Tool · curated 28 Jun 2026
GitHub - sattyamjjain/agent-audit-kit: Static scanner for MCP-connected AI agent pipelines. 296 rules across 12 categories, 12 compliance frameworks, OWASP Agentic 10/10 + MCP 10/10, GitHub Action, SARIF, public CVE-to-rule ledger.
First reported · updated · 3 reports github.com
Coverage timeline
Why it matters
agent-audit-kit gives defenders a runnable, CI-integrable way to scan MCP and AI agent pipelines for known vulnerability classes, an increasingly important control as MCP-based tooling expands the agentic attack surface.
agent-audit-kit is a static scanner for MCP-connected AI agent pipelines, shipping 296 rules across 12 categories, mappings to 12 compliance frameworks, OWASP Agentic 10/10 and MCP 10/10 coverage, a GitHub Action, SARIF output, and a public CVE-to-rule ledger. The tool is aimed at helping defenders detect security weaknesses in AI agent and MCP integrations before deployment.