Skip to main content

sechelix

Optional execution runtime for the SecHelix AppSec Agent Skill.

The Agent Skill is the product and works without this package. Install sechelix when you want the workflow orchestrated by code instead of by an agent reading SKILL.md.

pipx install sechelix     # or: uv tool install sechelix
sechelix doctor
sechelix audit .

What it does

  • a deterministic reasoner DAG over 18 node roles, with cycle rejection
  • per-node telemetry: model, provider, tokens, cost, duration, context digest
  • a budget governor that fails closed — running out before a required verification produces INCOMPLETE, never a clean gate
  • least-context specialist views, so a dependency reasoner never sees the whole repository narrative
  • a coverage ledger that records what previous runs did not examine
  • replayable run workspaces with tamper detection

The first run will say INCOMPLETE

That is correct. The runner orchestrates; it does not reason about code. With no reasoning executor configured every specialist lane is BLOCKED and the run reports No security claim can be made from this run.

A stub returning "no findings" would be indistinguishable from a genuine clean audit, and a fail-closed gate would hand out a PASS for a run that examined nothing. To actually analyse code, pass --executor claude-code with an authenticated Claude Code CLI on PATH.

No dependencies

The runner uses the standard library only, and a test asserts it. A security tool that drags in a dependency tree has widened the attack surface of the thing it was installed to protect.

Status

Alpha. Nothing here has been measured against another tool, and no comparative claim is made. See the repository for what is measured and what is not.

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

sechelix-0.1.1.tar.gz (391.8 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

sechelix-0.1.1-py3-none-any.whl (402.7 kB view details)

Uploaded Python 3

File details

Details for the file sechelix-0.1.1.tar.gz.

File metadata

  • Download URL: sechelix-0.1.1.tar.gz
  • Upload date:
  • Size: 391.8 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for sechelix-0.1.1.tar.gz
Algorithm Hash digest
SHA256 edb390f2f4487846c85b81a3c1ea6d7ad0b469d667e7dee86ba346dd222879f6
MD5 88a9d595dc7ade85fc71c21cfe0c718c
BLAKE2b-256 c7918c7be4d093405b241a1b7359ff4dba7ab58af567bdee18220b1bead1f705

See more details on using hashes here.

Provenance

The following attestation bundles were made for sechelix-0.1.1.tar.gz:

Publisher: publish-pypi.yml on omarmohelal/SecHelix

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file sechelix-0.1.1-py3-none-any.whl.

File metadata

  • Download URL: sechelix-0.1.1-py3-none-any.whl
  • Upload date:
  • Size: 402.7 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for sechelix-0.1.1-py3-none-any.whl
Algorithm Hash digest
SHA256 9a47418378230f7807053ff75be14edd0183c6f2d7759ebe2dbfbc139aeb239f
MD5 d1bfc8f984c413933d51a21944767a1d
BLAKE2b-256 60f6b1f4e98451d83552cc2ee36826a0bd7be42f70ae26eb33841ae1bfd9018d

See more details on using hashes here.

Provenance

The following attestation bundles were made for sechelix-0.1.1-py3-none-any.whl:

Publisher: publish-pypi.yml on omarmohelal/SecHelix

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Release history Release notifications | RSS feed

0.3.0

2 files

0.2.1

2 files

0.2.0

2 files

This release

0.1.1 This release

2 files

0.1.0

2 files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page