securityagent-core
Shared DLP engine, security skills, and policy enforcement for AI coding agents. Used by SecurityAgent and AgnosticSecurity.
What's inside
| Package | What it does |
|---|---|
endpoint_agent/ |
DLP engine — file blocking (60+ path patterns), confidence-scored content scanning (PII, credentials, semantic disclosure detection) with structural validators (Luhn, SSA rules, entropy) and context-aware scoring, data flow taint tracking (tags sensitive data at ingress, detects at egress via hash/n-gram/substring matching), tool call argument scanning (MCP/function call DLP + taint registry), behavioral monitoring (8-signal anomaly scoring), honeypot traps, credential scanning. LLM intent analysis with llama3.1:8b default + fallback chain. Notebook-aware .ipynb extraction. PDF extraction via 3-tier pipeline (PyMuPDF → Tesseract OCR → pypdf fallback) with encrypted PDF detection |
skills/ |
Agent-agnostic MCP skills — secure_read, secure_exec, analyze_prompt, scan_output, check_policy, get_session_policy, audit_log |
policy/ |
Policy engine — per-session least privilege, behavioral chain detection (11 attack patterns), audit trail with agent attribution. Obsidian vault integration via memory_bridge.py for cross-session policy context |
obsidianMemory/ |
Obsidian vault — daily session logs, second-brain knowledge base, used by memory_bridge.py for persistent threat/policy tracking |
plugin.py |
Standalone CLI entry point + validate_exec(), validate_prompt(), validate_output() pure functions |
Install
pip install git+https://github.com/kaushikdharamshi/securityagent-core.git
# With optional dependencies
pip install "securityagent-core[cloud] @ git+https://github.com/kaushikdharamshi/securityagent-core.git"
pip install "securityagent-core[llm] @ git+https://github.com/kaushikdharamshi/securityagent-core.git"
Usage
Python SDK
from skills.adapters.python_sdk import SecurityAgentSDK
sdk = SecurityAgentSDK(agent_id="my-agent", agent_type="langchain")
# DLP-gated file read
result = sdk.secure_read("/path/to/file")
# Command validation
result = sdk.secure_exec("ls -la")
# Prompt intent analysis
result = sdk.analyze_prompt("Get me all customer SSNs")
MCP Server
python -m skills.adapters.mcp_server # after pip install
Any MCP-compatible client (Claude Code, Copilot, custom agents) can connect via stdio JSON-RPC.
CLI
python -m plugin ~/.env # File read gate
python -m plugin --exec "cat ~/.env" # Exec validation
python -m plugin --prompt "Get all passwords" # Prompt analysis
python -m plugin --skill secure_read --params '{"path":"~/.env"}' # Skills layer
python -m plugin --mcp-server # MCP server
Claude Code Integration
See integrations/claude_code/ for PreToolUse hook configuration.
Tests
pip install -e ".[dev]"
pytest
Release files for securityagent-core 4.45.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| securityagent_core-4.45.0.tar.gz | 195.2 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| securityagent_core-4.45.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 419.7 kB
Release files / securityagent_core-4.45.0.tar.gz
| Download URL | securityagent_core-4.45.0.tar.gz |
|---|---|
| Size | 195.2 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
2458e43f6fc2b9bd43801b502637c17f5d2a0db65de360577486df3e6d342c0d
|
|
BLAKE2b-256 checksum How to use checksums |
e2b024c69a8a5f56d19b932f8f94dc0184a9e9a8d6bf0e7a4beee2798baceca1
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/6.2.0 CPython/3.12.11
|
Release files / securityagent_core-4.45.0-py3-none-any.whl
| Download URL | securityagent_core-4.45.0-py3-none-any.whl |
|---|---|
| Size | 224.5 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
02dda713fb0444cf6e06f5edbaf6fa0bfde1c54815568e33d558e09f15e167f5
|
|
BLAKE2b-256 checksum How to use checksums |
da9cfd1315951bf9816cfa7abf33755422ce3c2fc6f319a8d1d0a479ddb525b1
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/6.2.0 CPython/3.12.11
|