Skip to main content

sechelix

Optional execution runtime for the SecHelix AppSec Agent Skill.

The Agent Skill is the product and works without this package. Install sechelix when you want the workflow orchestrated by code instead of by an agent reading SKILL.md.

pipx install sechelix     # or: uv tool install sechelix
sechelix doctor
sechelix audit .

What it does

  • a deterministic reasoner DAG over 18 node roles, with cycle rejection
  • per-node telemetry: model, provider, tokens, cost, duration, context digest
  • a budget governor that fails closed — running out before a required verification produces INCOMPLETE, never a clean gate
  • least-context specialist views, so a dependency reasoner never sees the whole repository narrative
  • a coverage ledger that records what previous runs did not examine
  • replayable run workspaces with tamper detection

The first run will say INCOMPLETE

That is correct. The runner orchestrates; it does not reason about code. With no reasoning executor configured every specialist lane is BLOCKED and the run reports No security claim can be made from this run.

A stub returning "no findings" would be indistinguishable from a genuine clean audit, and a fail-closed gate would hand out a PASS for a run that examined nothing. To actually analyse code, select an already-authenticated supported CLI on PATH:

sechelix audit . --executor claude-code
sechelix audit . --executor gemini-cli

SecHelix invokes the official CLIs; it does not read or reuse their OAuth/API credentials. Each node is isolated, and provider quota/errors remain fail-closed.

No dependencies

The runner uses the standard library only, and a test asserts it. A security tool that drags in a dependency tree has widened the attack surface of the thing it was installed to protect.

Status

Alpha. Nothing here has been measured against another tool, and no comparative claim is made. See the repository for what is measured and what is not.

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

sechelix-0.3.0.tar.gz (400.7 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

sechelix-0.3.0-py3-none-any.whl (407.9 kB view details)

Uploaded Python 3

File details

Details for the file sechelix-0.3.0.tar.gz.

File metadata

  • Download URL: sechelix-0.3.0.tar.gz
  • Upload date:
  • Size: 400.7 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for sechelix-0.3.0.tar.gz
Algorithm Hash digest
SHA256 55c46c7de25021c9fc11e67a94987dd9d3f91ea585b1fc6668946adc77727b99
MD5 80725eb1c5094ee81e07202affbc719b
BLAKE2b-256 7ca01eb59d5b456a98e829c6b719c569ecdf1319c6f10eecc091df82e0e92527

See more details on using hashes here.

Provenance

The following attestation bundles were made for sechelix-0.3.0.tar.gz:

Publisher: publish-pypi.yml on omarmohelal/SecHelix

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file sechelix-0.3.0-py3-none-any.whl.

File metadata

  • Download URL: sechelix-0.3.0-py3-none-any.whl
  • Upload date:
  • Size: 407.9 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for sechelix-0.3.0-py3-none-any.whl
Algorithm Hash digest
SHA256 6bedbadd1c060cde8bc4b6b084cb5e619c754b362707ba5def89c1fcea98b3da
MD5 62dae530071b0a4e143c3e445800353d
BLAKE2b-256 974b253017612fc1ad0f5b8e3801bf684d7b12e61147a8940d157698c1ace3fc

See more details on using hashes here.

Provenance

The following attestation bundles were made for sechelix-0.3.0-py3-none-any.whl:

Publisher: publish-pypi.yml on omarmohelal/SecHelix

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Release history Release notifications | RSS feed

This release

0.3.0 This release

2 files

0.2.1

2 files

0.2.0

2 files

0.1.1

2 files

0.1.0

2 files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page