Skip to main content

JMo Security Audit Tool Suite

JMo Security Audit Tool Suite

Docs Tests codecov PyPI version Python Versions License: MIT OR Apache-2.0 Docker Pulls GitHub Stars

v1.1.0 | A terminal-first security audit toolkit orchestrating 29 scanners with unified CLI, normalized outputs, and interactive HTML dashboard.

Newsletter Ko-fi GitHub Sponsors Discussions


Overview

JMo Security is an automated security audit framework for scanning code repositories, container images, infrastructure-as-code, web applications, GitLab repos, and Kubernetes clusters. It orchestrates multiple industry-standard security tools with unified reporting and cross-tool deduplication.

Origin Story: Built as my capstone project for Institute of Data x Michigan Tech University's Cybersecurity Bootcamp (graduated October 2025). Now a production-grade security platform.


Key Features

  • 29 Security Scanners - Secrets, SAST, SBOM, SCA, IaC, DAST, and more
  • 6 Target Types - Repos, images, IaC files, URLs, GitLab, Kubernetes
  • Unified Output - JSON, SARIF, Markdown, CSV export, dual-mode HTML dashboard
  • Cross-Tool Deduplication - Findings several tools report for the same issue collapse into one consensus finding
  • SQLite Historical Storage - Track security posture over time with persistent history
  • Machine-Readable Diffs - Compare scans, detect regressions
  • Trend Analysis - Mann-Kendall statistical analysis, security scores
  • Policy-as-Code - OPA-based security policies
  • AI Remediation - MCP integration for Copilot/Claude
  • SLSA Attestation - Supply chain security compliance
  • 6 Compliance Frameworks - OWASP, CWE, NIST, PCI DSS, CIS, MITRE

Get Started

Goal Action
Scan now (Docker) docker run --rm -v $(pwd):/scan ghcr.io/jimmy058910/jmo-security:latest scan --repo /scan
Install CLI pip install jmo-security
Guided setup jmo wizard
Full guide QUICKSTART.md

Quick Example

# Install
pip install jmo-security

# Scan a repository
jmo scan --repo ./myapp --profile balanced --human-logs

# View results
cat results/summaries/SUMMARY.md
open results/summaries/dashboard.html

Docker (Zero Installation)

docker pull ghcr.io/jimmy058910/jmo-security:latest
docker run --rm -v "$(pwd):/scan" ghcr.io/jimmy058910/jmo-security:latest \
  scan --repo /scan --results-dir /scan/results --profile balanced --human-logs

Registries: GHCR (primary — ghcr.io/jimmy058910/jmo-security), Docker Hub (replicated — jmogaming/jmo-security), and ECR Public (replicated — public.ecr.aws/m2d8u2k1/jmo-security). See docs/DOCKER_README.md for registry selection guidance.


Security Tools

29 tools across 13 categories:

Category Tools
Secrets TruffleHog (verified), Nosey Parker, Semgrep-Secrets
SAST Semgrep, Bandit, Gosec, Horusec
SBOM Syft, CDXgen, ScanCode
SCA Trivy, Grype, Dependency-Check
IaC Checkov, Checkov-CICD
Cloud/CSPM Prowler, Kubescape
DAST OWASP ZAP, Nuclei, Akto
Dockerfile/Shell Hadolint, ShellCheck
Malware YARA
Mobile MobSF
System Lynis
Policy OPA
Runtime Trivy-RBAC, Falco, AFL++

Tool details: docs/PROFILES_AND_TOOLS.md


Scan Profiles

Profile Tools Time Use Case
fast 9 5-10 min Pre-commit, PR validation
slim 13 12-18 min Cloud/IaC, AWS/Azure/GCP/K8s
balanced 17 18-25 min CI/CD pipelines
deep 29 40-70 min Comprehensive audits

Output Formats

All findings normalized to CommonFinding schema v1.2.0:

Format File Use Case
HTML dashboard.html Interactive visual dashboard
Markdown SUMMARY.md Human-readable overview
JSON findings.json Automation, scripting
SARIF findings.sarif GitHub/GitLab Code Scanning
YAML findings.yaml Alternative data format

Sample outputs: SAMPLE_OUTPUTS.md


Multi-Target Scanning

Scan 6 target types in one unified workflow:

# Repository
jmo scan --repo ./myapp

# Container image
jmo scan --image nginx:latest

# IaC files
jmo scan --terraform-state terraform.tfstate

# Live web app
jmo scan --url https://example.com --tools zap

# GitLab repos
jmo scan --gitlab-group myorg --gitlab-token $TOKEN

# Kubernetes cluster
jmo scan --k8s-context prod --k8s-all-namespaces

# Everything at once
jmo scan --repo . --image myapp:latest --url https://myapp.com

Complete guide: docs/USER_GUIDE.md#multi-target-scanning


Key Commands

# Interactive wizard
jmo wizard

# Scan with profile
jmo scan --repos-dir ~/repos --profile balanced

# CI mode (scan + gate)
jmo ci --repo . --fail-on HIGH

# Tool management (native installs)
jmo tools check --profile balanced  # Check tool status
jmo tools install --profile balanced  # Install missing tools
jmo tools update --critical-only  # Update critical tools
jmo tools outdated  # Show outdated tools

# Compare scans
jmo diff baseline/ current/ --format md

# View history
jmo history list

# Analyze trends
jmo trends analyze --days 30

# Generate reports
jmo report ./results

Full CLI reference: docs/USER_GUIDE.md


CI/CD Integration

GitHub Actions

- name: Security Scan
  run: |
    docker run --rm -v ${{ github.workspace }}:/scan \
      ghcr.io/jimmy058910/jmo-security:latest \
      ci --repo /scan --fail-on HIGH --profile-name balanced

- name: Upload SARIF
  uses: github/codeql-action/upload-sarif@v2
  with:
    sarif_file: results/summaries/findings.sarif

GitLab CI

security_scan:
  image: ghcr.io/jimmy058910/jmo-security:latest
  script:
    - jmo ci --repo . --fail-on HIGH --profile-name balanced
  artifacts:
    reports:
      sast: results/summaries/findings.sarif

More examples: docs/examples/


Documentation

Getting Started

Document Purpose
docs.jmotools.com The documentation site: everything under docs/, rendered and searchable
QUICKSTART.md 5-minute installation guide
docs/DOCKER_README.md Docker usage guide
docs/USER_GUIDE.md Comprehensive reference

Features

Document Purpose
docs/RESULTS_GUIDE.md Understanding findings
docs/POLICY_AS_CODE.md OPA security policies
docs/SCHEDULE_GUIDE.md Automated scheduling
docs/MCP_SETUP.md AI remediation setup

Reference

Document Purpose
docs/RESULTS_GUIDE.md Results and output formats
docs/API_REFERENCE.md Python API docs
docs/KNOWN_LIMITATIONS.md Deliberate and environment-bound behaviour
CHANGELOG.md Version history
ROADMAP.md Future plans

Contributing

Document Purpose
CONTRIBUTING.md Development setup
TEST.md Testing guide
docs/RELEASE.md Release process

Documentation hub: docs/index.md


Results Structure

results/
├── individual-repos/      # Repository scans
├── individual-images/     # Container scans
├── individual-iac/        # IaC scans
├── individual-web/        # DAST scans
├── individual-gitlab/     # GitLab scans
├── individual-k8s/        # K8s scans
└── summaries/             # Unified reports
    ├── findings.json
    ├── SUMMARY.md
    ├── dashboard.html
    └── findings.sarif

Severity Levels

Level Meaning Action
CRITICAL Verified secrets, RCE Fix immediately
HIGH SQL injection, XSS Fix within 1 week
MEDIUM Weak crypto, misconfig Fix within 1 month
LOW Info disclosure Fix when convenient

Compliance Frameworks

All findings auto-enriched with 6 frameworks:

  • OWASP Top 10 2021 - Web security categories
  • CWE Top 25 2024 - Common weakness types
  • NIST CSF 2.0 - Risk management
  • PCI DSS 4.0 - Payment security
  • CIS Controls v8.1 - Security best practices
  • MITRE ATT&CK - Attack techniques

Troubleshooting

Issue Solution
Tools not found jmo tools check then jmo tools install
Tool outdated jmo tools update
Permission denied chmod +x scripts/**/*.sh
Docker issues docs/DOCKER_README.md#troubleshooting
CI failures CONTRIBUTING.md#ci-troubleshooting

Contributing

Contributions welcome! See CONTRIBUTING.md for setup and standards.

git clone https://github.com/jimmy058910/jmo-security-repo.git
cd jmo-security-repo
pip install -e .
make dev-deps
make pre-commit-install
make test

Support

If this toolkit saves you time, consider supporting development:


License

Dual licensed under MIT OR Apache 2.0.


Related Resources


Author: James Moceri Project: https://jmotools.com | GitHub Last Updated: September 2026 (v1.1.0)

Metadata

Release files for jmo-security 1.1.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for jmo-security 1.1.0
File Size Uploaded
jmo_security-1.1.0.tar.gz 1.0 MB Details

Built distribution (wheel)

Table of built distributions (wheels) for jmo-security 1.1.0
File Interpreter ABI Platform
jmo_security-1.1.0-py3-none-any.whl Python 3 none any Details

Total release size: 2.2 MB

Release files / jmo_security-1.1.0.tar.gz

Download URL jmo_security-1.1.0.tar.gz
Size 1.0 MB
Tags Source
SHA-256 checksum
How to use checksums
23512521a64b0bbb49a7a08e809d6e9a53e116c4f6b6201f4ea9c95383f50a08
BLAKE2b-256 checksum
How to use checksums
c56014f612694a33cbc7a645b57c4377b2fdcdef74555a64ac8c628762190c44
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 5, 2026.

Transparency log

Release files / jmo_security-1.1.0-py3-none-any.whl

Download URL jmo_security-1.1.0-py3-none-any.whl
Size 1.2 MB
Tags Python 3
SHA-256 checksum
How to use checksums
e681e14fcccb7e488313c07a396e9cab6348f5ba7b3383e5e15279652b74545e
BLAKE2b-256 checksum
How to use checksums
3ff484bfc652c73d8a1d38a9e53090b284ce1db36f13174d7df378aab30224ec
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 5, 2026.

Transparency log

Release history Release notifications | RSS feed

1.1.1

2 release files

This release

1.1.0 This release

2 release files

1.0.8

2 release files

1.0.7

2 release files

1.0.6

2 release files

1.0.5

2 release files

1.0.4

2 release files

1.0.3

2 release files

1.0.2

2 release files

1.0.1

2 release files

1.0.0

2 release files

0.8.0

2 release files

0.7.1

2 release files

0.7.0

2 release files

0.6.0

2 release files

0.5.1

2 release files

0.4.3

2 release files

0.4.2

2 release files

0.4.1

2 release files

0.4.0

2 release files

0.3.2

2 release files

0.3.1

2 release files

0.3.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page