AgentSec Audit's maintainer claims its released static linter detects risky agent configurations and MCP tool declarations through CLI, MCP, and CI interfaces, enabling pre-deployment security gates without executing agents.
state: watchingheat: lowuncertainty: mediumknownscott: lowagentic-security security-auditing agent-harnesseshicklax13
What is this?
AgentSec Audit is an installable static linter by solo maintainer hicklax13 that scans agent system prompts, function-call schemas, and MCP tool declarations — exposed via CLI, a native MCP server, and a GitHub Action — marketed as pre-deployment security gates aligned to the OWASP Agentic Top-10 and ISO 42001/SOC 2, without ever executing the agent. This web round confirms the category is crowded and maturing around it — Invariant Labs' mcp-scan, AgentAuditKit's GitHub Action, mcp-audit, and enterprise-vendor guidance recommending exactly this registration-time scanning — while also independently documenting the technique's known limits: one 2026 audit triaged most of its HIGH static findings (8/8 prompt-injection hits, most code-execution hits) as standard tool instructions or designed functionality rather than real risk, and the Cursor 'MCPoison' CVE (CVE-2025-54136) shows approved tool declarations going silently stale on server updates — precisely the declaration-drift the lone HN commenter raised and something no static pre-deployment gate catches. Nothing in this round validates AgentSec Audit's own detection coverage, false-positive rate, or adoption.
Why it matters to Scott
Already held: Scott's wikis carry both halves of this story — ip:framework.decision-authority-infrastructure and ip:source.compliance-cosplay argue that static linting with ISO 42001/SOC 2 marketing is compliance surface, not the runtime enforcement consequential decisions need, while ip:concept.evaluation-driven-development and ip:source.mcp-as-the-tool-belt-standard-giving-ai-agents-hands-and-eyes-ebook already require binding pre-deployment validation and version-pinned tool declarations. The new grounding only documents the limits his canon predicts (static findings triaged as false positives, Cursor's declaration-drift CVE) and more category churn already tracked via Snyk agent-scan and AgentShield — with the tool itself unvalidated and zero-adoption, nothing here changes what he would build, argue, or publish.
ip:framework.decision-authority-infrastructureip:source.compliance-cosplayip:concept.evaluation-driven-developmentip:source.mcp-as-the-tool-belt-standard-giving-ai-agents-hands-and-eyes-ebookradar:concept.mcp-securityradar:concept.static-analysisradar:concept.agentic-securityradar:snyk-agent-scanradar:agentshield-offline-agent-scannerradar:mcp-schema-drift-audit
queries asked of Scott's wikis
- evaluation-driven development release gating pre-deployment validation
- MCP tool belt ebook tool declaration trust and validation requirements
- decision authority infrastructure runtime enforcement vs static checks
- agent harness security tool poisoning prompt injection defenses
- MCP server version pinning declaration drift configuration scanning
- dev projects linter CI pass/fail gate agent configuration
Measured heat
now 0 pts/hpeak 1 pts/hcomments 0/hpeers p16momentum: steady2 platformsage 514h
points/hour across evidence · reading as of 2026-10-12 02:59:37.977291+11:00 · deterministic, not a model opinion
How the heat travelled
pace: p36 vs 1032 stories at the 336h mark (now 514h old) — ahead of agentgate-signed-agent-receipts (1.3x), behind agent-memory-add-search-evaluation (0.8x)
Evidence (4) — ⭐ canonical anchor
| source | object | author | score | comments |
| 🟧 hn | AgentSec AuditRetrieved article excerptOpen article · Retrieved 2026-09-20T06:21:48.011116+00:00 # AgentSec Audit
> Automated security scanning, policy linting, and compliance certification for autonomous AI agents, tool configurations, and Model Context Protocol (MCP) servers.
Built for the **OWASP Top 10 for Agentic Applications (2026 ASI01–ASI10)** and **ISO 42001 / SOC 2 Type II** processing integrity audits.
---
## Features
- **Deterministic Static AST & Schema Linter:** Scans system prompts, function calling schemas, and MCP tool declarations.
- **OWASP ASI-10 Rule Enforcement:** Detects arbitrary shell/eval execution, goal hijacking vectors, unbounded delegation depth, and unsanitized memory write loops.
- **Native MCP Interface:** Exposes `audit_agent_config` over stdio JSON-RPC so Hermes Desktop, Claude Code, and Codex can audit agents natively.
- **Turnkey CI/CD:** Ready for GitHub Actions with automated PR pass/fail gating.
---
## Quickstart
### Installation
```
git clone https://github.com/hicklax13/agentsec-audit.git
cd agentsec-audit
pip install -r requirements.txt
```
### Run a Local Security Audit
```
python -m src.cli scan ./sample_agent.json --format html --out report.html
```
---
## GitHub Action Integration
Add this to your repository workflow:
```
name: AgentSec Compliance Check
on: [push, pull_request]
jobs:
audit:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: hicklax13/agentsec-audit@v1
with:
config-path: "agent.json"
fail-on-violation: "true"
``` | ConnorBHickey13 | 2 | 1 |
| 🟧 echo.github ⭐ | The repository describes deterministic AST and schema linting for agent prompts, function schemas, and MCP declarations, with native MCP acc | hicklax13 | — | — |
| 🟧 hn | Show HN: Guardmcp – I scanned the official MCP registry with a config scanner | melalonsra | 1 | 0 |
| 🟧 hn | Prompt Injection Detection and Defense Tools for Enterprise AI Agents | manveerc | 1 | 0 |
Interpretation history
2026-10-10T14:19:19Z
New Arcade.dev blog post (hn.story.50032282) adds a third data point to the static agent-config auditing category but does not validate AgentSec Audit's detection coverage, false-positive rate, or adoption — it is more category corroboration, not tool validation. The case remains a cold, unvalidated solo project inside a hot topic band.
2026-10-10T13:39:44Z
evidence attached: hn.story.50032282 — Arcade.dev blog post on prompt injection detection tools for enterprise agents directly relates to static security auditing of agent configurations
2026-09-24T22:22:28Z
grounded: known/low — Already held: Scott's wikis carry both halves of this story — ip:framework.decision-authority-infrastructure and ip:source.compliance-cosplay argue that static
2026-09-24T22:15:50Z
Guardmcp's independent scan of the official MCP registry makes static MCP config auditing a two-implementation practice rather than one maintainer's project, lifting the case from seed to watching — but it corroborates the technique category, not AgentSec Audit's detection claims, which remain unvalidated. Both submissions flatlined at bottom-quartile velocity, so the case parks as a low-signal instance inside a hot category.
2026-09-24T20:37:40Z
evidence attached: hn.story.49833750 — A second independent static MCP config scanner, applied to the official registry, corroborates the emerging static MCP configuration-auditing episode carried by this case.
2026-09-20T06:25:53Z
grounded: known/low — The claimed pre-deployment checks repeat Scott’s Evaluation-Driven Development position on binding release gates and his MCP Tool Belt ebook’s requirement for s
2026-09-20T06:22:12Z
case created — An installable first-party artifact establishes a distinct tooling episode, but its advertised detection coverage and compliance claims remain unvalidated.
Decision trace
- 10-11 01:19repriceNew Arcade.dev blog post (hn.story.50032282) adds a third data point to the static agent-config auditing category but does not validate AgentSec Audit's detection coverage, false-positive rate, o
- 10-11 00:43attention_routeThe editor compared this story and chose to keep watching.
- 10-11 00:39attention_candidateattach
- 10-11 00:39attachArcade.dev blog post on prompt injection detection tools for enterprise agents directly relates to static security auditing of agent configurations
- 10-11 00:39propose_attachArcade.dev blog post on prompt injection detection tools for enterprise agents directly relates to static security auditing of agent configurations
- 09-25 08:22repriceGuardmcp's independent scan of the official MCP registry makes static MCP config auditing a two-implementation practice rather than one maintainer's project, lifting the case from seed to wa
- 09-25 08:22groundAlready held: Scott's wikis carry both halves of this story — ip:framework.decision-authority-infrastructure and ip:source.compliance-cosplay argue that static linting with ISO 42001/SOC 2 market
- 09-25 06:37attachA second independent static MCP config scanner, applied to the official registry, corroborates the emerging static MCP configuration-auditing episode carried by this case.
- 09-25 06:28propose_attachA second independent static MCP config scanner, applied to the official registry, corroborates the emerging static MCP configuration-auditing episode carried by this case.
- 09-20 23:40review_screenThe new comment raises a general concern about MCP tool declaration drift but provides no new implementation result, credible contradiction, release, access change, or first-hand evidence about AgentS
- 09-20 16:25groundThe claimed pre-deployment checks repeat Scott’s Evaluation-Driven Development position on binding release gates and his MCP Tool Belt ebook’s requirement for security controls around tool access; sta
- 09-20 16:22createAn installable first-party artifact establishes a distinct tooling episode, but its advertised detection coverage and compliance claims remain unvalidated.