Razin - Static analysis for LLM agent skills
Razin is a local scanner for SKILL.md-defined agent skills.
It performs static analysis only (no execution) and writes deterministic findings.
Table of contents
- Documentation
- Requirements
- Install
- Quick start
- Local development
- Where to read more
- Contributing
- Security
- License
Documentation
Full documentation lives at:
Canonical docs source in this repository:
docs/
Use this README for quick start only.
Requirements
- Python
3.12+
Install
With Homebrew (current, via tap):
brew tap theinfosecguy/homebrew-tap
brew install razin
razin --help
With PyPI:
pip install razin
razin --help
Quick start
Run a scan:
razin scan -r . -o output/
Validate config:
razin validate-config -r .
Common CI gates
# Fail if any high-severity finding exists
razin scan -r . --fail-on high --no-stdout
# Fail if aggregate score is 70 or above
razin scan -r . --fail-on-score 70 --no-stdout
Output formats
# Default per-skill JSON reports
razin scan -r . -o output/ --output-format json
# Add CSV + SARIF exports
razin scan -r . -o output/ --output-format json,csv,sarif
Local development
uv sync --dev
uv run pytest -q
uv run ruff check src tests
uv run mypy src tests
Docs preview and checks:
uv sync --group docs
uv run mkdocs serve
uv run mkdocs build --strict
uv run mdformat --check README.md docs
Where to read more
- Getting started
- CLI reference
- Configuration
- Detectors
- Output formats
- Docker workflow
- CI and exit codes
- Troubleshooting
Contributing
See CONTRIBUTING.md.
Security
See SECURITY.md.
License
Release files for razin 1.5.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| razin-1.5.0.tar.gz | 237.8 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| razin-1.5.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 385.9 kB
Release files / razin-1.5.0.tar.gz
| Download URL | razin-1.5.0.tar.gz |
|---|---|
| Size | 237.8 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
96966ac5188e523c5bdf9572e33fa24dee58015eac2f2dde97adbba1ba2d4765
|
|
BLAKE2b-256 checksum How to use checksums |
379651fec086668436be9396c404c9cbb967d1bb3014a15177c4de81cd032ac7
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.7
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Mar 15, 2026.
Transparency logRelease files / razin-1.5.0-py3-none-any.whl
| Download URL | razin-1.5.0-py3-none-any.whl |
|---|---|
| Size | 148.1 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
ac7ede8d0ba4ebb35bb97849a2c83e4d03d094a05d0cdd25c245d3ec6e37034d
|
|
BLAKE2b-256 checksum How to use checksums |
2a09125f1b171b2bbc57dac61e450de615178041015da3bad08deafa5c156264
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.7
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Mar 15, 2026.
Transparency log