sechelix
Optional execution runtime for the SecHelix AppSec Agent Skill.
The Agent Skill is the product and works without this package. Install sechelix
when you want the workflow orchestrated by code instead of by an agent reading
SKILL.md.
pipx install sechelix # or: uv tool install sechelix
sechelix doctor
sechelix audit .
What it does
- a deterministic reasoner DAG over 18 node roles, with cycle rejection
- per-node telemetry: model, provider, tokens, cost, duration, context digest
- a budget governor that fails closed — running out before a required
verification produces
INCOMPLETE, never a clean gate - least-context specialist views, so a dependency reasoner never sees the whole repository narrative
- a coverage ledger that records what previous runs did not examine
- replayable run workspaces with tamper detection
The first run will say INCOMPLETE
That is correct. The runner orchestrates; it does not reason about code. With no
reasoning executor configured every specialist lane is BLOCKED and the run
reports No security claim can be made from this run.
A stub returning "no findings" would be indistinguishable from a genuine clean
audit, and a fail-closed gate would hand out a PASS for a run that examined
nothing. To actually analyse code, pass --executor claude-code with an
authenticated Claude Code CLI on PATH.
No dependencies
The runner uses the standard library only, and a test asserts it. A security tool that drags in a dependency tree has widened the attack surface of the thing it was installed to protect.
Status
Alpha. Nothing here has been measured against another tool, and no comparative claim is made. See the repository for what is measured and what is not.
- Repository: https://github.com/omarmohelal/SecHelix
- Quickstart: https://github.com/omarmohelal/SecHelix/blob/main/docs/v4-quickstart.md
- Licence: Apache-2.0
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file sechelix-0.1.1.tar.gz.
File metadata
- Download URL: sechelix-0.1.1.tar.gz
- Upload date:
- Size: 391.8 kB
- Tags: Source
- Uploaded using Trusted Publishing? Yes
- Uploaded via:
twine/7.0.0 CPython/3.13.14
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
edb390f2f4487846c85b81a3c1ea6d7ad0b469d667e7dee86ba346dd222879f6
|
|
| MD5 |
88a9d595dc7ade85fc71c21cfe0c718c
|
|
| BLAKE2b-256 |
c7918c7be4d093405b241a1b7359ff4dba7ab58af567bdee18220b1bead1f705
|
Provenance
The following attestation bundles were made for sechelix-0.1.1.tar.gz:
Publisher:
publish-pypi.yml on omarmohelal/SecHelix
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
sechelix-0.1.1.tar.gz -
Subject digest:
edb390f2f4487846c85b81a3c1ea6d7ad0b469d667e7dee86ba346dd222879f6 - Sigstore transparency entry: 2708394588
- Sigstore integration time:
-
Permalink:
omarmohelal/SecHelix@4b6fa9d64b7cb1a17bb7dc343f2454129a8b37ae -
Branch / Tag:
refs/heads/main - Owner: https://github.com/omarmohelal
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
publish-pypi.yml@4b6fa9d64b7cb1a17bb7dc343f2454129a8b37ae -
Trigger Event:
push
-
Statement type:
File details
Details for the file sechelix-0.1.1-py3-none-any.whl.
File metadata
- Download URL: sechelix-0.1.1-py3-none-any.whl
- Upload date:
- Size: 402.7 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? Yes
- Uploaded via:
twine/7.0.0 CPython/3.13.14
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
9a47418378230f7807053ff75be14edd0183c6f2d7759ebe2dbfbc139aeb239f
|
|
| MD5 |
d1bfc8f984c413933d51a21944767a1d
|
|
| BLAKE2b-256 |
60f6b1f4e98451d83552cc2ee36826a0bd7be42f70ae26eb33841ae1bfd9018d
|
Provenance
The following attestation bundles were made for sechelix-0.1.1-py3-none-any.whl:
Publisher:
publish-pypi.yml on omarmohelal/SecHelix
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
sechelix-0.1.1-py3-none-any.whl -
Subject digest:
9a47418378230f7807053ff75be14edd0183c6f2d7759ebe2dbfbc139aeb239f - Sigstore transparency entry: 2708394656
- Sigstore integration time:
-
Permalink:
omarmohelal/SecHelix@4b6fa9d64b7cb1a17bb7dc343f2454129a8b37ae -
Branch / Tag:
refs/heads/main - Owner: https://github.com/omarmohelal
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
publish-pypi.yml@4b6fa9d64b7cb1a17bb7dc343f2454129a8b37ae -
Trigger Event:
push
-
Statement type: