Skip to main content

Autonomous security agent that scans, verifies, fixes vulnerabilities and generates reports.

Project description

SecAgent AI

Autonomous AI Security Agent — scan, verify, and auto-fix security vulnerabilities in your codebase using xAI Grok.

pip install secagent-ai

What is SecAgent?

SecAgent is a CLI tool that acts as an autonomous security engineer. Point it at a file or directory and it will:

  • Scan for secrets, vulnerabilities, and insecure code patterns
  • Verify each finding with AI to eliminate false positives
  • Fix real vulnerabilities by generating and applying secure patches
  • Report everything in a readable Markdown report with cost tracking

All AI reasoning is powered by xAI Grok.


Installation

Requirements: Python 3.11+

pip install secagent-ai

On first run, SecAgent will walk you through a one-time setup to save your Grok API key:

secagent scan ./myproject
╔══════════════════════════════════════════╗
║           S E C A G E N T  AI            ║
║    Autonomous AI Security Agent v0.1.0   ║
╚══════════════════════════════════════════╝
──────────────── First-Time Setup ─────────

Welcome to SecAgent!
To get started, enter your xAI Grok API key.
Get one at: https://console.x.ai/

Grok API Key: ********************************
Setup complete! Config saved to: C:\Users\you\.secagent\config.json

Your key is saved locally and never sent anywhere except the xAI API.


Usage

Scan a file or directory

secagent scan ./myproject
secagent scan ./app/auth.py

Scans for vulnerabilities and saves results. Does not modify any files.

Scan and auto-fix

secagent fix ./myproject
secagent fix ./app/auth.py

Verifies findings, generates patches, applies fixes, and writes a fix.md report.

Re-configure your API key

secagent configure

Check version

secagent version

Verbose mode

secagent scan ./myproject --verbose
secagent fix ./myproject --verbose

Optional Tools

SecAgent works out of the box with its built-in scanners. Installing these tools unlocks additional scanning capabilities:

Tool Purpose Install
Gitleaks Secret & credential scanning brew install gitleaks
Trivy Dependency vulnerability scanning brew install trivy

SecAgent degrades gracefully — if a tool isn't installed, it's skipped automatically. The built-in scanner and AI scanner always run regardless.


How It Works

SecAgent runs a 9-stage pipeline:

Stage 1  │ Planner Agent    │ Analyzes your codebase, selects the right scanners
Stage 2  │ Scanner Executor │ Runs all selected scanners in parallel
Stage 3  │ Result Parser    │ Normalizes findings into a unified format
Stage 4  │ Deduplicator     │ Merges duplicate findings across scanners
Stage 5  │ Verifier Agent   │ AI classifies True Positive vs False Positive
Stage 6  │ Fixer Agent      │ AI generates a secure patch for each real finding
Stage 7  │ Validator Agent  │ AI confirms the patch is correct and safe
Stage 8  │ Patch Applier    │ Applies the patch to your file (with backup)
Stage 9  │ Report Builder   │ Generates fix.md + token usage cost report

All AI stages use xAI Grok. Stages 1, 5 use the fast non-reasoning model. Stages 6, 7 use the reasoning model for higher accuracy.


Output

After a fix run, SecAgent creates:

  • fix.md — full report of findings, verification results, patches applied, and skipped fixes
  • .secagent/logs/cost.md — token usage and estimated API cost per stage
  • .secagent/data/*.vulns.json — cached scan results (reused on subsequent fix runs)

Configuration

Your API key and model settings are stored at:

Platform Path
Windows C:\Users\<you>\.secagent\config.json
Linux / Mac ~/.secagent/config.json

To update your key at any time:

secagent configure

Example Output

SecAgent v0.1.0
Scanning /home/user/myapp (directory)

[Stage 1] Planner selected: builtin-secrets, ai-scanner, gitleaks
[Stage 2] Running 3 scanners...
[Stage 3] Parsed 5 findings
[Stage 4] Deduplicated to 4 unique findings

[Stage 5] Verifying findings...  4 TP  |  0 FP
[Stage 6] Fixing 4 vulnerabilities...
[Stage 7] Validating patches...  4 valid
[Stage 8] Applying 4 patches...

──────────────────────────────────────────────────
Findings: 4  TP: 4  FP: 0  Fixed: 4

Report generated: fix.md

┌─ Token Usage & Estimated Cost ──────────────────┐
│ Stage     │ Model     │ Tokens  │ Cost (USD)     │
│ planner   │ fast      │  1,240  │ $0.0002        │
│ scanner   │ reasoning │  8,430  │ $0.0042        │
│ verifier  │ fast      │  2,100  │ $0.0004        │
│ fixer     │ reasoning │ 12,800  │ $0.0064        │
│ validator │ reasoning │  6,300  │ $0.0032        │
│ Total     │           │ 30,870  │ $0.0144        │
└─────────────────────────────────────────────────┘

License

MIT — free to use, modify, and distribute.


Links

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

secagent_ai-0.1.1.tar.gz (33.8 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

secagent_ai-0.1.1-py3-none-any.whl (44.5 kB view details)

Uploaded Python 3

File details

Details for the file secagent_ai-0.1.1.tar.gz.

File metadata

  • Download URL: secagent_ai-0.1.1.tar.gz
  • Upload date:
  • Size: 33.8 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.1.0 CPython/3.11.7

File hashes

Hashes for secagent_ai-0.1.1.tar.gz
Algorithm Hash digest
SHA256 66d733786c7d677783ac8d0dd1fc0adc1cc7fcebe6dbd291f24486eedbef3f3c
MD5 9e64b6b4fb024402b89729f1d662196f
BLAKE2b-256 c2ab33daa3b9a8bb1e544ee764e1ff1b707649f6b37acdb492ab3bdbd3739da8

See more details on using hashes here.

File details

Details for the file secagent_ai-0.1.1-py3-none-any.whl.

File metadata

  • Download URL: secagent_ai-0.1.1-py3-none-any.whl
  • Upload date:
  • Size: 44.5 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.1.0 CPython/3.11.7

File hashes

Hashes for secagent_ai-0.1.1-py3-none-any.whl
Algorithm Hash digest
SHA256 209c487d521ecb9b094673a5bc3a7d02e0adc8cd63b3399c45d8fe7215da8032
MD5 456e6cb31552d05d3b06712238637383
BLAKE2b-256 c2557e02055d3777672251213ab0113e6a6c1897fceaaaf9c9a489a44949e84c

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page