Skip to main content

CVE-style advisory database and static scanner for AI agent security risks

Project description

AgentFort

Static security scanner for AI agent codebases. Analyzes repositories and MCP config files against a CVE-style advisory database — no live agent interaction required.

What it does

  • Scans Python repos for dangerous patterns: eval(), exec(), shell=True, hardcoded API keys
  • Parses MCP config files (claude_desktop_config.json, .mcp.json) for shell execution tools, overly broad filesystem access, and unverified npx/uvx packages
  • Detects agent framework imports (LangChain, CrewAI, AutoGen, OpenAI, Anthropic, etc.) and cross-references against known vulnerabilities
  • Queries OSV.dev live for real CVEs against every detected package — findings stay current without any database updates
  • Produces risk scores, terminal reports, Markdown, and JSON output
  • Exits with code 1 on critical findings — CI pipeline friendly

Install

# From repo root (inside a virtualenv)
pip install agentfort

# Or dev install from repo root
pip install -e .

Usage

# Scan a repo
agentfort scan --repo /path/to/your/agent-project

# Scan just an MCP config file
agentfort scan --mcp-config ~/.config/claude/claude_desktop_config.json

# JSON output (clean stdout, progress on stderr)
agentfort scan --repo . --format json

# Markdown report to file
agentfort scan --repo . --format md --output report.md

# Only show high and above
agentfort scan --repo . --min-severity high

# Disable CI exit code
agentfort scan --repo . --no-fail-on-critical

# Skip OSV live lookup (air-gapped / CI without outbound)
agentfort scan --repo . --offline

# Browse advisories
agentfort advisories list
agentfort advisories list --severity critical
agentfort advisories show AGSA-001

Live CVE lookup (OSV.dev)

Every scan queries OSV.dev in parallel for known CVEs against every package detected in the repo. No database to update — findings reflect OSV's current state on each run.

  • Results are capped at 5 CVEs per package (highest severity first) to avoid noise from very old pinned versions
  • Uses GHSA severity labels (database_specific.severity) for accurate critical/high/medium/low mapping
  • Falls back silently if the network is unreachable — use --offline to skip the lookup entirely
# Scan with live CVEs (default)
agentfort scan --repo .

# Air-gapped / no outbound network
agentfort scan --repo . --offline

Advisory database

14 static advisories covering structural/behavioral risks from the OWASP Agentic Top 10. Package CVEs are handled live by OSV.dev (see above).

ID Severity Risk
AGSA-001 Critical LangChain ShellTool unrestricted shell execution
AGSA-002 Critical MCP server exposes shell execution tool
AGSA-003 Critical eval()/exec() in agent tool handler
AGSA-005 Critical AutoGen/CrewAI code execution without confirmation
AGSA-004 High Hardcoded API key or secret in MCP config
AGSA-006 High MCP filesystem server with overly broad path (/, ~)
AGSA-007 High subprocess with shell=True or os.system()
AGSA-008 High Agent tool writes to arbitrary file paths
AGSA-010 High Prompt injection via unvalidated tool output
AGSA-013 High OpenAI Assistants file_search/code_interpreter without scope restriction
AGSA-009 Medium MCP server loaded via unverified npx/uvx package
AGSA-012 Medium Secrets exposed via os.environ in tool scope
AGSA-014 Medium Non-PyPI/non-npm dependency as framework component
AGSA-015 Medium System prompt in user-accessible config location

Risk score

0–100. Each finding adds: critical=40, high=15, medium=5, low=1. Capped at 100.

Output formats

Terminal (default) — Rich panels with color-coded severity table and detail panels for critical/high findings.

JSON — Machine-readable. Progress messages go to stderr so stdout is clean for piping:

agentfort scan --repo . --format json 2>/dev/null | jq '.findings[] | select(.severity=="critical")'

Markdown — Full report with summary table and per-finding sections, suitable for GitHub issues or PR comments.

Project structure

agentfort/                  # project root
├── agentfort/              # Python package
│   ├── cli.py              # Click CLI entry point
│   ├── models.py           # Finding, ScanResult dataclasses
│   ├── db/
│   │   ├── advisory.py     # Advisory loader and index
│   │   └── data/           # AGSA-001.yaml … AGSA-015.yaml
│   ├── scanner/
│   │   ├── frameworks.py   # requirements.txt / pyproject.toml / package.json
│   │   ├── mcp.py          # MCP config file scanner
│   │   ├── osv.py          # Live CVE lookup via OSV.dev API
│   │   ├── patterns.py     # Python source pattern scanner
│   │   └── secrets.py      # Hardcoded credential scanner
│   └── report/
│       └── formatter.py    # Terminal, Markdown, JSON renderers
└── pyproject.toml

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

agentfort-0.1.2.tar.gz (27.4 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

agentfort-0.1.2-py3-none-any.whl (33.1 kB view details)

Uploaded Python 3

File details

Details for the file agentfort-0.1.2.tar.gz.

File metadata

  • Download URL: agentfort-0.1.2.tar.gz
  • Upload date:
  • Size: 27.4 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.12.3

File hashes

Hashes for agentfort-0.1.2.tar.gz
Algorithm Hash digest
SHA256 3a3b90c8bccb3a38607a97e9ab89bec4432833cc6857fb48542332feb45dd606
MD5 65c5eab6d5bfb2a1ec713b427cbeaa33
BLAKE2b-256 7083d441b6fe50e47f37e2dfd7ba958a3e8260a9a3145fcf374c97dcff477fd5

See more details on using hashes here.

File details

Details for the file agentfort-0.1.2-py3-none-any.whl.

File metadata

  • Download URL: agentfort-0.1.2-py3-none-any.whl
  • Upload date:
  • Size: 33.1 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.12.3

File hashes

Hashes for agentfort-0.1.2-py3-none-any.whl
Algorithm Hash digest
SHA256 02249f400c925e40dd1a06b67f5adadb6e3e8a703d2c814f369eef225790b066
MD5 d834bf5992a97dee3f33d25a08f06571
BLAKE2b-256 c77c5594e591fe1f7320d8f3d9c7736a9df8376f907ea6e99840e86e1120e365

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page