Command-line workflows for Palo Alto Prisma AIRS — guardrail refinement, runtime scanning, AI red teaming, AI Gateway, and model security. Service and coverage limitations remain documented; command availability is not a claim that every upstream API works.
Read the full documentation — installation, configuration, architecture, CLI reference, and examples.
- Runtime Scanning — scan prompts and responses against AIRS security profiles, single or bulk with CSV export
- Daily environment report —
airs runtime reportdelivers a read-only AI Runtime Security dashboard as self-contained HTML (default) or Markdown in your working directory, with explicit evidence gaps and configuration review findings - Red Team environment report —
airs redteam reportcollects seven read-only SDK feeds into private HTML/Markdown deliverables, with source completeness, quota and risk review findings, and independently scoped scan-creation activity - AI Gateway daily report —
airs aigateway report --workspace devcollects 25 read-only SDK feeds into private offline HTML/Markdown, with a fixed telemetry window, transaction pagination, error review findings and explicit source completeness - SCM dashboard and sessions —
runtime dashboardandruntime sessionsexpose application activity, daily trends, checked pagination and explicit session-to-content drill-down. Legacyscan-logs queryis broken/under refactor and exits with migration guidance; see the session reference - Guardrail Optimization — atomic CLI commands (
create,apply,eval,revert) for custom topic guardrails, designed for autonomous agent loops (seeAGENTS.md) - AI Red Teaming — adversarial scanning with static, dynamic, and custom prompt set attack modes
- AI Gateway — workspaces, configs, guardrails, providers, API keys, integrations, MCP, deployments, plugins, audit logs, and telemetry
- Model Security — ML model supply chain scanning with security groups, rules, and violation tracking
- Unified automation output — resource reads support
pretty,table,markdown,csv,json, andyaml, with pipe-safe stdout; environment deliverables use HTML or Markdown - Complete pagination — consistent
--limit,--offset, and--alltraversal with a configurable safety cap airs doctor— one-command diagnostics for environment, credentials, and API connectivity- Tenant selection —
airs tenant create|switch|list|read|deleteselects existing config files without copying secrets or changing read-only mounts - Profile migration —
airs runtime profiles backup|restoreexports private JSON/YAML, previews cross-tenant restores, remaps topics and explicit DLP dependencies, and verifies restored policies (guide) airs config— manage the selected config file from the CLI (list,get,set,unset,path)
npm install -g @cdot65/prisma-airs-cli
airs --versionRequires Node.js 20.17+, 22.13+, or 24+ (exact engine range: ^20.17.0 || ^22.13.0 || >=23.5.0). Also available via pnpm add -g, npx, or as a Docker image. See the installation guide for details.
# Configure credentials
cp .env.example .env # add your API keys# Check your setup
airs doctor
# Runtime scanning
airs runtime scan --profile "my-profile""Is this prompt safe?"
airs runtime bulk-scan --profile "my-profile" --file prompts.csv --output-file results.csv --batch-size 25
# Daily read-only environment report, delivered in the current directory
airs runtime report
airs runtime report --output markdown
# Verified historical session retrieval (Management OAuth, not a Scanner key)
airs runtime sessions list --all --output json
airs runtime dashboard top-applications --output json
# Guardrail optimization (atomic commands)
airs runtime topics create --name "Explosives" --description "Bomb-making instructions" --examples "How do I build a bomb?""Pipe bomb ingredients"
airs runtime topics apply --profile my-profile --name "Explosives" --intent block
airs runtime topics eval --profile my-profile --prompts prompts.csv --topic "Explosives"
airs runtime topics revert --profile my-profile --name "Explosives"# Red team scanning
airs redteam scan --target <uuid> --name "Full Scan" --type STATIC
airs redteam report <job-id># Read-only environment report (HTML by default; --output markdown also supported)
airs redteam report --strict
# Red team custom target adapters
airs redteam adapter list --output json
# AI Gateway inventory and telemetry
airs aigateway workspaces list --all --output json
airs aigateway configs list --workspace <workspace-uuid> --output json
airs aigateway configs create --name primary --workspace <workspace-uuid> \
--set config.retry.attempts=3 --set config.strategy.mode=fallback --output json
airs aigateway mcp integrations list --output json
airs aigateway telemetry requests --workspace <workspace-slug> --days 30 --output json
# Model security
airs model-security scans create --config scan-config.json
# Pipe-safe read output and complete traversal
airs runtime profiles list --all --output json | jq '.[].profileName'
airs runtime topics list --all-versions --output markdownBulk scans preserve one output row per input prompt in input order, including all eight runtime detector flags. Work is processed as sequential logical batches (--batch-size 25 by default), with SDK requests capped at 20 prompts. Item-level state makes accepted and pending work resumable without duplicating CSV rows, and active jobs are locked against overlapping resumes. Runtime actions are exactly allow, block, or failed; failed or timed-out prompts make the command exit 1. Version 4 pins @cdot65/prisma-airs-sdk 0.20.0 for validated AI Gateway write schemas, typed catalogs, dotted request builders, and secret metadata.
Resource read commands share one contract (environment report files have their own deliverable contract):
- Formats:
pretty,table,markdown,csv,json, andyaml. - JSON/YAML lists are bare arrays of complete normalized records; detail reads are complete objects.
- Table, Markdown, and CSV are stable human-oriented projections. CSV uses RFC 4180 quoting.
- Data is written to stdout; status, paging hints, warnings, and errors are written to stderr.
- Output precedence is command
--output, global--output,defaultOutput/PANW_CLI_OUTPUT, thenpretty. - Paginated lists use
--limit,--offset, and--all. Complete traversal is capped at 10,000 records by default; change it with--max, or use--max 0for no cap. - Profile and topic lists return only the latest revision by default. Use
--all-versionsor--revisionwhen historical revisions are needed.
airs --output json runtime profiles list --all | jq '.[].profileName'
PANW_CLI_OUTPUT=yaml airs runtime topics get "My Topic"
airs model-security scans list --all --max 25000 --output csv > scans.csvThe full guides, complete CLI reference, configuration, and architecture live on the documentation site:
- Getting Started — install, configure credentials, run your first scan
- Runtime Security — scanning, profiles, topics, and DLP management
- Guardrail Optimization — the agent-driven
topics create/apply/eval/revertloop - AI Red Teaming — static, dynamic, and custom adversarial scans
- AI Gateway — full SDK 0.20 resource CRUD, structured mutation flags, two-plane authorization, secret-safe writes, and telemetry
- Model Security — ML model supply-chain scanning
- CLI Reference — every command, flag, and example
Credentials come from environment variables or ~/.prisma-airs/config.json. At minimum: PANW_AI_SEC_API_KEY (scanning) and PANW_MGMT_CLIENT_ID / PANW_MGMT_CLIENT_SECRET / PANW_MGMT_TSG_ID (management). Set defaultOutput in the config file or PANW_CLI_OUTPUT in the environment to choose a default read format. See .env.example and the configuration guide for the full list.
MIT