audit-packs-ai
audit-packs-ai provides AI-powered consensus adjudication, composite confidence scoring, and false-positive filtering for the audit-packs ecosystem.
⚠️ IMPORTANT: This is a sub-package of the
audit-packscompliance mapping toolkit. It is NOT designed to be run as a standalone CLI tool. If you are looking for the main CLI and GitHub Action scanner execution engine, please install and refer to audit-packs.
📦 Installation
To install this package with core dependencies:
pip install audit-packs-ai
To install with full LLM SDK dependencies (for OpenAI, Anthropic, and Google APIs):
pip install 'audit-packs-ai[ai]'
🤖 The AI Consensus Ensemble
To resolve the high noise and false-positive rates of typical static security tools, audit-packs-ai passes each finding through a multi-agent debate before applying a confidence gate:
- Detector: Establishes initial compliance relevance and confidence.
- Verifier: Builds the argument proving the compliance check is violated.
- Adversarial: Builds the argument defending why this check is a false positive under local configuration context.
- Judge: Moderates the debate, analyzes the code/environment context, and issues a final consensus confidence score.
📊 Confidence Scoring Weights
The engine scores compliance findings by weighting six distinct telemetry signals:
| Signal | Weight | Source |
|---|---|---|
| Rule Confidence | 20% | Built-in confidence metadata from the static engine rule. |
| Data-Flow Confidence | 20% | Flow-sensitivity analysis on variables (source-to-sink). |
| Model Consensus | 25% | Final consensus score output by the LLM Judge. |
| Evidence Confidence | 15% | Richness and presence of code context and lines. |
| Control Severity | 10% | Criticality score of the mapped compliance control. |
| Historical Precision | 10% | Long-term precision metrics tracked for the rule ID. |
🛠️ API Surface & Modules
| Module | Key API Exports | Description |
|---|---|---|
audit_packs_ai.adjudicate |
adjudicate(), load_model_config() |
Executes the multi-agent LLM debate for one ControlFinding; loads and validates the model routing config. |
audit_packs_ai.confidence |
score_finding(), apply_confidence_gate() |
Evaluates composite confidence scores and filters findings. |
📦 Ecosystem Architecture
audit-packs is built as a modular ecosystem consisting of five Python packages:
| Package | PyPI Link | Role | Standalone? |
|---|---|---|---|
audit-packs |
pypi | Main CLI & Action entrypoint | Yes |
audit-packs-core |
pypi | Primitives, diff parsing, normalization | No |
audit-packs-mapping |
pypi | Compliance pack loader & OSCAL exporter | No |
audit-packs-evidence |
pypi | Evidence collectors & heuristic agents | No |
audit-packs-ai |
pypi | LLM consensus & confidence scoring | No |
🔗 Related Resources
- Main GitHub Repository: https://github.com/prakharsingh/audit-packs
- Documentation & Setup: docs/SETUP.md
- Issue Tracker: https://github.com/prakharsingh/audit-packs/issues
📄 License
This library is licensed under the Apache-2.0 License. See the LICENSE file in the main repository for details.
Metadata
Release files for audit-packs-ai 0.9.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| audit_packs_ai-0.9.0.tar.gz | 12.6 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| audit_packs_ai-0.9.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 23.9 kB
Release files / audit_packs_ai-0.9.0.tar.gz
| Download URL | audit_packs_ai-0.9.0.tar.gz |
|---|---|
| Size | 12.6 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
f6eccf196d7bbb3c8b8ce34ef5fe28f887c53d7113a67d14376ed388a2dbf39c
|
|
BLAKE2b-256 checksum How to use checksums |
7eb9a91fd44e584550a4a7dd406792b141257aaa76e3cd952eb267b64b9ed691
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/6.1.0 CPython/3.13.13
|
Release files / audit_packs_ai-0.9.0-py3-none-any.whl
| Download URL | audit_packs_ai-0.9.0-py3-none-any.whl |
|---|---|
| Size | 11.3 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
1e5d24be388381b6ca4136f731712c0f67c69ecf737e38c5aa0a6a365c7ae0ad
|
|
BLAKE2b-256 checksum How to use checksums |
08e2bbe9b5692bfa656170557b8390d32473cdef1bde3f34acbe18cc50708397
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/6.1.0 CPython/3.13.13
|