Skip to main content

QUIET COYOTE — AI Agent Compliance Scanner

klynx-comply is an open-source CLI that scans AI agent codebases for security, governance, and safety issues before deployment. Built by KlynxAI.


Install

pip install klynx-comply

Or from source:

git clone https://github.com/klynx-ai/klynxai-assistant
cd tools/klynx-comply
pip install -e .

Quick Start

# Scan current directory
klynx-comply scan

# Scan a specific path
klynx-comply scan ./my-agent-app

# Output as JSON (for CI/CD)
klynx-comply scan --format json --output report.json

# Output as SARIF (GitHub Code Scanning, VS Code, Azure DevOps)
klynx-comply scan --format sarif --output results.sarif

# Only report HIGH and above
klynx-comply scan --severity HIGH

# Fail CI only on CRITICAL
klynx-comply scan --fail-on critical

# Run specific checks only
klynx-comply scan --checks SC-001 --checks AT-001

# List all checks
klynx-comply checks

Checks

ID Category Name Severity
SC-001 Security Hardcoded Secrets CRITICAL
AT-001 Governance Audit Trail Coverage HIGH
AG-001 Security Auth Gating on Endpoints HIGH
PII-001 Privacy PII Handling Safety HIGH
AP-001 Governance Agent Policy Envelope HIGH
HO-001 Safety Human Oversight Gates HIGH
PI-001 Security Prompt Injection Vulnerability HIGH
IV-001 Security Input Validation at Boundaries MEDIUM

CI/CD Integration

GitHub Actions

- name: Agent compliance scan
  run: |
    pip install klynx-comply
    klynx-comply scan --format sarif --output results.sarif --fail-on high

- name: Upload SARIF
  uses: github/codeql-action/upload-sarif@v3
  with:
    sarif_file: results.sarif

GitLab CI

comply:
  script:
    - pip install klynx-comply
    - klynx-comply scan --format json --output gl-sast-report.json
  artifacts:
    reports:
      sast: gl-sast-report.json

Suppression

Add # comply:ignore to a line to suppress all findings on that line:

api_key = "test-key-for-unit-tests-only"  # comply:ignore

Exit Codes

Code Meaning
0 Compliant — no findings at or above --fail-on severity
1 Non-compliant — blocking findings found
2 Scan error

KlynxAI Integration

When run inside a KlynxAI-managed environment, klynx-comply integrates with:

  • Dragon Policy Engine — auto-validates PolicyEnvelope usage
  • KlynxScan — feeds findings into vulnerability dashboard
  • WarRoom AI — compliance gate before deployment

License

Apache 2.0 — free to use, modify, and distribute.

Built with by KlynxAI

Metadata

Release files for klynx-comply 0.3.2

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for klynx-comply 0.3.2
File Size Uploaded
klynx_comply-0.3.2.tar.gz 39.7 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for klynx-comply 0.3.2
File Interpreter ABI Platform
klynx_comply-0.3.2-py3-none-any.whl Python 3 none any Details

Total release size: 82.5 kB

Release files / klynx_comply-0.3.2.tar.gz

Download URL klynx_comply-0.3.2.tar.gz
Size 39.7 kB
Tags Source
SHA-256 checksum
How to use checksums
52b927a0260439b59c8c674778b42f655ef309b0e3344e4821d85068bd085067
BLAKE2b-256 checksum
How to use checksums
5cfc1dfdb2b08132f9188781731ed599074e11aa400e2b54fea91c66012a3c1c
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.14.0

Release files / klynx_comply-0.3.2-py3-none-any.whl

Download URL klynx_comply-0.3.2-py3-none-any.whl
Size 42.8 kB
Tags Python 3
SHA-256 checksum
How to use checksums
28263bddb55f2a9b492935b52ecf92e2ee52d14aa673716d2de51812d65b886b
BLAKE2b-256 checksum
How to use checksums
5bc0cecba27be3c7df7e8c2ae24b08bd30fea34bf75a5ceeb66d8506d846c96c
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.14.0

Release history Release notifications | RSS feed

This release

0.3.2 This release

2 release files

0.3.1

2 release files

0.3.0

2 release files

0.2.2

2 release files

0.2.1

2 release files

0.2.0

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page