Open-source auditor for Non-Human Identities and AI Agent attack surfaces in cloud environments
Project description
AgentSentry 🛡️
Open-source auditor for Non-Human Identities and AI Agent attack surfaces across AWS, Azure, GCP, GitHub, Kubernetes, and your local machine.
"45 machine identities for every 1 human. Almost none of them are governed."
AgentSentry discovers every IAM role, API key, service account, SSH key, and AI agent in your environment — builds an attack graph of their access relationships — and scores the blast radius if any identity is compromised, using a novel AI-Amplification Factor that quantifies how autonomous AI agents multiply attack surface.
Quick Start
pip install nhi-audit
agentsentry interactive
No cloud credentials needed to try it:
agentsentry scan mock # full multi-cloud demo
agentsentry scan local # scan this machine now
Installation
pip install nhi-audit # core (local scanner included)
pip install nhi-audit[aws] # + AWS
pip install nhi-audit[azure] # + Azure
pip install nhi-audit[gcp] # + GCP
pip install nhi-audit[github] # + GitHub
pip install nhi-audit[k8s] # + Kubernetes
pip install nhi-audit[all-clouds] # everything
Windows PATH fix (run once):
python -m agentsentry --install-path
Provider Setup
| Provider | Setup | Command |
|---|---|---|
| Local | Nothing | agentsentry scan local |
| AWS | aws configure |
agentsentry scan aws |
| Azure | az login |
agentsentry scan azure |
| GCP | gcloud auth application-default login |
agentsentry scan gcp |
| GitHub | set GITHUB_TOKEN=ghp_... |
agentsentry scan github |
| K8s | kubectl config use-context |
agentsentry scan k8s |
| AI Agents | Nothing | agentsentry scan agents --path . |
All Commands
agentsentry interactive # guided provider picker (recommended)
agentsentry scan mock # demo, no credentials
agentsentry scan local --path ./myproject # scan specific directory
agentsentry scan aws --visualize # + interactive HTML attack graph
agentsentry scan aws --enrich # + CISA KEV threat intel
agentsentry scan all # auto-detect + scan everything ready
agentsentry providers # check what's configured
agentsentry blast "ml-pipeline-executor" # blast radius analysis
Risk Scoring: P×R×E×A
Risk = Privilege × Reachability × Exposure × AI-Amplification
CRITICAL ≥ 100 | HIGH ≥ 50 | MEDIUM ≥ 20 | LOW < 20
The AI-Amplification Factor is a novel research contribution — the first formal quantification of how autonomous AI agents multiply the blast radius of a compromised identity.
Standalone Executable
No Python needed. Download from GitHub Releases:
| Platform | File |
|---|---|
| Windows | agentsentry-windows.exe |
| macOS | agentsentry-macos |
| Linux | agentsentry-linux |
Repository Structure
agent-sentry/
├── agentsentry/ ← CLI tool (Python, open-source)
├── website/ ← Marketing site (Next.js, Vercel)
└── paper/ ← Research paper (IEEE LaTeX)
Links
- Website & Docs: agent-sentry-beta.vercel.app
- PyPI: pypi.org/project/nhi-audit
- Issues: GitHub Issues
License: MIT — free forever.
Project details
Release history Release notifications | RSS feed
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file nhi_audit-0.1.7.tar.gz.
File metadata
- Download URL: nhi_audit-0.1.7.tar.gz
- Upload date:
- Size: 172.5 kB
- Tags: Source
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/6.2.0 CPython/3.14.3
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
93c29db9957ccfbee53dcb79426eba38afae969af7c0691edf9cba2998aea45a
|
|
| MD5 |
5d3542f126f19da85ddcfb28baf80639
|
|
| BLAKE2b-256 |
bb3fcc4632ea64d801240283a60e62f0f195e834b0548adbd3a9027da3b33d35
|
File details
Details for the file nhi_audit-0.1.7-py3-none-any.whl.
File metadata
- Download URL: nhi_audit-0.1.7-py3-none-any.whl
- Upload date:
- Size: 200.0 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/6.2.0 CPython/3.14.3
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
3f46a7e4376cbfc305759d0f6c1402c241510ee1b4755334dc3d2d37eddc9f28
|
|
| MD5 |
63303bebbc7eb92c5fc7efff8b640ed4
|
|
| BLAKE2b-256 |
5ec7fa41e1c4a25e8ffe7aa7cf128fe670d7bb53ef389c4a4dc60b45ea030a37
|