Skip to main content

Security Audit Pack

TrustedSandbox optionalv1.0.0MITVerified80

by AgentNode · published 5 months ago · toolpack

Scan code for security vulnerabilities using static analysis.

Audit code for OWASP Top 10 vulnerabilities, SQL injection, XSS, and more. Uses Semgrep and Bandit rules for Python, JavaScript, and other languages.

langchaincrewaigeneric

Quick Start

bash
agentnode install security-audit-pack

Runs in a subprocess with filtered environment by default. Declared permissions are policy-checked, not sandboxed.

Usage

From package
python
from security_audit_pack.tool import run

result = run(
    action="audit_security",
    path="/workspace/my-api",
    language="python",
    standards=["owasp-top-10", "cwe-top-25"],
    severity_threshold="medium"
)

print(f"Files analyzed: {result['files_analyzed']}")
print(f"Issues found: {result['total_issues']}")
print(f"Critical: {result['severity_counts']['critical']}")
print(f"High: {result['severity_counts']['high']}")
print(f"Medium: {result['severity_counts']['medium']}\n")

for issue in result["issues"][:5]:
    print(f"[{issue['severity'].upper()}] {issue['title']}")
    print(f"  File: {issue['file']}:{issue['line']}")
    print(f"  CWE: {issue['cwe_id']} — {issue['cwe_name']}")
    print(f"  Fix: {issue['remediation']}")
    print()

Runs locally on your machine. No execution data is sent to AgentNode. Permissions are checked before execution. Learn how this works

Verification

high confidence80/100✔ Verified
smokeReturned valid result
+25/25
testsTests failed
0/15
importAll tools imported successfully
+15/15
installInstalled in 1.5s
+15/15
contractAll contract checks passed
+10/10
determinismConsistent output across runs (normalized)
+5/5
reliability3/3 runs passed
+10/10

Package installs and imports correctly. runtime checks passed.

install1.5s
import67ms
smoke606ms
tests1.2s

This package was executed and validated by AgentNode before listing. Install, import, and runtime checks passed.

Verified in real_auto mode

Python 3.12.3ffmpegpopplertesseractuv

Last verified 29d ago· Runner v2.0.0

Use this when you need to...

  • Scan Python code for SQL injection and XSS vulnerabilities
  • Audit Node.js applications against OWASP Top 10 security risks
  • Detect insecure cryptographic practices in source files
  • Generate security compliance reports with remediation guidance
  • Identify unsafe deserialization and command injection patterns

README

Version History

Capabilities

security_auditaudit_securitytool

Permissions

Sandbox optionalFrom a trusted publisher — runs on the host by default. You can require isolation with sandbox.host_trust_policy.

Declared by the publisher. Checked before execution by the policy gate.

Networknone
Filesystemworkspace_read
Code Executionlimited_subprocess
Data Accessinput_only
User Approvalonce

Permissions are policy-checked before execution. For trusted and curated packages that run on the host, network and filesystem access are policy-checked but not OS-sandboxed. When runtime isolation is required for untrusted/community code, AgentNode uses sandbox-or-fail-closed if the required container runtime and pinned image are available. Learn more

Privacy

All tool execution happens locally on your machine. AgentNode never receives:

  • • Tool inputs or outputs
  • • Execution logs
  • • Data your agent processes

Only install events and search queries are sent to the registry.

bash
agentnode install security-audit-pack

Files (3)

License

MIT

Stats

Downloads0
Installs0
Versionv1.0.0
Published3/16/2026
Channelstable
Typetoolpack
Entrypointsecurity_audit_pack.tool

Compatibility

Frameworks

langchaincrewaigeneric

Runtime

python

Python Version

>=3.10

Trust & Security

PublisherTrusted
SignatureNone
ProvenanceNone
Security Issues0

Publisher

A

AgentNode

@agentnode