3eded120014110c96315d548879ac0e087a4b5648de4a3d77894
BLAKE2b-256 checksum
How to use checksums
7d3bce10f81bd3d6b20cd04dc7c34f990c87e0c00536b0b5cab19dd05df44a90
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 29, 2026.

Transparency log

Release history Release notifications | RSS feed

0.1.1

2 release files

This release

0.1.0 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page