Skip to main content

fluidattacks-agent

Reports what a running Python workload actually imports and runs, so that a dependency inventory can say which of its findings are reachable at runtime and which are not.

It is a library, not a service. It observes the interpreter it is installed in, sends what it saw, and does nothing else. It takes no dependencies: the standard library only, because it is installed into workloads we do not own.

Installing

pip install fluidattacks-agent

That is the whole setup. A .pth file at the root of the wheel starts the probe at interpreter start, before the workload's own program runs, so nothing has to be imported or called by hand.

Turning it off

FLUIDATTACKS_AGENT=off

Also 0, false, no, disabled or none. A workload that says no pays for reading the setting and for nothing above it. Saying nothing is taken for yes, because installing the package is the consent.

What it observes

  • distributions whose modules were imported, and which modules
  • functions that were executed, where the interpreter offers that
  • how often, in windows, and when a symbol was first reached

Only what an installed distribution owns is attributed. The standard library and a workload's own first-party code produce no records.

The credential

Naming a credential and a root is what makes the probe observe at all. A workload that leaves either out starts nothing:

FLUIDATTACKS_AGENT_TOKEN_FILE a file holding the credential, preferred
FLUIDATTACKS_AGENT_TOKEN the credential itself, read only if no file is named
FLUIDATTACKS_AGENT_ROOT the nickname of the root its reports are filed under
FLUIDATTACKS_AGENT_WORKLOAD what this workload is called, optional

A file is preferred over a variable because a file can be mode 400, while an environment variable is readable by any process of the same user.

The credential is issued for a group of the platform and serves every workload of it; each workload names its root by the nickname the platform shows for it. Where reports go is fixed in the probe; no setting names an address. A credential or a root of any other shape is a misconfiguration, and the probe starts nothing rather than sign what nobody could file.

What travels, and what does not

Reports are gzipped and signed with a key derived from the credential; the credential itself never travels, appears in no record, and is in no exception. The far end must prove who it is — certificate chain and hostname both — and no redirect is followed.

What a report contains is distribution names, versions, module and function names, and counts. No arguments, no return values, no file contents, no environment.

Licence

MPL-2.0

Release files for fluidattacks-agent 0.6.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Built distributions (wheels)

Table of built distributions (wheels) for fluidattacks-agent 0.6.0
File Interpreter ABI Platform
fluidattacks_agent-0.6.0-cp311-abi3-manylinux_2_17_x86_64.whl CPython 3.11 abi3 Linux glibc 2.17+ x86-64 Details
fluidattacks_agent-0.6.0-cp311-abi3-manylinux_2_17_aarch64.whl CPython 3.11 abi3 Linux glibc 2.17+ ARM64 Details
fluidattacks_agent-0.6.0-cp311-abi3-macosx_11_0_arm64.whl CPython 3.11 abi3 macOS 11.0+ ARM64 Details

Total release size: 4.8 MB

Release files / fluidattacks_agent-0.6.0-cp311-abi3-manylinux_2_17_x86_64.whl

Download URL fluidattacks_agent-0.6.0-cp311-abi3-manylinux_2_17_x86_64.whl
Size 1.3 MB
Tags CPython 3.11 Linux glibc 2.17+ x86-64 abi3
SHA-256 checksum
How to use checksums
537b84e3ddc25baf4c18f608a3454d24c90ccccc202f467a007f86a46894f6bc
BLAKE2b-256 checksum
How to use checksums
b39b9561d3217d09dd3a39d40ab9b78906186164a34e21bd700068c30aa7f816
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via uv/0.11.11 {"installer":{"name":"uv","version":"0.11.11","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":null,"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}

Release files / fluidattacks_agent-0.6.0-cp311-abi3-manylinux_2_17_aarch64.whl

Download URL fluidattacks_agent-0.6.0-cp311-abi3-manylinux_2_17_aarch64.whl
Size 1.3 MB
Tags CPython 3.11 Linux glibc 2.17+ ARM64 abi3
SHA-256 checksum
How to use checksums
12146eecef0aa03d8c8a39b574a3aee6cb7a59b13ece98a0372852d1a18f1455
BLAKE2b-256 checksum
How to use checksums
1fc214c97ef6448e85bf68ea89aca21f75eb712c17ff947d8ae24dfb8f467db4
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via uv/0.11.11 {"installer":{"name":"uv","version":"0.11.11","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":null,"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}

Release files / fluidattacks_agent-0.6.0-cp311-abi3-macosx_11_0_arm64.whl

Download URL fluidattacks_agent-0.6.0-cp311-abi3-macosx_11_0_arm64.whl
Size 2.2 MB
Tags CPython 3.11 abi3 macOS 11.0+ ARM64
SHA-256 checksum
How to use checksums
99a56719a8c362a755f610e70401e6619dbf1256a8568352d10da7d733294029
BLAKE2b-256 checksum
How to use checksums
568fe05bfb4f3b054ae7d054684056150a0b271b3cd3e4da1674c1afe5de0904
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via uv/0.11.11 {"installer":{"name":"uv","version":"0.11.11","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":null,"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}

Release history Release notifications | RSS feed

0.6.1

3 release files

This release

0.6.0 This release

3 release files

0.5.0

3 release files

0.4.0

3 release files

0.3.0

2 release files

0.2.0

2 release files

0.1.2

2 release files

0.1.1

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page