EMO-Cyber-Agent
A portable, model-agnostic, governed cybersecurity subagent for code, applications, agents, prompts, MCP, and cloud security.
Portable, model-agnostic cybersecurity sub-agent for software projects.
EMO-Cyber-Agent is designed to be installed once as a Python package and then invoked through:
- MCP for agent hosts such as coding assistants and IDE agents.
- CLI for humans, CI/CD, and agents that can execute commands.
- Python API for embedding and automation.
The project is intentionally model-agnostic. Model weights, GPU/runtime deployment, and provider-specific infrastructure are out of scope for this repository. The core product is the security methodology, agent control loop, tool contracts, evidence model, policy enforcement, and stable interfaces.
Design goals
- Portable across agent hosts.
- Read-only by default.
- Evidence-first findings: every material claim must point to evidence.
- Security-specialist behavior: the host agent delegates security work; EMO owns the security workflow.
- Deterministic tools around probabilistic reasoning.
- Verification before escalation when safe and permitted.
- Strict separation between untrusted repository content and agent instructions.
- Stable JSON schemas so MCP, CLI, and Python API return the same result model.
- Pluggable tool adapters and model providers.
- No required dependency on a particular LLM, cloud, IDE, or repository platform.
Non-goals
- Building a general-purpose coding agent.
- Bundling model weights.
- Automatic production changes by default.
- Replacing SAST, SCA, secret scanners, DAST, runtime security, or human security review.
- Exploit development or offensive operation against systems without explicit authorization.
Repository map
EMO-Cyber-Agent/
├── docs/ # Specifications and implementation plan
├── src/emo_cyber_agent/ # Package skeleton
├── tests/ # Unit/contract/fixture test plan
├── examples/ # Integration examples
├── scripts/ # Developer utilities
├── .github/workflows/ # CI templates
├── pyproject.toml
├── .env.example
└── Makefile
Development status
Core engine (domain, policy, tools, evidence, reasoning, verification,
findings, reporting) plus MCP and CLI adapters are implemented and tested
according to docs/16-implementation-plan.md. Progress is recorded per
task in reports/development/ECA-T*.md.
Installation
pip install emo-cyber
cyber-agent --help
Optional isolation:
pipx install emo-cyber
From source (developers):
pip install -e '.[all]' # package + MCP/HTTP/dev extras
Quickstart
cyber-agent audit . --format json > result.json
cyber-agent report --findings findings.json --audit-id <id> --format markdown
cyber-agent mcp # stdio server for MCP hosts (OpenCode, Hermes, pi, Cline, VS Code, …)
Commands
cyber-agent doctor # operational presence checks (no secrets printed)
cyber-agent audit <target> [--mode quick|standard|deep] [--focus a,b] [--format human|json]
cyber-agent review <target> [--focus a,b] [--format human|json]
cyber-agent verify --candidate cand.json --method <m> --kind <k> --locator <loc> --rationale <r> --audit-id <id>
cyber-agent status <audit_id> # read-only; unknown audits report NOT_FOUND
cyber-agent report --findings findings.json --audit-id <id> --format json|jsonl|markdown
cyber-agent mcp # MCP stdio server (thin adapter over Core)
Only implemented options exist — there are no --shell, --exec,
--grant, --sudo, --allow-write, or --bypass-policy flags, and no
--github-token-style secret flags (use environment/secret providers).
Output formats and exit codes
--format jsonemits machine-readable JSON on stdout; diagnostics go to stderr, socyber-agent audit . --format json > result.jsonstays clean.- Findings never change the exit code; command status and security results are separate concerns.
0 SUCCESS · 1 AUDIT/DOMAIN FAILURE · 2 INVALID INPUT · 3 POLICY DENIED ·
4 SECURITY BLOCKED · 5 PROVIDER/TOOL UNAVAILABLE · 6 VERIFICATION
INCONCLUSIVE · 7 INTERNAL ERROR · 130 interrupted (POSIX standard)
CI example
cyber-agent audit . --format json > result.json
python -c "import json; print(json.load(open('result.json'))['result']['status'])"
Security model
Read-only by default; repository content is untrusted data; no material finding without evidence; no destructive action without an explicit permission transition; MCP and CLI are thin adapters — Core decides, tools prove, verification confirms, reporting projects.
Progress is advisory-only (never authorizes actions). Recovery is bounded
and fail-closed (POLICY_DENIED / INTEGRITY_FAILURE never retry).
Host-supplied context is untrusted until scope-bound by Core/Policy.
Host integration
Register EMO once as an MCP server, then delegate security work from any
compatible host. Full per-host guides live in docs/integrations/.
{ "mcpServers": { "emo-cyber-agent": { "command": "cyber-agent", "args": ["mcp"] } } }
| Host | Status |
|---|---|
| Generic MCP host (stdio) | Contract Tested |
| OpenCode | Supported (config), Contract Tested discovery |
| Pi (stdio / Streamable HTTP) | Supported (config), project-scoped |
| Hermes (per-server filtering) | Supported (config), least-surface guidance |
| Jan (Desktop + Agent/CLI shared config) | Supported (config) |
| AnythingLLM (workspace/RAG = untrusted inputs) | Supported (config), boundary guidance |
Levels: Supported = config + mapping shipped; Contract Tested = in-repo
contract tests; Environment Tested = live binary exercised (where available);
otherwise Not Tested — see docs/integrations/ per host.
Limitations
Read-only analysis; no auto-remediation, no exploit capabilities, no scores-as-verdicts. Live-host interop beyond contract tests is environment-dependent (see host docs). Progress never gates security decisions; recovery never mutates policy, evidence, or findings.
Metadata
Release files for emo-cyber 0.1.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| emo_cyber-0.1.0.tar.gz | 982.8 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| emo_cyber-0.1.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 1.7 MB
Release files / emo_cyber-0.1.0.tar.gz
| Download URL | emo_cyber-0.1.0.tar.gz |
|---|---|
| Size | 982.8 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
69274781793e21629b1a83f122baf28c5b33f85c854020bee36de2c3d836d0c1
|
|
BLAKE2b-256 checksum How to use checksums |
3f1e7dbcc654effb698a7181b116ba7953e07a38ed075ae5ebf8c5ac0965ec7f
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 6, 2026.
Transparency logRelease files / emo_cyber-0.1.0-py3-none-any.whl
| Download URL | emo_cyber-0.1.0-py3-none-any.whl |
|---|---|
| Size | 698.7 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
0b9e35b7401807f42dd6c9fde55e132ff706dbc64f48f2aa34197eea9addf4ab
|
|
BLAKE2b-256 checksum How to use checksums |
5e564a44a2f2d02844acb03f1500a98cf104f70e1533d6aa301255e201556c89
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 6, 2026.
Transparency log