Tool · curated 28 Jun 2026

GitHub - sattyamjjain/agent-audit-kit: Static scanner for MCP-connected AI agent pipelines. 296 rules across 12 categories, 12 compliance frameworks, OWASP Agentic 10/10 + MCP 10/10, GitHub Action, SARIF, public CVE-to-rule ledger.

Coverage timeline

26 Jun 2026github.com 14 Aug 2026github.com 16 Aug 2026github.com

Why it matters

agent-audit-kit gives defenders a runnable, CI-integrable way to scan MCP and AI agent pipelines for known vulnerability classes, an increasingly important control as MCP-based tooling expands the agentic attack surface.

agent-audit-kit is a static scanner for MCP-connected AI agent pipelines, shipping 296 rules across 12 categories, mappings to 12 compliance frameworks, OWASP Agentic 10/10 and MCP 10/10 coverage, a GitHub Action, SARIF output, and a public CVE-to-rule ledger. The tool is aimed at helping defenders detect security weaknesses in AI agent and MCP integrations before deployment.