2026-10-11 16:37 UTC

AgentSec Audit's maintainer claims its released static linter detects risky agent configurations and MCP tool declarations through CLI, MCP, and CI interfaces, enabling pre-deployment security gates without executing agents.

state: watchingheat: lowuncertainty: mediumknownscott: lowagentic-security security-auditing agent-harnesseshicklax13

What is this?

AgentSec Audit is an installable static linter by solo maintainer hicklax13 that scans agent system prompts, function-call schemas, and MCP tool declarations — exposed via CLI, a native MCP server, and a GitHub Action — marketed as pre-deployment security gates aligned to the OWASP Agentic Top-10 and ISO 42001/SOC 2, without ever executing the agent. This web round confirms the category is crowded and maturing around it — Invariant Labs' mcp-scan, AgentAuditKit's GitHub Action, mcp-audit, and enterprise-vendor guidance recommending exactly this registration-time scanning — while also independently documenting the technique's known limits: one 2026 audit triaged most of its HIGH static findings (8/8 prompt-injection hits, most code-execution hits) as standard tool instructions or designed functionality rather than real risk, and the Cursor 'MCPoison' CVE (CVE-2025-54136) shows approved tool declarations going silently stale on server updates — precisely the declaration-drift the lone HN commenter raised and something no static pre-deployment gate catches. Nothing in this round validates AgentSec Audit's own detection coverage, false-positive rate, or adoption.

Why it matters to Scott

Already held: Scott's wikis carry both halves of this story — ip:framework.decision-authority-infrastructure and ip:source.compliance-cosplay argue that static linting with ISO 42001/SOC 2 marketing is compliance surface, not the runtime enforcement consequential decisions need, while ip:concept.evaluation-driven-development and ip:source.mcp-as-the-tool-belt-standard-giving-ai-agents-hands-and-eyes-ebook already require binding pre-deployment validation and version-pinned tool declarations. The new grounding only documents the limits his canon predicts (static findings triaged as false positives, Cursor's declaration-drift CVE) and more category churn already tracked via Snyk agent-scan and AgentShield — with the tool itself unvalidated and zero-adoption, nothing here changes what he would build, argue, or publish.
ip:framework.decision-authority-infrastructureip:source.compliance-cosplayip:concept.evaluation-driven-developmentip:source.mcp-as-the-tool-belt-standard-giving-ai-agents-hands-and-eyes-ebookradar:concept.mcp-securityradar:concept.static-analysisradar:concept.agentic-securityradar:snyk-agent-scanradar:agentshield-offline-agent-scannerradar:mcp-schema-drift-audit
queries asked of Scott's wikis
  • evaluation-driven development release gating pre-deployment validation
  • MCP tool belt ebook tool declaration trust and validation requirements
  • decision authority infrastructure runtime enforcement vs static checks
  • agent harness security tool poisoning prompt injection defenses
  • MCP server version pinning declaration drift configuration scanning
  • dev projects linter CI pass/fail gate agent configuration

Measured heat

now 0 pts/hpeak 1 pts/hcomments 0/hpeers p16momentum: steady2 platformsage 514h
points/hour across evidence · reading as of 2026-10-12 02:59:37.977291+11:00 · deterministic, not a model opinion

How the heat travelled

09-20 06:22 (minted)⭐ origin echo-reconstructedThe repository describes deterministic AST and schema linting for agent prompts, function schemas, and MCP declarations, with native MCP acc
hicklax13 on github (echo) · attributed from hn.story.49772914 · published time unknown
—
09-20 06:07first on hacker news · published · lag ?AgentSec Audit
ConnorBHickey13
—
09-20 06:07amplified on hacker news 👑hn.story.49772914
ConnorBHickey13
peak 2 · 1 comments · 60% of case engagement
09-24 17:13amplified on hacker newshn.story.49833750
melalonsra
peak 1 · 0 comments · 21% of case engagement
10-10 12:30amplified on hacker newshn.story.50032282
manveerc
peak 1 · 0 comments · 21% of case engagement
09-20 06:20our radar first saw it · lag ?discovery anchor: hn.story.49772914—
pace: p36 vs 1032 stories at the 336h mark (now 514h old) — ahead of agentgate-signed-agent-receipts (1.3x), behind agent-memory-add-search-evaluation (0.8x)

Evidence (4) — ⭐ canonical anchor

sourceobjectauthorscorecomments
🟧 hnAgentSec Audit
Retrieved article excerpt

Open article · Retrieved 2026-09-20T06:21:48.011116+00:00

# AgentSec Audit

> Automated security scanning, policy linting, and compliance certification for autonomous AI agents, tool configurations, and Model Context Protocol (MCP) servers.

Built for the **OWASP Top 10 for Agentic Applications (2026 ASI01–ASI10)** and **ISO 42001 / SOC 2 Type II** processing integrity audits.

---

## Features

- **Deterministic Static AST & Schema Linter:** Scans system prompts, function calling schemas, and MCP tool declarations.
- **OWASP ASI-10 Rule Enforcement:** Detects arbitrary shell/eval execution, goal hijacking vectors, unbounded delegation depth, and unsanitized memory write loops.
- **Native MCP Interface:** Exposes `audit_agent_config` over stdio JSON-RPC so Hermes Desktop, Claude Code, and Codex can audit agents natively.
- **Turnkey CI/CD:** Ready for GitHub Actions with automated PR pass/fail gating.

---

## Quickstart

### Installation

```
git clone https://github.com/hicklax13/agentsec-audit.git
cd agentsec-audit
pip install -r requirements.txt
```

### Run a Local Security Audit

```
python -m src.cli scan ./sample_agent.json --format html --out report.html
```

---

## GitHub Action Integration

Add this to your repository workflow:

```
name: AgentSec Compliance Check
on: [push, pull_request]

jobs:
  audit:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4
      - uses: hicklax13/agentsec-audit@v1
        with:
          config-path: "agent.json"
          fail-on-violation: "true"
```
ConnorBHickey1321
🟧 echo.github ⭐The repository describes deterministic AST and schema linting for agent prompts, function schemas, and MCP declarations, with native MCP acchicklax13——
🟧 hnShow HN: Guardmcp – I scanned the official MCP registry with a config scannermelalonsra10
🟧 hnPrompt Injection Detection and Defense Tools for Enterprise AI Agentsmanveerc10

Interpretation history

Decision trace