AgentAuditKit MCP Security Scan
Version updated for https://github.com/sattyamjjain/agent-audit-kit to version v0.3.80.
- This action is used across all versions by ? repositories.
Action Type
This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary
AgentAuditKit is a security scanner designed to detect misconfigurations, hardcoded secrets, tool poisoning, and other vulnerabilities in AI agent pipelines. It runs offline and deterministically, ensuring that the same input always yields the same findings. Additionally, it produces auditor-ready compliance-evidence packs, including SARIF for GitHub Security tab and PDF reports mapped to multiple security frameworks.
What’s Changed
Installation
pip:
pip install agent-audit-kit==v0.3.80
Docker:
docker pull ghcr.io/sattyamjjain/agent-audit-kit:v0.3.80
GitHub Action:
- uses: sattyamjjain/agent-audit-kit@v0.3.80
with:
fail-on: high
Supply chain
rules.json— deterministic rule bundlerules.json.sha256— trusted digestsbom.cdx.json/sbom.spdx.json— CycloneDX + SPDX SBOM*.sigstore— Sigstore keyless signatures (verify withagent-audit-kit verify-bundle)
What’s Changed
- Detect unauthenticated MCP sidecar dashboards, and stop reading double quotes as a shell mitigation by @sattyamjjain in https://github.com/sattyamjjain/agent-audit-kit/pull/606
Full Changelog: https://github.com/sattyamjjain/agent-audit-kit/compare/v0.3.79...v0.3.80