Skip to main content

sechelix

Optional execution runtime for the SecHelix AppSec Agent Skill.

The Agent Skill is the product and works without this package. Install sechelix when you want the workflow orchestrated by code instead of by an agent reading SKILL.md.

pipx install sechelix     # or: uv tool install sechelix
sechelix doctor
sechelix audit .

What it does

  • a deterministic reasoner DAG over 18 node roles, with cycle rejection
  • per-node telemetry: model, provider, tokens, cost, duration, context digest
  • a budget governor that fails closed — running out before a required verification produces INCOMPLETE, never a clean gate
  • least-context specialist views, so a dependency reasoner never sees the whole repository narrative
  • a coverage ledger that records what previous runs did not examine
  • replayable run workspaces with tamper detection

The first run will say INCOMPLETE

That is correct. The runner orchestrates; it does not reason about code. With no reasoning executor configured every specialist lane is BLOCKED and the run reports No security claim can be made from this run.

A stub returning "no findings" would be indistinguishable from a genuine clean audit, and a fail-closed gate would hand out a PASS for a run that examined nothing. To actually analyse code, pass --executor claude-code with an authenticated Claude Code CLI on PATH.

No dependencies

The runner uses the standard library only, and a test asserts it. A security tool that drags in a dependency tree has widened the attack surface of the thing it was installed to protect.

Status

Alpha. Nothing here has been measured against another tool, and no comparative claim is made. See the repository for what is measured and what is not.

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

sechelix-0.1.0.tar.gz (391.4 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

sechelix-0.1.0-py3-none-any.whl (403.4 kB view details)

Uploaded Python 3

File details

Details for the file sechelix-0.1.0.tar.gz.

File metadata

  • Download URL: sechelix-0.1.0.tar.gz
  • Upload date:
  • Size: 391.4 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for sechelix-0.1.0.tar.gz
Algorithm Hash digest
SHA256 a7e8e07b09b9b4a18c6ef1435b39f830b4694aa092ce7c065dc75bea68153b2c
MD5 b055737209114857b339579c52d00059
BLAKE2b-256 07a102bcbb0a1d9853248a788bcb71133308bce1bb3b29d494bf9985dfce2e21

See more details on using hashes here.

Provenance

The following attestation bundles were made for sechelix-0.1.0.tar.gz:

Publisher: publish-pypi.yml on omarmohelal/SecHelix

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file sechelix-0.1.0-py3-none-any.whl.

File metadata

  • Download URL: sechelix-0.1.0-py3-none-any.whl
  • Upload date:
  • Size: 403.4 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for sechelix-0.1.0-py3-none-any.whl
Algorithm Hash digest
SHA256 bda1485b4e69907847969ada5a46dfc46e2ec7925822a28516bc2339435c4e08
MD5 1dfbd182ff98c87b6f829f1ca4c0f990
BLAKE2b-256 c89cd400fe831aa569f32906591cdecf1372c1caaddd352e97feab00ebbb5153

See more details on using hashes here.

Provenance

The following attestation bundles were made for sechelix-0.1.0-py3-none-any.whl:

Publisher: publish-pypi.yml on omarmohelal/SecHelix

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Release history Release notifications | RSS feed

0.3.0

2 files

0.2.1

2 files

0.2.0

2 files

0.1.1

2 files

This release

0.1.0 This release

2 files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page