A zero-dependency, standards-anchored AI security toolkit that any developer or security reviewer can run in seconds — in the IDE, in CI, or from the terminal.
Quick start · The bundle · How it works · Standards · In your IDE · Honest limits · Contributing
"Stop trying to build a model that cannot be fooled. Build the system around it, so that when the model is fooled — and it will be — nothing important breaks."
Grey Panda makes the secure path the easy path for anyone building LLM-powered, agentic, or Model Context Protocol (MCP) features — from a solo indie developer to an enterprise AppSec team.
⚡ Quick start
pip install grey-panda # pure Python, zero dependencies
gp scan . # scan your repo — real findings, beautiful report
Add drop-in guardrails to an existing LLM call in under two minutes — you never rewrite the call, you wrap it:
from greypanda import PromptGuardrail, DLPScanner, OutputGuardrail
guard, dlp, out = PromptGuardrail(), DLPScanner(), OutputGuardrail()
safe = guard.assert_safe(user_input) # block known injection + strip invisible Unicode
clean = dlp.redact(safe) # remove PII & secrets before the model sees them
reply = call_your_llm(clean) # ← your existing call, unchanged
answer = out.sanitize(reply).sanitized_text # neutralise XSS constructs + exfil URLs (escape_html=True to fully escape)
🎯 Why this exists
Prompt injection is the #1 AI attack pattern and it needs no authentication (OWASP LLM01). Agentic systems can take an irreversible action from a single injected instruction. And MCP has opened a whole new surface — tool poisoning and rug pulls. Your existing AppSec tools don't see any of it.
🐼 The idea: one calm guardian
Grey Panda keeps two rare qualities as non-negotiable: intellectual honesty (a whole doc on what it can and cannot do) and standards-anchoring (every rule cites an OWASP ID). No neon-hacker theatre — just controls that are a joy to adopt.
📦 What's in the bundle
Five audience-facing module kits, all powered by one shared, zero-dependency engine:
| Kit | For | Start here |
|---|---|---|
| 🧰 Module 1 — Developer Kit | Building AI features | Drop-in SDK + IDE integration |
| 🛡️ Module 2 — Security Reviewer Kit | Reviewing / gating | AISVS verify, threat models, sign-off |
| 🔍 Module 3 — Scanner & CI/CD Kit | Platform / DevOps | 26 rules, SARIF, GitHub Action |
| 🤖 Module 4 — MCP & Agent Security Kit | Agents & MCP | Rule of Two, HITL, manifest pinning, ACS |
| 📚 Module 5 — Standards & Governance Kit | Everyone / compliance | Knowledge pack, mappings, Can/Cannot-Do |
⚙️ How it works
Defense in depth, not prevention theatre. Full walkthrough: HOW-TO-add-guardrails · architecture: docs/ARCHITECTURE.md.
🔐 Standards-anchored
Every rule, checklist item, and SDK control cites a specific ID. Explore any control from the CLI:
gp standards LLM01:2026 # explain a control + its Grey Panda fix
gp standards # list every standard and control ID
Full mapping tables: Module 5 → mappings/.
✅ Proof
See the before/after for yourself — the same app, insecure vs. rebuilt with Grey Panda controls:
gp scan examples/vulnerable_app --profile enterprise # 🔴 findings
gp scan examples/secure_app --profile enterprise # ✅ clean
👥 For everyone
gp scan . --profile solo # high-signal core, fail on CRITICAL
gp init . --profile team # scaffold config + GitHub Action + pre-commit
gp verify . --level 2 # AISVS Level 2 verification report
More: Module 1 → PROFILES.
🚀 Get started
pip install grey-panda # from PyPI
pipx install grey-panda # isolated CLI
uvx grey-panda scan . # zero-install run
| Command | Does |
|---|---|
gp scan [path] |
Scan for AI/agent/MCP issues (--profile, --format md/json/sarif, --fail-on) |
gp init [path] |
Scaffold config, GitHub Action, and pre-commit into a repo |
gp verify [path] |
AISVS Level 1/2/3 verification report |
gp checklist |
Print the AI security checklist |
gp standards [id] |
List or explain standards / control IDs |
gp agbom <agent> |
Emit an Agent Bill of Materials |
gp mcp |
Run Grey Panda as an MCP server (stdio) |
gp doctor |
Environment self-check + honest-limits pointer |
🤝 In your IDE
Grey Panda secures MCP — and ships as an MCP server, so Claude Code, Cursor, Windsurf, or VS Code can call it while you code:
{ "mcpServers": { "grey-panda": { "command": "gp", "args": ["mcp"] } } }
Then ask your assistant to "review this file with grey panda" or "explain LLM03". Details: Module 1 → HOW-TO-use-in-your-ide and Module 4 → HOW-TO-run-the-mcp-server.
🧭 Honest about limits
Grey Panda is a strong floor, not a ceiling. Pattern matching cannot stop all prompt injection; regex DLP is language-specific; static analysis has false positives and negatives. We ship a whole document — with a confidence level and failure condition for every capability: WHAT_IT_CAN_AND_CANNOT_DO.md. Read it before you rely on the tool.
🌱 Contributing
Adding a scanner rule is editing one dataclass with a bad + good example — see CONTRIBUTING.md and Module 3 → HOW-TO-write-a-rule. Everyone is welcome under our Code of Conduct. Found a vulnerability in Grey Panda itself? See SECURITY.md.
Build from source:
git clone https://github.com/dibakshya01/grey-panda && cd grey-panda
pip install -e ".[dev]"
python -m unittest discover -s tests # zero-dependency test suite
gp scan . --profile enterprise --fail-on HIGH # Grey Panda scans itself, clean
📄 License
Apache-2.0. Standards cited are the property of their respective authors (see NOTICE). OWASP® is a registered trademark of the OWASP Foundation; Grey Panda is an independent, community project and is not affiliated with or endorsed by OWASP.
🐼 Grey Panda — make the secure path the easy path.
Metadata
Release files for grey-panda 1.0.2
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| grey_panda-1.0.2.tar.gz | 117.5 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| grey_panda-1.0.2-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 193.8 kB
Release files / grey_panda-1.0.2.tar.gz
| Download URL | grey_panda-1.0.2.tar.gz |
|---|---|
| Size | 117.5 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
e83a0cda20925de871619614539aaf10ccfd03bb39b3cd5e5f97cc580565ee1f
|
|
BLAKE2b-256 checksum How to use checksums |
91a67ee7166782a46b24f3773ceef76ed461910fbc9e32c24522663f2d971c0f
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/6.2.0 CPython/3.9.6
|
Release files / grey_panda-1.0.2-py3-none-any.whl
| Download URL | grey_panda-1.0.2-py3-none-any.whl |
|---|---|
| Size | 76.3 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
cbb6937675df3b05974186021f0c5c91a0e5c6fb1f8d6ff3e906595ca50aa057
|
|
BLAKE2b-256 checksum How to use checksums |
fa07b9302199d79f6f6da21059c4de23e10cead02ddf1ca9659f309daf00e3d6
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/6.2.0 CPython/3.9.6
|