igris
Security scanner for AI agent workflows.
Find vulnerabilities in LangChain, CrewAI, OpenAI Agents SDK, and other AI agent frameworks before attackers do.
What It Does
igris connects to running AI agents and tests them for security vulnerabilities:
- Prompt Injection — Can attackers override the agent's instructions?
- System Prompt Extraction — Can attackers leak the agent's configuration?
- Jailbreaks — Can attackers bypass safety guardrails?
- Tool Abuse — Can attackers make the agent misuse its tools?
- Multi-Turn Escalation — Can attackers manipulate the agent over conversation?
Quick Start
# Install
pip install igris
# Scan an agent
igris scan --http http://localhost:8000/chat
# Map agent capabilities
igris map --http http://localhost:8000/chat
Example Output
🔒 Scan Starting
Target: http://localhost:8000/chat
✓ Connected successfully
Discovering agent capabilities...
File Access: ✓
Code Execution: ✓
Web Access: ✗
Memory: ✓
Running security scans...
🚨 Found 4 Vulnerabilities
Critical: 1 High: 2 Medium: 1 Low: 0
┏━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━┓
┃ Severity ┃ Title ┃ Category ┃ Confidence ┃
┡━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━┩
│ CRITICAL │ Dangerous Tool Execution │ tool_abuse │ confirmed │
│ HIGH │ System Prompt Extraction │ prompt_injection │ likely │
│ HIGH │ Multi-Turn Escalation │ multi_turn │ confirmed │
│ MEDIUM │ Potential Override │ prompt_injection │ possible │
└──────────┴──────────────────────────┴──────────────────┴────────────┘
Installation
pip install igris
Or with AI-powered analysis:
pip install igris[ai]
Usage
Scan an Agent
# Basic scan
igris scan --http http://localhost:8000/chat
# With authentication
igris scan --http https://api.example.com/agent --auth "Bearer sk-xxx"
# Save report
igris scan --http http://localhost:8000/chat --output report.json
# Verbose output
igris scan --http http://localhost:8000/chat --verbose
Map Agent Architecture
# Discover what the agent can do
igris map --http http://localhost:8000/chat
Supported Frameworks
igris works with any AI agent that exposes an HTTP endpoint:
- ✅ LangChain / LangGraph
- ✅ CrewAI
- ✅ OpenAI Agents SDK
- ✅ AutoGen
- ✅ Custom agents
Why igris?
Traditional security tools test code. igris tests behavior.
AI agents make decisions at runtime. They interpret instructions, choose tools, and act on user input. Static analysis can't find these bugs — you need to actually talk to the agent and see what it does.
igris does exactly that: sends adversarial inputs, observes agent behavior, and reports when the agent does something dangerous.
From the Creator of mcpsec
igris is built by the creator of mcpsec, which has reported 12+ vulnerabilities ranging from Medium to Critical severity in popular MCP implementations.
Same approach, one layer up: mcpsec tests MCP servers (the transport layer), igris tests agent workflows (the orchestration layer).
License
MIT
Author
Manthan Ghasadiya
- GitHub: @manthanghasadiya
- LinkedIn: linkedin.com/in/man-ghasadiya
Release files for igris 0.2.3
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| igris-0.2.3.tar.gz | 36.5 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| igris-0.2.3-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 76.7 kB
Release files / igris-0.2.3.tar.gz
| Download URL | igris-0.2.3.tar.gz |
|---|---|
| Size | 36.5 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
7ceb2a7fa883cc472d9e1c165528da69774693ca4016ab6f021619b8a2c418fa
|
|
BLAKE2b-256 checksum How to use checksums |
562011f603187e18c1083dc4e771870019ae99edbbcb2c49ab9d0a59b2f0e2c4
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/6.2.0 CPython/3.13.12
|
Release files / igris-0.2.3-py3-none-any.whl
| Download URL | igris-0.2.3-py3-none-any.whl |
|---|---|
| Size | 40.3 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
6510544bbf25b02bf1934e2848e472e8f69776815289b1ff570dfb78d1c65b57
|
|
BLAKE2b-256 checksum How to use checksums |
faf7ccd3fa55aaf8da8a0ec22691997cf2bbc63108604a1a36a21109ff40486d
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/6.2.0 CPython/3.13.12
|