Skip to main content

aisec-suite

tests python license

One command that runs three AI-security scanners on a repository and writes SARIF for GitHub code scanning.

Scanner What it checks Input found automatically
mcpaudit MCP tool poisoning and over-broad tool scope (static checks) Tool definitions extracted statically from source (Python FastMCP decorators, TS/JS registerTool/addTool/server.tool), plus manifest *.json files
memsentry Injected instructions and hidden payloads in agent context files CLAUDE.md, AGENTS.md, GEMINI.md, .cursorrules, .windsurfrules, .clinerules, .cursor/rules/*, copilot-instructions.md
ragsentry Injection and retrieval manipulation in RAG source documents A directory you pass with --rag

No third-party code is executed: tool definitions are read from source, not by launching the server.

pip install "aisec-suite[scanners]"   # also installs pyhroff-mcpaudit, memsentry, pyhroff-ragsentry from PyPI
aisec scan . --sarif aisec.sarif --fail-on high
aisec scan . --rag ./docs --json findings.json

Exit codes: 0 clean, 1 a finding at or above --fail-on, 2 a scanner crashed (so a clean result can't be trusted; only with --fail-on). Use --include-tests to also extract tools from tests/examples/fixtures.

Adopting it on an existing repo without a wall of red

aisec scan . --write-baseline .aisec-baseline.json     # accept what exists today
aisec scan . --baseline .aisec-baseline.json --fail-on high   # CI now fails only on NEW findings

Fingerprints ignore line numbers, so moving code around does not resurface accepted findings. Every run also writes a Markdown table to the GitHub job summary (--summary).

GitHub Action

One line, no install step; the scanners come from PyPI:

permissions:
  contents: read
  security-events: write
steps:
  - uses: actions/checkout@v4
  - uses: Pyhroff/aisec-suite@v0.2.0
    with:
      fail-on: high

Inputs: path, fail-on, rag-dir, baseline, install, upload-sarif. Needs security-events: write for the upload step. Inputs reach the shell only through quoted env vars, never interpolated into script text.

(The action itself has not yet been run on GitHub Actions; the CLI and adapters are tested, including with fake scanners in CI.)

Honest scope

  • Static extraction is best-effort. In a study of 90 public MCP repos it found tools in 53 (about 59%); "no tools found" prints a note and means unknown, not safe.
  • Findings are heuristics for human review. In the same study only 37.5% (95% CI 24-53%) of mcpaudit v0.6's HIGH permission_scope findings were accurate, and none of the flagged repos had genuine tool poisoning. Use the patched scanners (mcpaudit 0.7 / memsentry 1.2) for fewer false positives; see mcp-scan-study/REPORT.md.
  • mcpaudit's dynamic (live LLM) and rug-pull checks are not part of this suite; use mcpaudit directly for those.
  • Line numbers for extracted tools point at the registration call, not the description text.

Development

pip install -e ".[dev]" && pytest -q (adapter tests use in-memory fake scanners and always run; a few end-to-end tests skip unless the real scanners are installed).

Evidence

Precision, recall, reachability and tool-poisoning benchmark results, with their limits, are in docs/STUDY.md. aisec scan --no-structural disables the poisoning heuristic; --reach strict makes HIGH mean a sink was reached.

Metadata

Release files for aisec-suite 0.3.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for aisec-suite 0.3.0
File Size Uploaded
aisec_suite-0.3.0.tar.gz 33.3 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for aisec-suite 0.3.0
File Interpreter ABI Platform
aisec_suite-0.3.0-py3-none-any.whl Python 3 none any Details

Total release size: 63.1 kB

Release files / aisec_suite-0.3.0.tar.gz

Download URL aisec_suite-0.3.0.tar.gz
Size 33.3 kB
Tags Source
SHA-256 checksum
How to use checksums
1b34a58b9c414455d5200083f50846b260374a2fc055ad7457ee1f77e794a8b2
BLAKE2b-256 checksum
How to use checksums
3282e854989da9f0f46ec06bcc950ac58510dd820042ae4e18b054c5ef300c93
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 2, 2026.

Transparency log

Release files / aisec_suite-0.3.0-py3-none-any.whl

Download URL aisec_suite-0.3.0-py3-none-any.whl
Size 29.8 kB
Tags Python 3
SHA-256 checksum
How to use checksums
e14633e7d677eca23eef292ca46f9ec9be4f1113a0ca4c60100161fcc0710656
BLAKE2b-256 checksum
How to use checksums
e563e15b7236af9ddfcbe60460c61e22b23e52c0ddb24c8f50e8eb0ce2135083
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 2, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

0.3.0 This release

2 release files

0.2.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page