Skip to main content

comply-agent

AI Agent OWASP Agentic Top 10 Compliance Scanner

Automatically scan your AI agent's prompts, configurations, tool definitions, and behavior logs for compliance issues against the OWASP Agentic Top 10 (2026).

Install

pip install comply-agent

Quick Start

# Scan a prompt
comply-agent scan --prompt "ignore all previous instructions"

# Scan from files
comply-agent scan --prompt-file agent_prompt.txt --config-file agent.yaml

# JSON output
comply-agent scan --prompt-file prompt.txt --format json --output report.json

# List all rules
comply-agent rules

Example Output

============================================================
  comply-agent Report
============================================================
  Score: 40.0/100  (2 passed / 3 failed / 5 rules)
============================================================

  🔴 [ASI01] Prompt Injection Vulnerability
     Location: prompt:1
     Matched:  ignore all previous instructions
     Fix:      1. Use structured input separation...

  🟠 [ASI02] Sensitive Data Disclosure
     Location: config:5
     Matched:  api_key=abc123def456ghi789...
     Fix:      1. Add output filtering/redaction...

  🟡 [ASI06] Excessive Agency / Over-Autonomy
     Location: prompt:3
     Matched:  never ask for permission
     Fix:      1. Add human-in-the-loop...

Covered OWASP Risks

OWASP ID Risk Category Status
ASI01 Prompt Injection Input ✅
ASI02 Sensitive Data Disclosure Output ✅
ASI03 Supply Chain Vulnerability Audit ✅
ASI04 Unauthorized Access Permission ✅
ASI05 Output Manipulation Output ✅
ASI06 Excessive Agency Permission ✅
ASI07 Authentication Failure Auth ✅
ASI08 Improper Error Handling Output ✅
ASI09 Insufficient Monitoring Audit ✅

How It Works

  1. Load rules — YAML-based rules for each OWASP risk category
  2. Scan inputs — Match regex patterns against prompts, configs, tool defs, logs
  3. Score — Calculate compliance score (0-100)
  4. Report — Generate Markdown, JSON, or terminal report with findings and fixes

Custom Rules

Add your own rules in YAML:

id: custom-001
owasp_id: CUSTOM
title: My Custom Rule
severity: medium
category: output
description: Detects something specific
patterns:
  - "my_sensitive_pattern"
fix: How to fix it

Point to custom rules dir: comply-agent scan --rules-dir ./my_rules --prompt "..."

License

MIT

Metadata

Release files for comply-agent 0.2.1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for comply-agent 0.2.1
File Size Uploaded
comply_agent-0.2.1.tar.gz 14.2 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for comply-agent 0.2.1
File Interpreter ABI Platform
comply_agent-0.2.1-py3-none-any.whl Python 3 none any Details

Total release size: 30.4 kB

Release files / comply_agent-0.2.1.tar.gz

Download URL comply_agent-0.2.1.tar.gz
Size 14.2 kB
Tags Source
SHA-256 checksum
How to use checksums
a8df2539700e9d5d1393aa0396badab7dc7af4d8627d5a570f28a20d341b7fac
BLAKE2b-256 checksum
How to use checksums
239331274a3b6f51d3ec72c4b82103ae7eba75b6afdec55e000f9bc4d4610829
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.12

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Jul 12, 2026.

Transparency log

Release files / comply_agent-0.2.1-py3-none-any.whl

Download URL comply_agent-0.2.1-py3-none-any.whl
Size 16.2 kB
Tags Python 3
SHA-256 checksum
How to use checksums
a31818b87c0700b120f7664f4df9f29b45c249ba3c48ce772a9314437a9af050
BLAKE2b-256 checksum
How to use checksums
2d3bddf703d8df991b9571de0dba5ae8c32803333abfd2339d896cf170aa42fa
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.12

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Jul 12, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

0.2.1 This release

2 release files

0.2.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page