AgentAuditKit MCP Security Scan
Version updated for https://github.com/sattyamjjain/agent-audit-kit to version v0.3.73.
- This action is used across all versions by ? repositories.
Action Type
This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary
Summary: AgentAuditKit is a security scanner designed to scan AI agent pipelines for misconfigurations, hardcoded secrets, tool poisoning, rug pulls, trust boundary violations, and tainted data flows. It runs fully offline and deterministically, ensuring consistent findings across different runs. The action provides auditor-ready compliance-evidence packs in SARIF format and PDF reports, covering 12 security frameworks.
What’s Changed
Installation
pip:
pip install agent-audit-kit==v0.3.73
Docker:
docker pull ghcr.io/sattyamjjain/agent-audit-kit:v0.3.73
GitHub Action:
- uses: sattyamjjain/agent-audit-kit@v0.3.73
with:
fail-on: high
Supply chain
rules.json— deterministic rule bundlerules.json.sha256— trusted digestsbom.cdx.json/sbom.spdx.json— CycloneDX + SPDX SBOM*.sigstore— Sigstore keyless signatures (verify withagent-audit-kit verify-bundle)
What’s Changed
- Composition-aware capability union, and honest limits on per-skill scanning by @sattyamjjain in https://github.com/sattyamjjain/agent-audit-kit/pull/567
Full Changelog: https://github.com/sattyamjjain/agent-audit-kit/compare/v0.3.72...v0.3.73