PermitGraph

CIAgent PermitLicensePython

Pre-flight security checks for AI coding agents.

PermitGraph scans a repository before agents receive tools, secrets, memory, MCP servers, or CI write access. It returns a clear permit decision: approved, needs_review, or blocked, with evidence a reviewer can inspect.

Run it before enabling Codex, Claude, Cursor, GitHub Actions agents, LangGraph/LangChain agents, or MCP tools inside sensitive repositories.

PermitGraph preview

Why This Exists

AI teams are wiring coding agents, MCP servers, CI workflows, repo instructions, and long-lived credentials into the same repos. Normal code review does not show whether an agent can reach a secret, write to a protected branch, follow unsafe repository instructions, or pass repo context into an external tool.

PermitGraph turns those agent-access facts into reviewable evidence before the agent runs.

60-Second Scan

Install dependencies:

uv sync --all-extras --dev

Scan a repository:

uv run agent-permit scan . --ci --exclude "tests/fixtures/**"

Open the generated evidence:

.agent-permit/runs/<run_id>/summary.md
.agent-permit/runs/<run_id>/permit.yaml
.agent-permit/runs/<run_id>/raw-findings.json
.agent-permit/runs/<run_id>/graph-paths.json

The scanner is static. It does not execute agent code, MCP servers, CI workflows, package scripts, or external tools.

What A Finding Looks Like

Plain-English result:

Status: needs_review
Review CI secrets and write permissions in github-mcp-server.
Why: a workflow references CI secrets and also has write permissions.
Reviewer question: should this automation be allowed before agent access continues?
Evidence: .github/workflows/agent.yml:18
Next step: use least-privilege workflow permissions or document an exception.

Machine-readable artifacts preserve the same evidence for CI, dashboards, proof packs, SARIF, and AI review.

Public Proof Artifacts

The repository includes sanitized fixture scans so reviewers can inspect real output without running private code:

FixtureStatusPurpose
safe-agentapprovedShows a clean repository passing the configured agent-access checks.
risky-ci-agentblockedShows a privileged pull request workflow with write access being stopped.
risky-mcp-agentneeds_reviewShows an MCP server receiving a credential reference and requiring human review.

Start with the public fixture manifest, then inspect the blocked CI summary, permit, raw findings, and finding baseline.

Regenerate them with:

uv run python tools/build_public_demo_artifacts.py

What It Checks

  • MCP server configuration and tool boundaries
  • CI workflow permissions and secret references
  • repository instructions for AI tools
  • credential-bearing environment references
  • generated agent artifacts
  • source-to-sink paths in the Agent Capability Graph
  • policy controls before access approval

How It Fits With Other Tools

ToolMain jobPermitGraph job
TrivyFind vulnerabilities, misconfigurations, secrets, and SBOM issues.Decide whether AI agents should receive repo/tool/credential access.
SemgrepFind code and security patterns across source files.Connect repo instructions, MCP config, CI permissions, and credentials into agent-access findings.
OPAEnforce general policy as code.Provide a domain-specific scanner and artifacts for AI agent access review.
LangSmithObserve, evaluate, and debug agents after or during execution.Gate access before the agent receives dangerous capabilities.

PermitGraph is not a replacement for SAST, dependency scanning, secrets scanning, or LLM observability. It is the missing review gate for agent permissions.

Deep Agent Review

Deep Agent review is part of the product path, not a side demo.

The deterministic scanner creates bounded evidence. The Deep Agent reads that evidence, reasons across related artifacts, writes a cited report, and the citation critic checks whether claims are grounded.

Run from an existing scan:

export OPENROUTER_API_KEY=<key>
uv run --extra deep-agent agent-permit investigate .agent-permit/runs/<run_id>

Offline deterministic fallback for tests or no-key debugging:

uv run agent-permit investigate .agent-permit/runs/<run_id> --deterministic-only

Default live-model path uses Claude Sonnet through OpenRouter. Prompt caching, response caching, timeout caps, completion caps, token metrics, and cache-hit metrics are recorded in local run artifacts.

GitHub Action

Use PermitGraph in pull requests before risky agent-access changes merge:

name: PermitGraphon:
pull_request:
permissions:
contents: readsecurity-events: writejobs:
scan:
runs-on: ubuntu-lateststeps:
- uses: actions/checkout@v6with:
persist-credentials: false
- uses: IntelIP/agent-permit-office@mainwith:
path: .exclude: | tests/fixtures/**sarif: "true"upload-sarif: "true"

Proof Packs

Generate dashboard data and a shareable proof pack:

python3 tools/export_dashboard_snapshot.py
python3 tools/export_dashboard_snapshot.py --proof-pack

The proof pack exporter prints both paths:

.agent-permit/proof-packs/<validation_run_id>
.agent-permit/proof-packs/<validation_run_id>.zip

Proof packs are redacted, but still sensitive. Review them before sharing.

Local Apps

Run the local dashboard:

cd dashboard
bun install
bun dev

Use the dashboard Queue scan flow with a GitHub repository URL. The hosted dashboard writes the job to the Worker API; the local CLI runner clones the repo and runs the scanner:

set -a;source .env;set +a
uv run --extra db --extra deep-agent agent-permit runner --once --deep-agent auto --agent-recursion-limit 20

Run the documentation site:

cd docs-site
bun install
bun dev

Then open http://localhost:3000/docs or the next free port printed by Next.js.

Common Commands

uv run agent-permit rules
uv run agent-permit scan . --ci --sarif
uv run agent-permit sarif .agent-permit/runs/<run_id>
uv run agent-permit baseline .agent-permit/runs/<run_id> --output .agent-permit/finding-baseline.json
uv run agent-permit scan . --ci --baseline .agent-permit/finding-baseline.json --ci-new-findings-only
uv run agent-permit scan . --ci --policy agent-permit-policy.json
uv run agent-permit analytics summarize .
uv run agent-permit eval tests/fixtures
uv run --extra phoenix agent-permit eval tests/fixtures --upload-phoenix

Open-Core Boundary

Open-source core:

  • deterministic scanner and rule registry
  • Agent Capability Graph builder and risky path finder
  • permit engine and local artifact schemas
  • Markdown, JSON, YAML, SARIF, baseline, diff, policy, metrics, and eval outputs
  • bounded Deep Agent evidence tools, prompt flow, and citation critic
  • OpenRouter adapter with local cost/cache telemetry
  • Phoenix local tracing and eval export support
  • GitHub Action and local dashboard snapshot workflow

Hosted product roadmap:

  • multi-repo queue and team review workflow
  • private repo connectors and scheduled scans
  • SSO/RBAC, assignments, approval history, and audit retention
  • managed model gateway, model policy, key isolation, and spend controls
  • policy packs, custom rules, notifications, support, and SLA

The hosted product is not required to use the local scanner. Commercial value is managed workflow, governance, retention, and integrations, not hiding scanner logic.

Safety Boundaries

  • Static scanning only: no agent, MCP server, CI workflow, package script, or external tool execution during scans.
  • Real .env files and generated/junk directories are skipped.
  • Secret values are not emitted; evidence may include secret variable names when needed for risk explanation.
  • Proof packs copy only allowlisted artifacts and apply redaction before export.
  • Deep Agent output explains scanner artifacts. It does not replace scanner evidence.

Documentation

Developer docs:

Planning and research archives live in docs/.

Contributing

Good first contribution areas:

  • deterministic rule improvements
  • false-positive reductions
  • fixture coverage
  • SARIF output improvements
  • GitHub Action hardening
  • documentation and demo clarity

Read CONTRIBUTING.md, SECURITY.md, and SUPPORT.md before opening issues or pull requests. Do not paste secrets, private code, raw traces, or customer data into public issues.

Verification

Run the public-release check:

python3 tools/release_check.py

Core checks:

uv run pytest -q
cd docs-site && bun run build

About

Pre-flight security checks for AI coding agents before tools, secrets, memory, MCP, or CI write access.

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

PermitGraph

CIAgent PermitLicensePython

Pre-flight security checks for AI coding agents.

PermitGraph scans a repository before agents receive tools, secrets, memory, MCP servers, or CI write access. It returns a clear permit decision: approved, needs_review, or blocked, with evidence a reviewer can inspect.

Run it before enabling Codex, Claude, Cursor, GitHub Actions agents, LangGraph/LangChain agents, or MCP tools inside sensitive repositories.

PermitGraph preview

Why This Exists

AI teams are wiring coding agents, MCP servers, CI workflows, repo instructions, and long-lived credentials into the same repos. Normal code review does not show whether an agent can reach a secret, write to a protected branch, follow unsafe repository instructions, or pass repo context into an external tool.

PermitGraph turns those agent-access facts into reviewable evidence before the agent runs.

60-Second Scan

Install dependencies:

uv sync --all-extras --dev

Scan a repository:

uv run agent-permit scan . --ci --exclude "tests/fixtures/**"

Open the generated evidence:

.agent-permit/runs/<run_id>/summary.md
.agent-permit/runs/<run_id>/permit.yaml
.agent-permit/runs/<run_id>/raw-findings.json
.agent-permit/runs/<run_id>/graph-paths.json

The scanner is static. It does not execute agent code, MCP servers, CI workflows, package scripts, or external tools.

What A Finding Looks Like

Plain-English result:

Status: needs_review
Review CI secrets and write permissions in github-mcp-server.
Why: a workflow references CI secrets and also has write permissions.
Reviewer question: should this automation be allowed before agent access continues?
Evidence: .github/workflows/agent.yml:18
Next step: use least-privilege workflow permissions or document an exception.

Machine-readable artifacts preserve the same evidence for CI, dashboards, proof packs, SARIF, and AI review.

Public Proof Artifacts

The repository includes sanitized fixture scans so reviewers can inspect real output without running private code:

FixtureStatusPurpose
safe-agentapprovedShows a clean repository passing the configured agent-access checks.
risky-ci-agentblockedShows a privileged pull request workflow with write access being stopped.
risky-mcp-agentneeds_reviewShows an MCP server receiving a credential reference and requiring human review.

Start with the public fixture manifest, then inspect the blocked CI summary, permit, raw findings, and finding baseline.

Regenerate them with:

uv run python tools/build_public_demo_artifacts.py

What It Checks

  • MCP server configuration and tool boundaries
  • CI workflow permissions and secret references
  • repository instructions for AI tools
  • credential-bearing environment references
  • generated agent artifacts
  • source-to-sink paths in the Agent Capability Graph
  • policy controls before access approval

How It Fits With Other Tools

ToolMain jobPermitGraph job
TrivyFind vulnerabilities, misconfigurations, secrets, and SBOM issues.Decide whether AI agents should receive repo/tool/credential access.
SemgrepFind code and security patterns across source files.Connect repo instructions, MCP config, CI permissions, and credentials into agent-access findings.
OPAEnforce general policy as code.Provide a domain-specific scanner and artifacts for AI agent access review.
LangSmithObserve, evaluate, and debug agents after or during execution.Gate access before the agent receives dangerous capabilities.

PermitGraph is not a replacement for SAST, dependency scanning, secrets scanning, or LLM observability. It is the missing review gate for agent permissions.

Deep Agent Review

Deep Agent review is part of the product path, not a side demo.

The deterministic scanner creates bounded evidence. The Deep Agent reads that evidence, reasons across related artifacts, writes a cited report, and the citation critic checks whether claims are grounded.

Run from an existing scan:

export OPENROUTER_API_KEY=<key>
uv run --extra deep-agent agent-permit investigate .agent-permit/runs/<run_id>

Offline deterministic fallback for tests or no-key debugging:

uv run agent-permit investigate .agent-permit/runs/<run_id> --deterministic-only

Default live-model path uses Claude Sonnet through OpenRouter. Prompt caching, response caching, timeout caps, completion caps, token metrics, and cache-hit metrics are recorded in local run artifacts.

GitHub Action

Use PermitGraph in pull requests before risky agent-access changes merge:

name: PermitGraphon:
pull_request:
permissions:
contents: readsecurity-events: writejobs:
scan:
runs-on: ubuntu-lateststeps:
- uses: actions/checkout@v6with:
persist-credentials: false
- uses: IntelIP/agent-permit-office@mainwith:
path: .exclude: | tests/fixtures/**sarif: "true"upload-sarif: "true"

Proof Packs

Generate dashboard data and a shareable proof pack:

python3 tools/export_dashboard_snapshot.py
python3 tools/export_dashboard_snapshot.py --proof-pack

The proof pack exporter prints both paths:

.agent-permit/proof-packs/<validation_run_id>
.agent-permit/proof-packs/<validation_run_id>.zip

Proof packs are redacted, but still sensitive. Review them before sharing.

Local Apps

Run the local dashboard:

cd dashboard
bun install
bun dev

Use the dashboard Queue scan flow with a GitHub repository URL. The hosted dashboard writes the job to the Worker API; the local CLI runner clones the repo and runs the scanner:

set -a;source .env;set +a
uv run --extra db --extra deep-agent agent-permit runner --once --deep-agent auto --agent-recursion-limit 20

Run the documentation site:

cd docs-site
bun install
bun dev

Then open http://localhost:3000/docs or the next free port printed by Next.js.

Common Commands

uv run agent-permit rules
uv run agent-permit scan . --ci --sarif
uv run agent-permit sarif .agent-permit/runs/<run_id>
uv run agent-permit baseline .agent-permit/runs/<run_id> --output .agent-permit/finding-baseline.json
uv run agent-permit scan . --ci --baseline .agent-permit/finding-baseline.json --ci-new-findings-only
uv run agent-permit scan . --ci --policy agent-permit-policy.json
uv run agent-permit analytics summarize .
uv run agent-permit eval tests/fixtures
uv run --extra phoenix agent-permit eval tests/fixtures --upload-phoenix

Open-Core Boundary

Open-source core:

  • deterministic scanner and rule registry
  • Agent Capability Graph builder and risky path finder
  • permit engine and local artifact schemas
  • Markdown, JSON, YAML, SARIF, baseline, diff, policy, metrics, and eval outputs
  • bounded Deep Agent evidence tools, prompt flow, and citation critic
  • OpenRouter adapter with local cost/cache telemetry
  • Phoenix local tracing and eval export support
  • GitHub Action and local dashboard snapshot workflow

Hosted product roadmap:

  • multi-repo queue and team review workflow
  • private repo connectors and scheduled scans
  • SSO/RBAC, assignments, approval history, and audit retention
  • managed model gateway, model policy, key isolation, and spend controls
  • policy packs, custom rules, notifications, support, and SLA

The hosted product is not required to use the local scanner. Commercial value is managed workflow, governance, retention, and integrations, not hiding scanner logic.

Safety Boundaries

  • Static scanning only: no agent, MCP server, CI workflow, package script, or external tool execution during scans.
  • Real .env files and generated/junk directories are skipped.
  • Secret values are not emitted; evidence may include secret variable names when needed for risk explanation.
  • Proof packs copy only allowlisted artifacts and apply redaction before export.
  • Deep Agent output explains scanner artifacts. It does not replace scanner evidence.

Documentation

Developer docs:

Planning and research archives live in docs/.

Contributing

Good first contribution areas:

  • deterministic rule improvements
  • false-positive reductions
  • fixture coverage
  • SARIF output improvements
  • GitHub Action hardening
  • documentation and demo clarity

Read CONTRIBUTING.md, SECURITY.md, and SUPPORT.md before opening issues or pull requests. Do not paste secrets, private code, raw traces, or customer data into public issues.

Verification

Run the public-release check:

python3 tools/release_check.py

Core checks:

uv run pytest -q
cd docs-site && bun run build

About

Pre-flight security checks for AI coding agents before tools, secrets, memory, MCP, or CI write access.

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

PermitGraph

CIAgent PermitLicensePython

Pre-flight security checks for AI coding agents.

PermitGraph scans a repository before agents receive tools, secrets, memory, MCP servers, or CI write access. It returns a clear permit decision: approved, needs_review, or blocked, with evidence a reviewer can inspect.

Run it before enabling Codex, Claude, Cursor, GitHub Actions agents, LangGraph/LangChain agents, or MCP tools inside sensitive repositories.

PermitGraph preview

Why This Exists

AI teams are wiring coding agents, MCP servers, CI workflows, repo instructions, and long-lived credentials into the same repos. Normal code review does not show whether an agent can reach a secret, write to a protected branch, follow unsafe repository instructions, or pass repo context into an external tool.

PermitGraph turns those agent-access facts into reviewable evidence before the agent runs.

60-Second Scan

Install dependencies:

uv sync --all-extras --dev

Scan a repository:

uv run agent-permit scan . --ci --exclude "tests/fixtures/**"

Open the generated evidence:

.agent-permit/runs/<run_id>/summary.md
.agent-permit/runs/<run_id>/permit.yaml
.agent-permit/runs/<run_id>/raw-findings.json
.agent-permit/runs/<run_id>/graph-paths.json

The scanner is static. It does not execute agent code, MCP servers, CI workflows, package scripts, or external tools.

What A Finding Looks Like

Plain-English result:

Status: needs_review
Review CI secrets and write permissions in github-mcp-server.
Why: a workflow references CI secrets and also has write permissions.
Reviewer question: should this automation be allowed before agent access continues?
Evidence: .github/workflows/agent.yml:18
Next step: use least-privilege workflow permissions or document an exception.

Machine-readable artifacts preserve the same evidence for CI, dashboards, proof packs, SARIF, and AI review.

Public Proof Artifacts

The repository includes sanitized fixture scans so reviewers can inspect real output without running private code:

FixtureStatusPurpose
safe-agentapprovedShows a clean repository passing the configured agent-access checks.
risky-ci-agentblockedShows a privileged pull request workflow with write access being stopped.
risky-mcp-agentneeds_reviewShows an MCP server receiving a credential reference and requiring human review.

Start with the public fixture manifest, then inspect the blocked CI summary, permit, raw findings, and finding baseline.

Regenerate them with:

uv run python tools/build_public_demo_artifacts.py

What It Checks

  • MCP server configuration and tool boundaries
  • CI workflow permissions and secret references
  • repository instructions for AI tools
  • credential-bearing environment references
  • generated agent artifacts
  • source-to-sink paths in the Agent Capability Graph
  • policy controls before access approval

How It Fits With Other Tools

ToolMain jobPermitGraph job
TrivyFind vulnerabilities, misconfigurations, secrets, and SBOM issues.Decide whether AI agents should receive repo/tool/credential access.
SemgrepFind code and security patterns across source files.Connect repo instructions, MCP config, CI permissions, and credentials into agent-access findings.
OPAEnforce general policy as code.Provide a domain-specific scanner and artifacts for AI agent access review.
LangSmithObserve, evaluate, and debug agents after or during execution.Gate access before the agent receives dangerous capabilities.

PermitGraph is not a replacement for SAST, dependency scanning, secrets scanning, or LLM observability. It is the missing review gate for agent permissions.

Deep Agent Review

Deep Agent review is part of the product path, not a side demo.

The deterministic scanner creates bounded evidence. The Deep Agent reads that evidence, reasons across related artifacts, writes a cited report, and the citation critic checks whether claims are grounded.

Run from an existing scan:

export OPENROUTER_API_KEY=<key>
uv run --extra deep-agent agent-permit investigate .agent-permit/runs/<run_id>

Offline deterministic fallback for tests or no-key debugging:

uv run agent-permit investigate .agent-permit/runs/<run_id> --deterministic-only

Default live-model path uses Claude Sonnet through OpenRouter. Prompt caching, response caching, timeout caps, completion caps, token metrics, and cache-hit metrics are recorded in local run artifacts.

GitHub Action

Use PermitGraph in pull requests before risky agent-access changes merge:

name: PermitGraphon:
pull_request:
permissions:
contents: readsecurity-events: writejobs:
scan:
runs-on: ubuntu-lateststeps:
- uses: actions/checkout@v6with:
persist-credentials: false
- uses: IntelIP/agent-permit-office@mainwith:
path: .exclude: | tests/fixtures/**sarif: "true"upload-sarif: "true"

Proof Packs

Generate dashboard data and a shareable proof pack:

python3 tools/export_dashboard_snapshot.py
python3 tools/export_dashboard_snapshot.py --proof-pack

The proof pack exporter prints both paths:

.agent-permit/proof-packs/<validation_run_id>
.agent-permit/proof-packs/<validation_run_id>.zip

Proof packs are redacted, but still sensitive. Review them before sharing.

Local Apps

Run the local dashboard:

cd dashboard
bun install
bun dev

Use the dashboard Queue scan flow with a GitHub repository URL. The hosted dashboard writes the job to the Worker API; the local CLI runner clones the repo and runs the scanner:

set -a;source .env;set +a
uv run --extra db --extra deep-agent agent-permit runner --once --deep-agent auto --agent-recursion-limit 20

Run the documentation site:

cd docs-site
bun install
bun dev

Then open http://localhost:3000/docs or the next free port printed by Next.js.

Common Commands

uv run agent-permit rules
uv run agent-permit scan . --ci --sarif
uv run agent-permit sarif .agent-permit/runs/<run_id>
uv run agent-permit baseline .agent-permit/runs/<run_id> --output .agent-permit/finding-baseline.json
uv run agent-permit scan . --ci --baseline .agent-permit/finding-baseline.json --ci-new-findings-only
uv run agent-permit scan . --ci --policy agent-permit-policy.json
uv run agent-permit analytics summarize .
uv run agent-permit eval tests/fixtures
uv run --extra phoenix agent-permit eval tests/fixtures --upload-phoenix

Open-Core Boundary

Open-source core:

  • deterministic scanner and rule registry
  • Agent Capability Graph builder and risky path finder
  • permit engine and local artifact schemas
  • Markdown, JSON, YAML, SARIF, baseline, diff, policy, metrics, and eval outputs
  • bounded Deep Agent evidence tools, prompt flow, and citation critic
  • OpenRouter adapter with local cost/cache telemetry
  • Phoenix local tracing and eval export support
  • GitHub Action and local dashboard snapshot workflow

Hosted product roadmap:

  • multi-repo queue and team review workflow
  • private repo connectors and scheduled scans
  • SSO/RBAC, assignments, approval history, and audit retention
  • managed model gateway, model policy, key isolation, and spend controls
  • policy packs, custom rules, notifications, support, and SLA

The hosted product is not required to use the local scanner. Commercial value is managed workflow, governance, retention, and integrations, not hiding scanner logic.

Safety Boundaries

  • Static scanning only: no agent, MCP server, CI workflow, package script, or external tool execution during scans.
  • Real .env files and generated/junk directories are skipped.
  • Secret values are not emitted; evidence may include secret variable names when needed for risk explanation.
  • Proof packs copy only allowlisted artifacts and apply redaction before export.
  • Deep Agent output explains scanner artifacts. It does not replace scanner evidence.

Documentation

Developer docs:

Planning and research archives live in docs/.

Contributing

Good first contribution areas:

  • deterministic rule improvements
  • false-positive reductions
  • fixture coverage
  • SARIF output improvements
  • GitHub Action hardening
  • documentation and demo clarity

Read CONTRIBUTING.md, SECURITY.md, and SUPPORT.md before opening issues or pull requests. Do not paste secrets, private code, raw traces, or customer data into public issues.

Verification

Run the public-release check:

python3 tools/release_check.py

Core checks:

uv run pytest -q
cd docs-site && bun run build

About

Pre-flight security checks for AI coding agents before tools, secrets, memory, MCP, or CI write access.

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

PermitGraph

CIAgent PermitLicensePython

Pre-flight security checks for AI coding agents.

PermitGraph scans a repository before agents receive tools, secrets, memory, MCP servers, or CI write access. It returns a clear permit decision: approved, needs_review, or blocked, with evidence a reviewer can inspect.

Run it before enabling Codex, Claude, Cursor, GitHub Actions agents, LangGraph/LangChain agents, or MCP tools inside sensitive repositories.

PermitGraph preview

Why This Exists

AI teams are wiring coding agents, MCP servers, CI workflows, repo instructions, and long-lived credentials into the same repos. Normal code review does not show whether an agent can reach a secret, write to a protected branch, follow unsafe repository instructions, or pass repo context into an external tool.

PermitGraph turns those agent-access facts into reviewable evidence before the agent runs.

60-Second Scan

Install dependencies:

uv sync --all-extras --dev

Scan a repository:

uv run agent-permit scan . --ci --exclude "tests/fixtures/**"

Open the generated evidence:

.agent-permit/runs/<run_id>/summary.md
.agent-permit/runs/<run_id>/permit.yaml
.agent-permit/runs/<run_id>/raw-findings.json
.agent-permit/runs/<run_id>/graph-paths.json

The scanner is static. It does not execute agent code, MCP servers, CI workflows, package scripts, or external tools.

What A Finding Looks Like

Plain-English result:

Status: needs_review
Review CI secrets and write permissions in github-mcp-server.
Why: a workflow references CI secrets and also has write permissions.
Reviewer question: should this automation be allowed before agent access continues?
Evidence: .github/workflows/agent.yml:18
Next step: use least-privilege workflow permissions or document an exception.

Machine-readable artifacts preserve the same evidence for CI, dashboards, proof packs, SARIF, and AI review.

Public Proof Artifacts

The repository includes sanitized fixture scans so reviewers can inspect real output without running private code:

FixtureStatusPurpose
safe-agentapprovedShows a clean repository passing the configured agent-access checks.
risky-ci-agentblockedShows a privileged pull request workflow with write access being stopped.
risky-mcp-agentneeds_reviewShows an MCP server receiving a credential reference and requiring human review.

Start with the public fixture manifest, then inspect the blocked CI summary, permit, raw findings, and finding baseline.

Regenerate them with:

uv run python tools/build_public_demo_artifacts.py

What It Checks

  • MCP server configuration and tool boundaries
  • CI workflow permissions and secret references
  • repository instructions for AI tools
  • credential-bearing environment references
  • generated agent artifacts
  • source-to-sink paths in the Agent Capability Graph
  • policy controls before access approval

How It Fits With Other Tools

ToolMain jobPermitGraph job
TrivyFind vulnerabilities, misconfigurations, secrets, and SBOM issues.Decide whether AI agents should receive repo/tool/credential access.
SemgrepFind code and security patterns across source files.Connect repo instructions, MCP config, CI permissions, and credentials into agent-access findings.
OPAEnforce general policy as code.Provide a domain-specific scanner and artifacts for AI agent access review.
LangSmithObserve, evaluate, and debug agents after or during execution.Gate access before the agent receives dangerous capabilities.

PermitGraph is not a replacement for SAST, dependency scanning, secrets scanning, or LLM observability. It is the missing review gate for agent permissions.

Deep Agent Review

Deep Agent review is part of the product path, not a side demo.

The deterministic scanner creates bounded evidence. The Deep Agent reads that evidence, reasons across related artifacts, writes a cited report, and the citation critic checks whether claims are grounded.

Run from an existing scan:

export OPENROUTER_API_KEY=<key>
uv run --extra deep-agent agent-permit investigate .agent-permit/runs/<run_id>

Offline deterministic fallback for tests or no-key debugging:

uv run agent-permit investigate .agent-permit/runs/<run_id> --deterministic-only

Default live-model path uses Claude Sonnet through OpenRouter. Prompt caching, response caching, timeout caps, completion caps, token metrics, and cache-hit metrics are recorded in local run artifacts.

GitHub Action

Use PermitGraph in pull requests before risky agent-access changes merge:

name: PermitGraphon:
pull_request:
permissions:
contents: readsecurity-events: writejobs:
scan:
runs-on: ubuntu-lateststeps:
- uses: actions/checkout@v6with:
persist-credentials: false
- uses: IntelIP/agent-permit-office@mainwith:
path: .exclude: | tests/fixtures/**sarif: "true"upload-sarif: "true"

Proof Packs

Generate dashboard data and a shareable proof pack:

python3 tools/export_dashboard_snapshot.py
python3 tools/export_dashboard_snapshot.py --proof-pack

The proof pack exporter prints both paths:

.agent-permit/proof-packs/<validation_run_id>
.agent-permit/proof-packs/<validation_run_id>.zip

Proof packs are redacted, but still sensitive. Review them before sharing.

Local Apps

Run the local dashboard:

cd dashboard
bun install
bun dev

Use the dashboard Queue scan flow with a GitHub repository URL. The hosted dashboard writes the job to the Worker API; the local CLI runner clones the repo and runs the scanner:

set -a;source .env;set +a
uv run --extra db --extra deep-agent agent-permit runner --once --deep-agent auto --agent-recursion-limit 20

Run the documentation site:

cd docs-site
bun install
bun dev

Then open http://localhost:3000/docs or the next free port printed by Next.js.

Common Commands

uv run agent-permit rules
uv run agent-permit scan . --ci --sarif
uv run agent-permit sarif .agent-permit/runs/<run_id>
uv run agent-permit baseline .agent-permit/runs/<run_id> --output .agent-permit/finding-baseline.json
uv run agent-permit scan . --ci --baseline .agent-permit/finding-baseline.json --ci-new-findings-only
uv run agent-permit scan . --ci --policy agent-permit-policy.json
uv run agent-permit analytics summarize .
uv run agent-permit eval tests/fixtures
uv run --extra phoenix agent-permit eval tests/fixtures --upload-phoenix

Open-Core Boundary

Open-source core:

  • deterministic scanner and rule registry
  • Agent Capability Graph builder and risky path finder
  • permit engine and local artifact schemas
  • Markdown, JSON, YAML, SARIF, baseline, diff, policy, metrics, and eval outputs
  • bounded Deep Agent evidence tools, prompt flow, and citation critic
  • OpenRouter adapter with local cost/cache telemetry
  • Phoenix local tracing and eval export support
  • GitHub Action and local dashboard snapshot workflow

Hosted product roadmap:

  • multi-repo queue and team review workflow
  • private repo connectors and scheduled scans
  • SSO/RBAC, assignments, approval history, and audit retention
  • managed model gateway, model policy, key isolation, and spend controls
  • policy packs, custom rules, notifications, support, and SLA

The hosted product is not required to use the local scanner. Commercial value is managed workflow, governance, retention, and integrations, not hiding scanner logic.

Safety Boundaries

  • Static scanning only: no agent, MCP server, CI workflow, package script, or external tool execution during scans.
  • Real .env files and generated/junk directories are skipped.
  • Secret values are not emitted; evidence may include secret variable names when needed for risk explanation.
  • Proof packs copy only allowlisted artifacts and apply redaction before export.
  • Deep Agent output explains scanner artifacts. It does not replace scanner evidence.

Documentation

Developer docs:

Planning and research archives live in docs/.

Contributing

Good first contribution areas:

  • deterministic rule improvements
  • false-positive reductions
  • fixture coverage
  • SARIF output improvements
  • GitHub Action hardening
  • documentation and demo clarity

Read CONTRIBUTING.md, SECURITY.md, and SUPPORT.md before opening issues or pull requests. Do not paste secrets, private code, raw traces, or customer data into public issues.

Verification

Run the public-release check:

python3 tools/release_check.py

Core checks:

uv run pytest -q
cd docs-site && bun run build

About

Pre-flight security checks for AI coding agents before tools, secrets, memory, MCP, or CI write access.

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

PermitGraph

CIAgent PermitLicensePython

Pre-flight security checks for AI coding agents.

PermitGraph scans a repository before agents receive tools, secrets, memory, MCP servers, or CI write access. It returns a clear permit decision: approved, needs_review, or blocked, with evidence a reviewer can inspect.

Run it before enabling Codex, Claude, Cursor, GitHub Actions agents, LangGraph/LangChain agents, or MCP tools inside sensitive repositories.

PermitGraph preview

Why This Exists

AI teams are wiring coding agents, MCP servers, CI workflows, repo instructions, and long-lived credentials into the same repos. Normal code review does not show whether an agent can reach a secret, write to a protected branch, follow unsafe repository instructions, or pass repo context into an external tool.

PermitGraph turns those agent-access facts into reviewable evidence before the agent runs.

60-Second Scan

Install dependencies:

uv sync --all-extras --dev

Scan a repository:

uv run agent-permit scan . --ci --exclude "tests/fixtures/**"

Open the generated evidence:

.agent-permit/runs/<run_id>/summary.md
.agent-permit/runs/<run_id>/permit.yaml
.agent-permit/runs/<run_id>/raw-findings.json
.agent-permit/runs/<run_id>/graph-paths.json

The scanner is static. It does not execute agent code, MCP servers, CI workflows, package scripts, or external tools.

What A Finding Looks Like

Plain-English result:

Status: needs_review
Review CI secrets and write permissions in github-mcp-server.
Why: a workflow references CI secrets and also has write permissions.
Reviewer question: should this automation be allowed before agent access continues?
Evidence: .github/workflows/agent.yml:18
Next step: use least-privilege workflow permissions or document an exception.

Machine-readable artifacts preserve the same evidence for CI, dashboards, proof packs, SARIF, and AI review.

Public Proof Artifacts

The repository includes sanitized fixture scans so reviewers can inspect real output without running private code:

FixtureStatusPurpose
safe-agentapprovedShows a clean repository passing the configured agent-access checks.
risky-ci-agentblockedShows a privileged pull request workflow with write access being stopped.
risky-mcp-agentneeds_reviewShows an MCP server receiving a credential reference and requiring human review.

Start with the public fixture manifest, then inspect the blocked CI summary, permit, raw findings, and finding baseline.

Regenerate them with:

uv run python tools/build_public_demo_artifacts.py

What It Checks

  • MCP server configuration and tool boundaries
  • CI workflow permissions and secret references
  • repository instructions for AI tools
  • credential-bearing environment references
  • generated agent artifacts
  • source-to-sink paths in the Agent Capability Graph
  • policy controls before access approval

How It Fits With Other Tools

ToolMain jobPermitGraph job
TrivyFind vulnerabilities, misconfigurations, secrets, and SBOM issues.Decide whether AI agents should receive repo/tool/credential access.
SemgrepFind code and security patterns across source files.Connect repo instructions, MCP config, CI permissions, and credentials into agent-access findings.
OPAEnforce general policy as code.Provide a domain-specific scanner and artifacts for AI agent access review.
LangSmithObserve, evaluate, and debug agents after or during execution.Gate access before the agent receives dangerous capabilities.

PermitGraph is not a replacement for SAST, dependency scanning, secrets scanning, or LLM observability. It is the missing review gate for agent permissions.

Deep Agent Review

Deep Agent review is part of the product path, not a side demo.

The deterministic scanner creates bounded evidence. The Deep Agent reads that evidence, reasons across related artifacts, writes a cited report, and the citation critic checks whether claims are grounded.

Run from an existing scan:

export OPENROUTER_API_KEY=<key>
uv run --extra deep-agent agent-permit investigate .agent-permit/runs/<run_id>

Offline deterministic fallback for tests or no-key debugging:

uv run agent-permit investigate .agent-permit/runs/<run_id> --deterministic-only

Default live-model path uses Claude Sonnet through OpenRouter. Prompt caching, response caching, timeout caps, completion caps, token metrics, and cache-hit metrics are recorded in local run artifacts.

GitHub Action

Use PermitGraph in pull requests before risky agent-access changes merge:

name: PermitGraphon:
pull_request:
permissions:
contents: readsecurity-events: writejobs:
scan:
runs-on: ubuntu-lateststeps:
- uses: actions/checkout@v6with:
persist-credentials: false
- uses: IntelIP/agent-permit-office@mainwith:
path: .exclude: | tests/fixtures/**sarif: "true"upload-sarif: "true"

Proof Packs

Generate dashboard data and a shareable proof pack:

python3 tools/export_dashboard_snapshot.py
python3 tools/export_dashboard_snapshot.py --proof-pack

The proof pack exporter prints both paths:

.agent-permit/proof-packs/<validation_run_id>
.agent-permit/proof-packs/<validation_run_id>.zip

Proof packs are redacted, but still sensitive. Review them before sharing.

Local Apps

Run the local dashboard:

cd dashboard
bun install
bun dev

Use the dashboard Queue scan flow with a GitHub repository URL. The hosted dashboard writes the job to the Worker API; the local CLI runner clones the repo and runs the scanner:

set -a;source .env;set +a
uv run --extra db --extra deep-agent agent-permit runner --once --deep-agent auto --agent-recursion-limit 20

Run the documentation site:

cd docs-site
bun install
bun dev

Then open http://localhost:3000/docs or the next free port printed by Next.js.

Common Commands

uv run agent-permit rules
uv run agent-permit scan . --ci --sarif
uv run agent-permit sarif .agent-permit/runs/<run_id>
uv run agent-permit baseline .agent-permit/runs/<run_id> --output .agent-permit/finding-baseline.json
uv run agent-permit scan . --ci --baseline .agent-permit/finding-baseline.json --ci-new-findings-only
uv run agent-permit scan . --ci --policy agent-permit-policy.json
uv run agent-permit analytics summarize .
uv run agent-permit eval tests/fixtures
uv run --extra phoenix agent-permit eval tests/fixtures --upload-phoenix

Open-Core Boundary

Open-source core:

  • deterministic scanner and rule registry
  • Agent Capability Graph builder and risky path finder
  • permit engine and local artifact schemas
  • Markdown, JSON, YAML, SARIF, baseline, diff, policy, metrics, and eval outputs
  • bounded Deep Agent evidence tools, prompt flow, and citation critic
  • OpenRouter adapter with local cost/cache telemetry
  • Phoenix local tracing and eval export support
  • GitHub Action and local dashboard snapshot workflow

Hosted product roadmap:

  • multi-repo queue and team review workflow
  • private repo connectors and scheduled scans
  • SSO/RBAC, assignments, approval history, and audit retention
  • managed model gateway, model policy, key isolation, and spend controls
  • policy packs, custom rules, notifications, support, and SLA

The hosted product is not required to use the local scanner. Commercial value is managed workflow, governance, retention, and integrations, not hiding scanner logic.

Safety Boundaries

  • Static scanning only: no agent, MCP server, CI workflow, package script, or external tool execution during scans.
  • Real .env files and generated/junk directories are skipped.
  • Secret values are not emitted; evidence may include secret variable names when needed for risk explanation.
  • Proof packs copy only allowlisted artifacts and apply redaction before export.
  • Deep Agent output explains scanner artifacts. It does not replace scanner evidence.

Documentation

Developer docs:

Planning and research archives live in docs/.

Contributing

Good first contribution areas:

  • deterministic rule improvements
  • false-positive reductions
  • fixture coverage
  • SARIF output improvements
  • GitHub Action hardening
  • documentation and demo clarity

Read CONTRIBUTING.md, SECURITY.md, and SUPPORT.md before opening issues or pull requests. Do not paste secrets, private code, raw traces, or customer data into public issues.

Verification

Run the public-release check:

python3 tools/release_check.py

Core checks:

uv run pytest -q
cd docs-site && bun run build

About

Pre-flight security checks for AI coding agents before tools, secrets, memory, MCP, or CI write access.

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

PermitGraph

CIAgent PermitLicensePython

Pre-flight security checks for AI coding agents.

PermitGraph scans a repository before agents receive tools, secrets, memory, MCP servers, or CI write access. It returns a clear permit decision: approved, needs_review, or blocked, with evidence a reviewer can inspect.

Run it before enabling Codex, Claude, Cursor, GitHub Actions agents, LangGraph/LangChain agents, or MCP tools inside sensitive repositories.

PermitGraph preview

Why This Exists

AI teams are wiring coding agents, MCP servers, CI workflows, repo instructions, and long-lived credentials into the same repos. Normal code review does not show whether an agent can reach a secret, write to a protected branch, follow unsafe repository instructions, or pass repo context into an external tool.

PermitGraph turns those agent-access facts into reviewable evidence before the agent runs.

60-Second Scan

Install dependencies:

uv sync --all-extras --dev

Scan a repository:

uv run agent-permit scan . --ci --exclude "tests/fixtures/**"

Open the generated evidence:

.agent-permit/runs/<run_id>/summary.md
.agent-permit/runs/<run_id>/permit.yaml
.agent-permit/runs/<run_id>/raw-findings.json
.agent-permit/runs/<run_id>/graph-paths.json

The scanner is static. It does not execute agent code, MCP servers, CI workflows, package scripts, or external tools.

What A Finding Looks Like

Plain-English result:

Status: needs_review
Review CI secrets and write permissions in github-mcp-server.
Why: a workflow references CI secrets and also has write permissions.
Reviewer question: should this automation be allowed before agent access continues?
Evidence: .github/workflows/agent.yml:18
Next step: use least-privilege workflow permissions or document an exception.

Machine-readable artifacts preserve the same evidence for CI, dashboards, proof packs, SARIF, and AI review.

Public Proof Artifacts

The repository includes sanitized fixture scans so reviewers can inspect real output without running private code:

FixtureStatusPurpose
safe-agentapprovedShows a clean repository passing the configured agent-access checks.
risky-ci-agentblockedShows a privileged pull request workflow with write access being stopped.
risky-mcp-agentneeds_reviewShows an MCP server receiving a credential reference and requiring human review.

Start with the public fixture manifest, then inspect the blocked CI summary, permit, raw findings, and finding baseline.

Regenerate them with:

uv run python tools/build_public_demo_artifacts.py

What It Checks

  • MCP server configuration and tool boundaries
  • CI workflow permissions and secret references
  • repository instructions for AI tools
  • credential-bearing environment references
  • generated agent artifacts
  • source-to-sink paths in the Agent Capability Graph
  • policy controls before access approval

How It Fits With Other Tools

ToolMain jobPermitGraph job
TrivyFind vulnerabilities, misconfigurations, secrets, and SBOM issues.Decide whether AI agents should receive repo/tool/credential access.
SemgrepFind code and security patterns across source files.Connect repo instructions, MCP config, CI permissions, and credentials into agent-access findings.
OPAEnforce general policy as code.Provide a domain-specific scanner and artifacts for AI agent access review.
LangSmithObserve, evaluate, and debug agents after or during execution.Gate access before the agent receives dangerous capabilities.

PermitGraph is not a replacement for SAST, dependency scanning, secrets scanning, or LLM observability. It is the missing review gate for agent permissions.

Deep Agent Review

Deep Agent review is part of the product path, not a side demo.

The deterministic scanner creates bounded evidence. The Deep Agent reads that evidence, reasons across related artifacts, writes a cited report, and the citation critic checks whether claims are grounded.

Run from an existing scan:

export OPENROUTER_API_KEY=<key>
uv run --extra deep-agent agent-permit investigate .agent-permit/runs/<run_id>

Offline deterministic fallback for tests or no-key debugging:

uv run agent-permit investigate .agent-permit/runs/<run_id> --deterministic-only

Default live-model path uses Claude Sonnet through OpenRouter. Prompt caching, response caching, timeout caps, completion caps, token metrics, and cache-hit metrics are recorded in local run artifacts.

GitHub Action

Use PermitGraph in pull requests before risky agent-access changes merge:

name: PermitGraphon:
pull_request:
permissions:
contents: readsecurity-events: writejobs:
scan:
runs-on: ubuntu-lateststeps:
- uses: actions/checkout@v6with:
persist-credentials: false
- uses: IntelIP/agent-permit-office@mainwith:
path: .exclude: | tests/fixtures/**sarif: "true"upload-sarif: "true"

Proof Packs

Generate dashboard data and a shareable proof pack:

python3 tools/export_dashboard_snapshot.py
python3 tools/export_dashboard_snapshot.py --proof-pack

The proof pack exporter prints both paths:

.agent-permit/proof-packs/<validation_run_id>
.agent-permit/proof-packs/<validation_run_id>.zip

Proof packs are redacted, but still sensitive. Review them before sharing.

Local Apps

Run the local dashboard:

cd dashboard
bun install
bun dev

Use the dashboard Queue scan flow with a GitHub repository URL. The hosted dashboard writes the job to the Worker API; the local CLI runner clones the repo and runs the scanner:

set -a;source .env;set +a
uv run --extra db --extra deep-agent agent-permit runner --once --deep-agent auto --agent-recursion-limit 20

Run the documentation site:

cd docs-site
bun install
bun dev

Then open http://localhost:3000/docs or the next free port printed by Next.js.

Common Commands

uv run agent-permit rules
uv run agent-permit scan . --ci --sarif
uv run agent-permit sarif .agent-permit/runs/<run_id>
uv run agent-permit baseline .agent-permit/runs/<run_id> --output .agent-permit/finding-baseline.json
uv run agent-permit scan . --ci --baseline .agent-permit/finding-baseline.json --ci-new-findings-only
uv run agent-permit scan . --ci --policy agent-permit-policy.json
uv run agent-permit analytics summarize .
uv run agent-permit eval tests/fixtures
uv run --extra phoenix agent-permit eval tests/fixtures --upload-phoenix

Open-Core Boundary

Open-source core:

  • deterministic scanner and rule registry
  • Agent Capability Graph builder and risky path finder
  • permit engine and local artifact schemas
  • Markdown, JSON, YAML, SARIF, baseline, diff, policy, metrics, and eval outputs
  • bounded Deep Agent evidence tools, prompt flow, and citation critic
  • OpenRouter adapter with local cost/cache telemetry
  • Phoenix local tracing and eval export support
  • GitHub Action and local dashboard snapshot workflow

Hosted product roadmap:

  • multi-repo queue and team review workflow
  • private repo connectors and scheduled scans
  • SSO/RBAC, assignments, approval history, and audit retention
  • managed model gateway, model policy, key isolation, and spend controls
  • policy packs, custom rules, notifications, support, and SLA

The hosted product is not required to use the local scanner. Commercial value is managed workflow, governance, retention, and integrations, not hiding scanner logic.

Safety Boundaries

  • Static scanning only: no agent, MCP server, CI workflow, package script, or external tool execution during scans.
  • Real .env files and generated/junk directories are skipped.
  • Secret values are not emitted; evidence may include secret variable names when needed for risk explanation.
  • Proof packs copy only allowlisted artifacts and apply redaction before export.
  • Deep Agent output explains scanner artifacts. It does not replace scanner evidence.

Documentation

Developer docs:

Planning and research archives live in docs/.

Contributing

Good first contribution areas:

  • deterministic rule improvements
  • false-positive reductions
  • fixture coverage
  • SARIF output improvements
  • GitHub Action hardening
  • documentation and demo clarity

Read CONTRIBUTING.md, SECURITY.md, and SUPPORT.md before opening issues or pull requests. Do not paste secrets, private code, raw traces, or customer data into public issues.

Verification

Run the public-release check:

python3 tools/release_check.py

Core checks:

uv run pytest -q
cd docs-site && bun run build

About

Pre-flight security checks for AI coding agents before tools, secrets, memory, MCP, or CI write access.

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

PermitGraph

CIAgent PermitLicensePython

Pre-flight security checks for AI coding agents.

PermitGraph scans a repository before agents receive tools, secrets, memory, MCP servers, or CI write access. It returns a clear permit decision: approved, needs_review, or blocked, with evidence a reviewer can inspect.

Run it before enabling Codex, Claude, Cursor, GitHub Actions agents, LangGraph/LangChain agents, or MCP tools inside sensitive repositories.

PermitGraph preview

Why This Exists

AI teams are wiring coding agents, MCP servers, CI workflows, repo instructions, and long-lived credentials into the same repos. Normal code review does not show whether an agent can reach a secret, write to a protected branch, follow unsafe repository instructions, or pass repo context into an external tool.

PermitGraph turns those agent-access facts into reviewable evidence before the agent runs.

60-Second Scan

Install dependencies:

uv sync --all-extras --dev

Scan a repository:

uv run agent-permit scan . --ci --exclude "tests/fixtures/**"

Open the generated evidence:

.agent-permit/runs/<run_id>/summary.md
.agent-permit/runs/<run_id>/permit.yaml
.agent-permit/runs/<run_id>/raw-findings.json
.agent-permit/runs/<run_id>/graph-paths.json

The scanner is static. It does not execute agent code, MCP servers, CI workflows, package scripts, or external tools.

What A Finding Looks Like

Plain-English result:

Status: needs_review
Review CI secrets and write permissions in github-mcp-server.
Why: a workflow references CI secrets and also has write permissions.
Reviewer question: should this automation be allowed before agent access continues?
Evidence: .github/workflows/agent.yml:18
Next step: use least-privilege workflow permissions or document an exception.

Machine-readable artifacts preserve the same evidence for CI, dashboards, proof packs, SARIF, and AI review.

Public Proof Artifacts

The repository includes sanitized fixture scans so reviewers can inspect real output without running private code:

FixtureStatusPurpose
safe-agentapprovedShows a clean repository passing the configured agent-access checks.
risky-ci-agentblockedShows a privileged pull request workflow with write access being stopped.
risky-mcp-agentneeds_reviewShows an MCP server receiving a credential reference and requiring human review.

Start with the public fixture manifest, then inspect the blocked CI summary, permit, raw findings, and finding baseline.

Regenerate them with:

uv run python tools/build_public_demo_artifacts.py

What It Checks

  • MCP server configuration and tool boundaries
  • CI workflow permissions and secret references
  • repository instructions for AI tools
  • credential-bearing environment references
  • generated agent artifacts
  • source-to-sink paths in the Agent Capability Graph
  • policy controls before access approval

How It Fits With Other Tools

ToolMain jobPermitGraph job
TrivyFind vulnerabilities, misconfigurations, secrets, and SBOM issues.Decide whether AI agents should receive repo/tool/credential access.
SemgrepFind code and security patterns across source files.Connect repo instructions, MCP config, CI permissions, and credentials into agent-access findings.
OPAEnforce general policy as code.Provide a domain-specific scanner and artifacts for AI agent access review.
LangSmithObserve, evaluate, and debug agents after or during execution.Gate access before the agent receives dangerous capabilities.

PermitGraph is not a replacement for SAST, dependency scanning, secrets scanning, or LLM observability. It is the missing review gate for agent permissions.

Deep Agent Review

Deep Agent review is part of the product path, not a side demo.

The deterministic scanner creates bounded evidence. The Deep Agent reads that evidence, reasons across related artifacts, writes a cited report, and the citation critic checks whether claims are grounded.

Run from an existing scan:

export OPENROUTER_API_KEY=<key>
uv run --extra deep-agent agent-permit investigate .agent-permit/runs/<run_id>

Offline deterministic fallback for tests or no-key debugging:

uv run agent-permit investigate .agent-permit/runs/<run_id> --deterministic-only

Default live-model path uses Claude Sonnet through OpenRouter. Prompt caching, response caching, timeout caps, completion caps, token metrics, and cache-hit metrics are recorded in local run artifacts.

GitHub Action

Use PermitGraph in pull requests before risky agent-access changes merge:

name: PermitGraphon:
pull_request:
permissions:
contents: readsecurity-events: writejobs:
scan:
runs-on: ubuntu-lateststeps:
- uses: actions/checkout@v6with:
persist-credentials: false
- uses: IntelIP/agent-permit-office@mainwith:
path: .exclude: | tests/fixtures/**sarif: "true"upload-sarif: "true"

Proof Packs

Generate dashboard data and a shareable proof pack:

python3 tools/export_dashboard_snapshot.py
python3 tools/export_dashboard_snapshot.py --proof-pack

The proof pack exporter prints both paths:

.agent-permit/proof-packs/<validation_run_id>
.agent-permit/proof-packs/<validation_run_id>.zip

Proof packs are redacted, but still sensitive. Review them before sharing.

Local Apps

Run the local dashboard:

cd dashboard
bun install
bun dev

Use the dashboard Queue scan flow with a GitHub repository URL. The hosted dashboard writes the job to the Worker API; the local CLI runner clones the repo and runs the scanner:

set -a;source .env;set +a
uv run --extra db --extra deep-agent agent-permit runner --once --deep-agent auto --agent-recursion-limit 20

Run the documentation site:

cd docs-site
bun install
bun dev

Then open http://localhost:3000/docs or the next free port printed by Next.js.

Common Commands

uv run agent-permit rules
uv run agent-permit scan . --ci --sarif
uv run agent-permit sarif .agent-permit/runs/<run_id>
uv run agent-permit baseline .agent-permit/runs/<run_id> --output .agent-permit/finding-baseline.json
uv run agent-permit scan . --ci --baseline .agent-permit/finding-baseline.json --ci-new-findings-only
uv run agent-permit scan . --ci --policy agent-permit-policy.json
uv run agent-permit analytics summarize .
uv run agent-permit eval tests/fixtures
uv run --extra phoenix agent-permit eval tests/fixtures --upload-phoenix

Open-Core Boundary

Open-source core:

  • deterministic scanner and rule registry
  • Agent Capability Graph builder and risky path finder
  • permit engine and local artifact schemas
  • Markdown, JSON, YAML, SARIF, baseline, diff, policy, metrics, and eval outputs
  • bounded Deep Agent evidence tools, prompt flow, and citation critic
  • OpenRouter adapter with local cost/cache telemetry
  • Phoenix local tracing and eval export support
  • GitHub Action and local dashboard snapshot workflow

Hosted product roadmap:

  • multi-repo queue and team review workflow
  • private repo connectors and scheduled scans
  • SSO/RBAC, assignments, approval history, and audit retention
  • managed model gateway, model policy, key isolation, and spend controls
  • policy packs, custom rules, notifications, support, and SLA

The hosted product is not required to use the local scanner. Commercial value is managed workflow, governance, retention, and integrations, not hiding scanner logic.

Safety Boundaries

  • Static scanning only: no agent, MCP server, CI workflow, package script, or external tool execution during scans.
  • Real .env files and generated/junk directories are skipped.
  • Secret values are not emitted; evidence may include secret variable names when needed for risk explanation.
  • Proof packs copy only allowlisted artifacts and apply redaction before export.
  • Deep Agent output explains scanner artifacts. It does not replace scanner evidence.

Documentation

Developer docs:

Planning and research archives live in docs/.

Contributing

Good first contribution areas:

  • deterministic rule improvements
  • false-positive reductions
  • fixture coverage
  • SARIF output improvements
  • GitHub Action hardening
  • documentation and demo clarity

Read CONTRIBUTING.md, SECURITY.md, and SUPPORT.md before opening issues or pull requests. Do not paste secrets, private code, raw traces, or customer data into public issues.

Verification

Run the public-release check:

python3 tools/release_check.py

Core checks:

uv run pytest -q
cd docs-site && bun run build

About

Pre-flight security checks for AI coding agents before tools, secrets, memory, MCP, or CI write access.

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

PermitGraph

CIAgent PermitLicensePython

Pre-flight security checks for AI coding agents.

PermitGraph scans a repository before agents receive tools, secrets, memory, MCP servers, or CI write access. It returns a clear permit decision: approved, needs_review, or blocked, with evidence a reviewer can inspect.

Run it before enabling Codex, Claude, Cursor, GitHub Actions agents, LangGraph/LangChain agents, or MCP tools inside sensitive repositories.

PermitGraph preview

Why This Exists

AI teams are wiring coding agents, MCP servers, CI workflows, repo instructions, and long-lived credentials into the same repos. Normal code review does not show whether an agent can reach a secret, write to a protected branch, follow unsafe repository instructions, or pass repo context into an external tool.

PermitGraph turns those agent-access facts into reviewable evidence before the agent runs.

60-Second Scan

Install dependencies:

uv sync --all-extras --dev

Scan a repository:

uv run agent-permit scan . --ci --exclude "tests/fixtures/**"

Open the generated evidence:

.agent-permit/runs/<run_id>/summary.md
.agent-permit/runs/<run_id>/permit.yaml
.agent-permit/runs/<run_id>/raw-findings.json
.agent-permit/runs/<run_id>/graph-paths.json

The scanner is static. It does not execute agent code, MCP servers, CI workflows, package scripts, or external tools.

What A Finding Looks Like

Plain-English result:

Status: needs_review
Review CI secrets and write permissions in github-mcp-server.
Why: a workflow references CI secrets and also has write permissions.
Reviewer question: should this automation be allowed before agent access continues?
Evidence: .github/workflows/agent.yml:18
Next step: use least-privilege workflow permissions or document an exception.

Machine-readable artifacts preserve the same evidence for CI, dashboards, proof packs, SARIF, and AI review.

Public Proof Artifacts

The repository includes sanitized fixture scans so reviewers can inspect real output without running private code:

FixtureStatusPurpose
safe-agentapprovedShows a clean repository passing the configured agent-access checks.
risky-ci-agentblockedShows a privileged pull request workflow with write access being stopped.
risky-mcp-agentneeds_reviewShows an MCP server receiving a credential reference and requiring human review.

Start with the public fixture manifest, then inspect the blocked CI summary, permit, raw findings, and finding baseline.

Regenerate them with:

uv run python tools/build_public_demo_artifacts.py

What It Checks

  • MCP server configuration and tool boundaries
  • CI workflow permissions and secret references
  • repository instructions for AI tools
  • credential-bearing environment references
  • generated agent artifacts
  • source-to-sink paths in the Agent Capability Graph
  • policy controls before access approval

How It Fits With Other Tools

ToolMain jobPermitGraph job
TrivyFind vulnerabilities, misconfigurations, secrets, and SBOM issues.Decide whether AI agents should receive repo/tool/credential access.
SemgrepFind code and security patterns across source files.Connect repo instructions, MCP config, CI permissions, and credentials into agent-access findings.
OPAEnforce general policy as code.Provide a domain-specific scanner and artifacts for AI agent access review.
LangSmithObserve, evaluate, and debug agents after or during execution.Gate access before the agent receives dangerous capabilities.

PermitGraph is not a replacement for SAST, dependency scanning, secrets scanning, or LLM observability. It is the missing review gate for agent permissions.

Deep Agent Review

Deep Agent review is part of the product path, not a side demo.

The deterministic scanner creates bounded evidence. The Deep Agent reads that evidence, reasons across related artifacts, writes a cited report, and the citation critic checks whether claims are grounded.

Run from an existing scan:

export OPENROUTER_API_KEY=<key>
uv run --extra deep-agent agent-permit investigate .agent-permit/runs/<run_id>

Offline deterministic fallback for tests or no-key debugging:

uv run agent-permit investigate .agent-permit/runs/<run_id> --deterministic-only

Default live-model path uses Claude Sonnet through OpenRouter. Prompt caching, response caching, timeout caps, completion caps, token metrics, and cache-hit metrics are recorded in local run artifacts.

GitHub Action

Use PermitGraph in pull requests before risky agent-access changes merge:

name: PermitGraphon:
pull_request:
permissions:
contents: readsecurity-events: writejobs:
scan:
runs-on: ubuntu-lateststeps:
- uses: actions/checkout@v6with:
persist-credentials: false
- uses: IntelIP/agent-permit-office@mainwith:
path: .exclude: | tests/fixtures/**sarif: "true"upload-sarif: "true"

Proof Packs

Generate dashboard data and a shareable proof pack:

python3 tools/export_dashboard_snapshot.py
python3 tools/export_dashboard_snapshot.py --proof-pack

The proof pack exporter prints both paths:

.agent-permit/proof-packs/<validation_run_id>
.agent-permit/proof-packs/<validation_run_id>.zip

Proof packs are redacted, but still sensitive. Review them before sharing.

Local Apps

Run the local dashboard:

cd dashboard
bun install
bun dev

Use the dashboard Queue scan flow with a GitHub repository URL. The hosted dashboard writes the job to the Worker API; the local CLI runner clones the repo and runs the scanner:

set -a;source .env;set +a
uv run --extra db --extra deep-agent agent-permit runner --once --deep-agent auto --agent-recursion-limit 20

Run the documentation site:

cd docs-site
bun install
bun dev

Then open http://localhost:3000/docs or the next free port printed by Next.js.

Common Commands

uv run agent-permit rules
uv run agent-permit scan . --ci --sarif
uv run agent-permit sarif .agent-permit/runs/<run_id>
uv run agent-permit baseline .agent-permit/runs/<run_id> --output .agent-permit/finding-baseline.json
uv run agent-permit scan . --ci --baseline .agent-permit/finding-baseline.json --ci-new-findings-only
uv run agent-permit scan . --ci --policy agent-permit-policy.json
uv run agent-permit analytics summarize .
uv run agent-permit eval tests/fixtures
uv run --extra phoenix agent-permit eval tests/fixtures --upload-phoenix

Open-Core Boundary

Open-source core:

  • deterministic scanner and rule registry
  • Agent Capability Graph builder and risky path finder
  • permit engine and local artifact schemas
  • Markdown, JSON, YAML, SARIF, baseline, diff, policy, metrics, and eval outputs
  • bounded Deep Agent evidence tools, prompt flow, and citation critic
  • OpenRouter adapter with local cost/cache telemetry
  • Phoenix local tracing and eval export support
  • GitHub Action and local dashboard snapshot workflow

Hosted product roadmap:

  • multi-repo queue and team review workflow
  • private repo connectors and scheduled scans
  • SSO/RBAC, assignments, approval history, and audit retention
  • managed model gateway, model policy, key isolation, and spend controls
  • policy packs, custom rules, notifications, support, and SLA

The hosted product is not required to use the local scanner. Commercial value is managed workflow, governance, retention, and integrations, not hiding scanner logic.

Safety Boundaries

  • Static scanning only: no agent, MCP server, CI workflow, package script, or external tool execution during scans.
  • Real .env files and generated/junk directories are skipped.
  • Secret values are not emitted; evidence may include secret variable names when needed for risk explanation.
  • Proof packs copy only allowlisted artifacts and apply redaction before export.
  • Deep Agent output explains scanner artifacts. It does not replace scanner evidence.

Documentation

Developer docs:

Planning and research archives live in docs/.

Contributing

Good first contribution areas:

  • deterministic rule improvements
  • false-positive reductions
  • fixture coverage
  • SARIF output improvements
  • GitHub Action hardening
  • documentation and demo clarity

Read CONTRIBUTING.md, SECURITY.md, and SUPPORT.md before opening issues or pull requests. Do not paste secrets, private code, raw traces, or customer data into public issues.

Verification

Run the public-release check:

python3 tools/release_check.py

Core checks:

uv run pytest -q
cd docs-site && bun run build

About

Pre-flight security checks for AI coding agents before tools, secrets, memory, MCP, or CI write access.

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages