aisec-suite
One command that runs three AI-security scanners on a repository and writes SARIF for GitHub code scanning.
| Scanner | What it checks | Input found automatically |
|---|---|---|
| mcpaudit | MCP tool poisoning and over-broad tool scope (static checks) | Tool definitions extracted statically from source (Python FastMCP decorators, TS/JS registerTool/addTool/server.tool), plus manifest *.json files |
| memsentry | Injected instructions and hidden payloads in agent context files | CLAUDE.md, AGENTS.md, GEMINI.md, .cursorrules, .windsurfrules, .clinerules, .cursor/rules/*, copilot-instructions.md |
| ragsentry | Injection and retrieval manipulation in RAG source documents | A directory you pass with --rag |
No third-party code is executed: tool definitions are read from source, not by launching the server.
pip install "aisec-suite[scanners]" # also installs pyhroff-mcpaudit, memsentry, pyhroff-ragsentry from PyPI
aisec scan . --sarif aisec.sarif --fail-on high
aisec scan . --rag ./docs --json findings.json
Exit codes: 0 clean, 1 a finding at or above --fail-on, 2 a scanner crashed (so a clean result can't be trusted; only with --fail-on). Use --include-tests to also extract tools from tests/examples/fixtures.
Adopting it on an existing repo without a wall of red
aisec scan . --write-baseline .aisec-baseline.json # accept what exists today
aisec scan . --baseline .aisec-baseline.json --fail-on high # CI now fails only on NEW findings
Fingerprints ignore line numbers, so moving code around does not resurface accepted findings. Every run also writes a Markdown table to the GitHub job summary (--summary).
GitHub Action
One line, no install step; the scanners come from PyPI:
permissions:
contents: read
security-events: write
steps:
- uses: actions/checkout@v4
- uses: Pyhroff/aisec-suite@v0.2.0
with:
fail-on: high
Inputs: path, fail-on, rag-dir, baseline, install, upload-sarif. Needs security-events: write for the upload step. Inputs reach the shell only through quoted env vars, never interpolated into script text.
(The action itself has not yet been run on GitHub Actions; the CLI and adapters are tested, including with fake scanners in CI.)
Honest scope
- Static extraction is best-effort. In a study of 90 public MCP repos it found tools in 53 (about 59%); "no tools found" prints a note and means unknown, not safe.
- Findings are heuristics for human review. In the same study only 37.5% (95% CI 24-53%) of mcpaudit v0.6's HIGH
permission_scopefindings were accurate, and none of the flagged repos had genuine tool poisoning. Use the patched scanners (mcpaudit 0.7 / memsentry 1.2) for fewer false positives; seemcp-scan-study/REPORT.md. - mcpaudit's dynamic (live LLM) and rug-pull checks are not part of this suite; use mcpaudit directly for those.
- Line numbers for extracted tools point at the registration call, not the description text.
Development
pip install -e ".[dev]" && pytest -q (adapter tests use in-memory fake scanners and always run; a few end-to-end tests skip unless the real scanners are installed).
Metadata
Release files for aisec-suite 0.2.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| aisec_suite-0.2.0.tar.gz | 16.8 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| aisec_suite-0.2.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 30.5 kB
Release files / aisec_suite-0.2.0.tar.gz
| Download URL | aisec_suite-0.2.0.tar.gz |
|---|---|
| Size | 16.8 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
29a44d2b7d47363ec6100fd6ae4daf4ddcc59b2e0fe1eae6eebbe63ecf5b2099
|
|
BLAKE2b-256 checksum How to use checksums |
812b96332c709821e8cbe676af17190038e4d1b2b9a21e08eb7958af6913c4a2
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 2, 2026.
Transparency logRelease files / aisec_suite-0.2.0-py3-none-any.whl
| Download URL | aisec_suite-0.2.0-py3-none-any.whl |
|---|---|
| Size | 13.8 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
586290bf17494c09a52f58b4532e62aaf30022aa9bfe7498273ef9147b3c1356
|
|
BLAKE2b-256 checksum How to use checksums |
7ed42b6d7b853e137144a8c122886ca1f21629578b6c2e62e904623fe55fdd34
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 2, 2026.
Transparency log