Skip to main content

AI security review agent for code, plans, and infrastructure

Project description

hiro-agent

AI security review agent for code, plans, and infrastructure.

What this project does

  • Reviews code diffs for security issues
  • Reviews implementation plans with threat-modeling prompts
  • Reviews infrastructure configs for security misconfigurations
  • Scans repositories with multi-skill, wave-based security investigations (experimental)

It integrates with Claude Code, Cursor, VSCode Copilot, and Codex CLI to enforce review workflows before commits and plan finalization.

Install

# Recommended (isolated environment, works on macOS/Linux)
pipx install hiro-agent

# Or with pip in a virtual environment
pip install hiro-agent

Quick Start

# Set up hooks for your AI coding tools
hiro setup

# Review code changes
git diff | hiro review-code

# Review an implementation plan
cat plan.md | hiro review-plan

# Review infrastructure configuration
hiro review-infra main.tf

# Experimental: full-repo scan
hiro scan

Commands

Command Description
hiro review-code Security review of code changes (stdin: git diff)
hiro review-plan STRIDE threat model review of a plan (stdin)
hiro review-infra IaC security review (file arg or stdin)
hiro scan Full-repo multi-skill security scan (experimental/beta)
hiro chat "<question>" Ask security questions about current repo
hiro setup Auto-detect and configure all AI coding tools
hiro upgrade Update installed hooks/configs to latest package behavior
hiro verify Verify hook integrity against installed version

Setup Options

hiro setup                # Auto-detect all tools
hiro setup --claude-code  # Claude Code only
hiro setup --cursor       # Cursor only
hiro setup --vscode       # VSCode Copilot only
hiro setup --codex        # Codex CLI only

Configuration

Set HIRO_API_KEY to connect to the Hiro platform for organizational context (security policies, memories, org profile). Without it, reviews still run using your ANTHROPIC_API_KEY directly.

export HIRO_API_KEY=hiro_ak_...     # Optional: Hiro platform context
export ANTHROPIC_API_KEY=sk-ant-... # Required if HIRO_API_KEY not set

More details: docs/configuration.md

How It Works

  1. hiro setup installs hook scripts in .hiro/hooks/ and configures your AI coding tool to call them
  2. Hooks track file modifications and block commits until hiro review-code has run
  3. Hooks track plan creation and block finalization until hiro review-plan has run
  4. Review agents use claude-agent-sdk to spawn a Claude instance that performs the security review
  5. When connected to Hiro (HIRO_API_KEY), reviews are enriched with your org's security policy, accepted risks, and architecture context

Stability

  • Primary/release-gated workflows: review-code, review-plan
  • Secondary workflow: review-infra
  • Experimental workflow: scan

Architecture and Methodology

  • Architecture: docs/architecture.md
  • Scan methodology: docs/scan-methodology.md
  • Troubleshooting: docs/troubleshooting.md
  • Development: docs/development.md

Contributing

  • Contribution guide: CONTRIBUTING.md
  • Code of conduct: CODE_OF_CONDUCT.md
  • Security reporting: SECURITY.md

License

MIT

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

hiro_agent-0.1.11.tar.gz (115.6 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

hiro_agent-0.1.11-py3-none-any.whl (65.8 kB view details)

Uploaded Python 3

File details

Details for the file hiro_agent-0.1.11.tar.gz.

File metadata

  • Download URL: hiro_agent-0.1.11.tar.gz
  • Upload date:
  • Size: 115.6 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.12

File hashes

Hashes for hiro_agent-0.1.11.tar.gz
Algorithm Hash digest
SHA256 f8078d2264e3e78fe0ab3aa58e454091b814bf618bbc468094216f740e6b5496
MD5 7d8bd7f04d5b52b5b7ba812f9700ad41
BLAKE2b-256 da406972e1c3cfbf94333dc39d6f498edf4686afdd77d759f42778de29d75e52

See more details on using hashes here.

Provenance

The following attestation bundles were made for hiro_agent-0.1.11.tar.gz:

Publisher: publish.yml on telophasehq/hiro-agent

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file hiro_agent-0.1.11-py3-none-any.whl.

File metadata

  • Download URL: hiro_agent-0.1.11-py3-none-any.whl
  • Upload date:
  • Size: 65.8 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.12

File hashes

Hashes for hiro_agent-0.1.11-py3-none-any.whl
Algorithm Hash digest
SHA256 7a5e1c9eed5b31b945476c3ba7d63d51fa682a9f0616158c67e639f246ce5acb
MD5 7928c3258fd9f3467d70e258af55ace0
BLAKE2b-256 574cc33e1b027401f6628cfdd61e54b74fcd3a6c2a9b4cbc957397a5a454b31d

See more details on using hashes here.

Provenance

The following attestation bundles were made for hiro_agent-0.1.11-py3-none-any.whl:

Publisher: publish.yml on telophasehq/hiro-agent

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page