QUIET COYOTE — AI Agent Compliance Scanner
klynx-comply is an open-source CLI that scans AI agent codebases for security,
governance, and safety issues before deployment. Built by KlynxAI.
Install
pip install klynx-comply
Or from source:
git clone https://github.com/klynx-ai/klynxai-assistant
cd tools/klynx-comply
pip install -e .
Quick Start
# Scan current directory
klynx-comply scan
# Scan a specific path
klynx-comply scan ./my-agent-app
# Output as JSON (for CI/CD)
klynx-comply scan --format json --output report.json
# Output as SARIF (GitHub Code Scanning, VS Code, Azure DevOps)
klynx-comply scan --format sarif --output results.sarif
# Only report HIGH and above
klynx-comply scan --severity HIGH
# Fail CI only on CRITICAL
klynx-comply scan --fail-on critical
# Run specific checks only
klynx-comply scan --checks SC-001 --checks AT-001
# List all checks
klynx-comply checks
Checks
| ID | Category | Name | Severity |
|---|---|---|---|
| SC-001 | Security | Hardcoded Secrets | CRITICAL |
| AT-001 | Governance | Audit Trail Coverage | HIGH |
| AG-001 | Security | Auth Gating on Endpoints | HIGH |
| PII-001 | Privacy | PII Handling Safety | HIGH |
| AP-001 | Governance | Agent Policy Envelope | HIGH |
| HO-001 | Safety | Human Oversight Gates | HIGH |
| PI-001 | Security | Prompt Injection Vulnerability | HIGH |
| IV-001 | Security | Input Validation at Boundaries | MEDIUM |
CI/CD Integration
GitHub Actions
- name: Agent compliance scan
run: |
pip install klynx-comply
klynx-comply scan --format sarif --output results.sarif --fail-on high
- name: Upload SARIF
uses: github/codeql-action/upload-sarif@v3
with:
sarif_file: results.sarif
GitLab CI
comply:
script:
- pip install klynx-comply
- klynx-comply scan --format json --output gl-sast-report.json
artifacts:
reports:
sast: gl-sast-report.json
Suppression
Add # comply:ignore to a line to suppress all findings on that line:
api_key = "test-key-for-unit-tests-only" # comply:ignore
Exit Codes
| Code | Meaning |
|---|---|
| 0 | Compliant — no findings at or above --fail-on severity |
| 1 | Non-compliant — blocking findings found |
| 2 | Scan error |
KlynxAI Integration
When run inside a KlynxAI-managed environment, klynx-comply integrates with:
- Dragon Policy Engine — auto-validates PolicyEnvelope usage
- KlynxScan — feeds findings into vulnerability dashboard
- WarRoom AI — compliance gate before deployment
License
Apache 2.0 — free to use, modify, and distribute.
Built with by KlynxAI
Metadata
Release files for klynx-comply 0.3.2
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| klynx_comply-0.3.2.tar.gz | 39.7 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| klynx_comply-0.3.2-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 82.5 kB
Release files / klynx_comply-0.3.2.tar.gz
| Download URL | klynx_comply-0.3.2.tar.gz |
|---|---|
| Size | 39.7 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
52b927a0260439b59c8c674778b42f655ef309b0e3344e4821d85068bd085067
|
|
BLAKE2b-256 checksum How to use checksums |
5cfc1dfdb2b08132f9188781731ed599074e11aa400e2b54fea91c66012a3c1c
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/6.2.0 CPython/3.14.0
|
Release files / klynx_comply-0.3.2-py3-none-any.whl
| Download URL | klynx_comply-0.3.2-py3-none-any.whl |
|---|---|
| Size | 42.8 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
28263bddb55f2a9b492935b52ecf92e2ee52d14aa673716d2de51812d65b886b
|
|
BLAKE2b-256 checksum How to use checksums |
5bc0cecba27be3c7df7e8c2ae24b08bd30fea34bf75a5ceeb66d8506d846c96c
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/6.2.0 CPython/3.14.0
|