Skip to main content

aisec-suite

tests python license

One command that runs three AI-security scanners on a repository and writes SARIF for GitHub code scanning.

Scanner What it checks Input found automatically
mcpaudit MCP tool poisoning and over-broad tool scope (static checks) Tool definitions extracted statically from source (Python FastMCP decorators, TS/JS registerTool/addTool/server.tool), plus manifest *.json files
memsentry Injected instructions and hidden payloads in agent context files CLAUDE.md, AGENTS.md, GEMINI.md, .cursorrules, .windsurfrules, .clinerules, .cursor/rules/*, copilot-instructions.md
ragsentry Injection and retrieval manipulation in RAG source documents A directory you pass with --rag

No third-party code is executed: tool definitions are read from source, not by launching the server.

pip install "aisec-suite[scanners]"   # also installs pyhroff-mcpaudit, memsentry, pyhroff-ragsentry from PyPI
aisec scan . --sarif aisec.sarif --fail-on high
aisec scan . --rag ./docs --json findings.json

Exit codes: 0 clean, 1 a finding at or above --fail-on, 2 a scanner crashed (so a clean result can't be trusted; only with --fail-on). Use --include-tests to also extract tools from tests/examples/fixtures.

Adopting it on an existing repo without a wall of red

aisec scan . --write-baseline .aisec-baseline.json     # accept what exists today
aisec scan . --baseline .aisec-baseline.json --fail-on high   # CI now fails only on NEW findings

Fingerprints ignore line numbers, so moving code around does not resurface accepted findings. Every run also writes a Markdown table to the GitHub job summary (--summary).

GitHub Action

One line, no install step; the scanners come from PyPI:

permissions:
  contents: read
  security-events: write
steps:
  - uses: actions/checkout@v4
  - uses: Pyhroff/aisec-suite@v0.2.0
    with:
      fail-on: high

Inputs: path, fail-on, rag-dir, baseline, install, upload-sarif. Needs security-events: write for the upload step. Inputs reach the shell only through quoted env vars, never interpolated into script text.

(The action itself has not yet been run on GitHub Actions; the CLI and adapters are tested, including with fake scanners in CI.)

Honest scope

  • Static extraction is best-effort. In a study of 90 public MCP repos it found tools in 53 (about 59%); "no tools found" prints a note and means unknown, not safe.
  • Findings are heuristics for human review. In the same study only 37.5% (95% CI 24-53%) of mcpaudit v0.6's HIGH permission_scope findings were accurate, and none of the flagged repos had genuine tool poisoning. Use the patched scanners (mcpaudit 0.7 / memsentry 1.2) for fewer false positives; see mcp-scan-study/REPORT.md.
  • mcpaudit's dynamic (live LLM) and rug-pull checks are not part of this suite; use mcpaudit directly for those.
  • Line numbers for extracted tools point at the registration call, not the description text.

Development

pip install -e ".[dev]" && pytest -q (adapter tests use in-memory fake scanners and always run; a few end-to-end tests skip unless the real scanners are installed).

Metadata

Release files for aisec-suite 0.2.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for aisec-suite 0.2.0
File Size Uploaded
aisec_suite-0.2.0.tar.gz 16.8 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for aisec-suite 0.2.0
File Interpreter ABI Platform
aisec_suite-0.2.0-py3-none-any.whl Python 3 none any Details

Total release size: 30.5 kB

Release files / aisec_suite-0.2.0.tar.gz

Download URL aisec_suite-0.2.0.tar.gz
Size 16.8 kB
Tags Source
SHA-256 checksum
How to use checksums
29a44d2b7d47363ec6100fd6ae4daf4ddcc59b2e0fe1eae6eebbe63ecf5b2099
BLAKE2b-256 checksum
How to use checksums
812b96332c709821e8cbe676af17190038e4d1b2b9a21e08eb7958af6913c4a2
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 2, 2026.

Transparency log

Release files / aisec_suite-0.2.0-py3-none-any.whl

Download URL aisec_suite-0.2.0-py3-none-any.whl
Size 13.8 kB
Tags Python 3
SHA-256 checksum
How to use checksums
586290bf17494c09a52f58b4532e62aaf30022aa9bfe7498273ef9147b3c1356
BLAKE2b-256 checksum
How to use checksums
7ed42b6d7b853e137144a8c122886ca1f21629578b6c2e62e904623fe55fdd34
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 2, 2026.

Transparency log

Release history Release notifications | RSS feed

0.3.0

2 release files

This release

0.2.0 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page