Security Audit Pack
★Trusted◇Sandbox optionalv1.0.0MIT✔Verified80by AgentNode · published 5 months ago · toolpack
Scan code for security vulnerabilities using static analysis.
Audit code for OWASP Top 10 vulnerabilities, SQL injection, XSS, and more. Uses Semgrep and Bandit rules for Python, JavaScript, and other languages.
Quick Start
agentnode install security-audit-packRuns in a subprocess with filtered environment by default. Declared permissions are policy-checked, not sandboxed.
Usage
From packagefrom security_audit_pack.tool import run
result = run(
action="audit_security",
path="/workspace/my-api",
language="python",
standards=["owasp-top-10", "cwe-top-25"],
severity_threshold="medium"
)
print(f"Files analyzed: {result['files_analyzed']}")
print(f"Issues found: {result['total_issues']}")
print(f"Critical: {result['severity_counts']['critical']}")
print(f"High: {result['severity_counts']['high']}")
print(f"Medium: {result['severity_counts']['medium']}\n")
for issue in result["issues"][:5]:
print(f"[{issue['severity'].upper()}] {issue['title']}")
print(f" File: {issue['file']}:{issue['line']}")
print(f" CWE: {issue['cwe_id']} — {issue['cwe_name']}")
print(f" Fix: {issue['remediation']}")
print()Runs locally on your machine. No execution data is sent to AgentNode. Permissions are checked before execution. Learn how this works
Verification
Package installs and imports correctly. runtime checks passed.
This package was executed and validated by AgentNode before listing. Install, import, and runtime checks passed.
Verified in real_auto mode
Last verified 29d ago· Runner v2.0.0
Use this when you need to...
- ›Scan Python code for SQL injection and XSS vulnerabilities
- ›Audit Node.js applications against OWASP Top 10 security risks
- ›Detect insecure cryptographic practices in source files
- ›Generate security compliance reports with remediation guidance
- ›Identify unsafe deserialization and command injection patterns
README
Version History
Capabilities
Permissions
Declared by the publisher. Checked before execution by the policy gate.
Permissions are policy-checked before execution. For trusted and curated packages that run on the host, network and filesystem access are policy-checked but not OS-sandboxed. When runtime isolation is required for untrusted/community code, AgentNode uses sandbox-or-fail-closed if the required container runtime and pinned image are available. Learn more
Privacy
All tool execution happens locally on your machine. AgentNode never receives:
- • Tool inputs or outputs
- • Execution logs
- • Data your agent processes
Only install events and search queries are sent to the registry.
agentnode install security-audit-packFiles (3)
License
MITStats
Compatibility
Frameworks
Runtime
pythonPython Version
>=3.10Trust & Security
Publisher
AgentNode
@agentnode