Skip to main content

sechelix

Optional execution runtime for the SecHelix AppSec Agent Skill.

The Agent Skill is the product and works without this package. Install sechelix when you want the workflow orchestrated by code instead of by an agent reading SKILL.md.

pipx install sechelix     # or: uv tool install sechelix
sechelix doctor
sechelix audit .

What it does

  • a deterministic reasoner DAG over 18 node roles, with cycle rejection
  • per-node telemetry: model, provider, tokens, cost, duration, context digest
  • a budget governor that fails closed — running out before a required verification produces INCOMPLETE, never a clean gate
  • least-context specialist views, so a dependency reasoner never sees the whole repository narrative
  • a coverage ledger that records what previous runs did not examine
  • replayable run workspaces with tamper detection

The first run will say INCOMPLETE

That is correct. The runner orchestrates; it does not reason about code. With no reasoning executor configured every specialist lane is BLOCKED and the run reports No security claim can be made from this run.

A stub returning "no findings" would be indistinguishable from a genuine clean audit, and a fail-closed gate would hand out a PASS for a run that examined nothing. To actually analyse code, select an already-authenticated supported CLI on PATH:

sechelix audit . --executor claude-code
sechelix audit . --executor gemini-cli

SecHelix invokes the official CLIs; it does not read or reuse their OAuth/API credentials. Each node is isolated, and provider quota/errors remain fail-closed.

No dependencies

The runner uses the standard library only, and a test asserts it. A security tool that drags in a dependency tree has widened the attack surface of the thing it was installed to protect.

Status

Alpha. Nothing here has been measured against another tool, and no comparative claim is made. See the repository for what is measured and what is not.

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

sechelix-0.2.1.tar.gz (399.1 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

sechelix-0.2.1-py3-none-any.whl (407.9 kB view details)

Uploaded Python 3

File details

Details for the file sechelix-0.2.1.tar.gz.

File metadata

  • Download URL: sechelix-0.2.1.tar.gz
  • Upload date:
  • Size: 399.1 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for sechelix-0.2.1.tar.gz
Algorithm Hash digest
SHA256 0a3a70e8ea6d86ef74b8f6ff6cca287e53224ab91c075289a82047a64267d6e8
MD5 44dbc5edcdea61bc7709c9ea2c50217a
BLAKE2b-256 ea3e0700ee193714ce6df4ca00b306b7def14667785094ddfe5f3e3de714ee18

See more details on using hashes here.

Provenance

The following attestation bundles were made for sechelix-0.2.1.tar.gz:

Publisher: publish-pypi.yml on omarmohelal/SecHelix

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file sechelix-0.2.1-py3-none-any.whl.

File metadata

  • Download URL: sechelix-0.2.1-py3-none-any.whl
  • Upload date:
  • Size: 407.9 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for sechelix-0.2.1-py3-none-any.whl
Algorithm Hash digest
SHA256 e3a5d31bd0ef81834bb9e16c28a3c0f3a799b85c8ae4b7e25d280c6058855bcc
MD5 0c0b9cbfa5ca5bed37d43cc498fb1056
BLAKE2b-256 40b347c3ed512f8ecd136a0c58b78af4c8e84db54f69e92b5e1f1e2a8b332859

See more details on using hashes here.

Provenance

The following attestation bundles were made for sechelix-0.2.1-py3-none-any.whl:

Publisher: publish-pypi.yml on omarmohelal/SecHelix

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Release history Release notifications | RSS feed

0.3.0

2 files

This release

0.2.1 This release

2 files

0.2.0

2 files

0.1.1

2 files

0.1.0

2 files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page