nuguard
AI-SBOM generation, static analysis, and automated red-teaming / adversarial-attack-generation for AI agents and applications.
What it does · See it in action · Framework coverage · Comparison · Getting started · FAQ
NuGuard is an open source AI application security toolkit. It generates an AI Bill of Materials (AI-SBOM) for your agentic application, statically analyzes it for structural risk, then red-teams a running instance with a catalog of 100+ adversarial scenarios — prompt injection, tool abuse, data exfiltration, and more — so you find the finding before an attacker does.
What It Does
See It In Action
A real scan of a live fintech agent — Pinnacle Bank Assistant — walking through all five NuGuard stages: AI-SBOM, Cognitive Policy, Static Analysis, Behavior, and Red-Team. No mocks, no slides — real findings, including a live transcript of the agent leaking another customer's flagged fraud transactions on a routine question.
→ Open the interactive demo — scroll through the full walkthrough yourself.
Comparison
Getting Started
Install, then generate an SBOM, statically analyze it, and red-team a live target:
pip install nuguard
nuguard init --target <your-app-url>
nuguard sbom generate --source <path-to-your-app> --output app.sbom.json
nuguard analyze --sbom app.sbom.json --format markdown
nuguard redteam --config nuguard.yaml --format markdown --output reports/redteam.md
🚀 Ready to run NuGuard?
Installation, the full CLI surface, and the configuration reference — all in one guide.
🤖 Using Claude Code?
Install the NuGuard plugin and run SBOM, analysis, behavior, and red-team scans directly from Claude Code or Claude Desktop.
Hosted Version
|
Contributing
🤝 Want to contribute?
Dev setup, running tests and lint, and the pull request process are covered in the Contributing guide.
Repo Notes
- The repository currently contains example applications under
tests/apps/ - LLM-assisted features depend on provider credentials being available via environment variables
FAQ
I have some questions, how do I reach out to folks behind this repo? You can contact us at oss@nuguard.ai For bug reporting, use the issues page on GitHub.
Do I need a live app to get findings?
No. nuguard sbom + nuguard analyze find structural and supply-chain risk statically.
nuguard behavior and nuguard redteam need a running target typically in a sandbox.
Which LLM providers are supported for LLM-assisted features?
Configured via the llm section of nuguard.yaml; provider credentials are read from environment variables. Lite LLM is used to abstract any llm provider.
What if I don't want to run all redteam scenarios?
Filter by category or profile, or set enabled: false per scenario in a catalog exported with nuguard redteam catalog-export.
License
Docs: Getting started · Quick start · CLI reference · Policy engine · Static analysis · Red-team Guide · Claude plugin · Troubleshooting · Security · Contributing
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file nuguard-0.9.5.tar.gz.
File metadata
- Download URL: nuguard-0.9.5.tar.gz
- Upload date:
- Size: 1.5 MB
- Tags: Source
- Uploaded using Trusted Publishing? Yes
- Uploaded via:
twine/7.0.0 CPython/3.13.14
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
3d4fb2123b6ec0bcb2f53d7d06d19d8b25ba3171f7fde961cffb18b75386994a
|
|
| MD5 |
cc8bf151c12dce38d2159d377512247f
|
|
| BLAKE2b-256 |
66c797b151ae6855483140254b2be7cb2f6017a8d28e499ced24a2a206abf7d2
|
Provenance
The following attestation bundles were made for nuguard-0.9.5.tar.gz:
Publisher:
publish-pypi.yml on NuGuardAI/nuguard
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
nuguard-0.9.5.tar.gz -
Subject digest:
3d4fb2123b6ec0bcb2f53d7d06d19d8b25ba3171f7fde961cffb18b75386994a - Sigstore transparency entry: 2667125798
- Sigstore integration time:
-
Permalink:
NuGuardAI/nuguard@0b1f28202d2b18306fa8bff731be5c81a0b506f8 -
Branch / Tag:
refs/heads/main - Owner: https://github.com/NuGuardAI
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
publish-pypi.yml@0b1f28202d2b18306fa8bff731be5c81a0b506f8 -
Trigger Event:
workflow_dispatch
-
Statement type:
File details
Details for the file nuguard-0.9.5-py3-none-any.whl.
File metadata
- Download URL: nuguard-0.9.5-py3-none-any.whl
- Upload date:
- Size: 1.7 MB
- Tags: Python 3
- Uploaded using Trusted Publishing? Yes
- Uploaded via:
twine/7.0.0 CPython/3.13.14
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
b0417dd4caf640800afd92310e3d31dd8d400a457320a1dac10c7fe67fa615f8
|
|
| MD5 |
d47951a1e4649b215106ab863812d38f
|
|
| BLAKE2b-256 |
0004e5b96d198fa2d845336bc44db8fc16959c27982b6765aafd9c377e1b8bd9
|
Provenance
The following attestation bundles were made for nuguard-0.9.5-py3-none-any.whl:
Publisher:
publish-pypi.yml on NuGuardAI/nuguard
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
nuguard-0.9.5-py3-none-any.whl -
Subject digest:
b0417dd4caf640800afd92310e3d31dd8d400a457320a1dac10c7fe67fa615f8 - Sigstore transparency entry: 2667125832
- Sigstore integration time:
-
Permalink:
NuGuardAI/nuguard@0b1f28202d2b18306fa8bff731be5c81a0b506f8 -
Branch / Tag:
refs/heads/main - Owner: https://github.com/NuGuardAI
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
publish-pypi.yml@0b1f28202d2b18306fa8bff731be5c81a0b506f8 -
Trigger Event:
workflow_dispatch
-
Statement type: