AgentSec: Audit AI Agent Workflows for Security Risks

Summary
AgentSec statically analyzes AI agent workflows for excessive permissions and paths from untrusted input to dangerous capabilities. It is aimed at developers and security teams reviewing supported agent frameworks before deployment or as part of CI.
At a glance
- Language
- Python
- License
- Apache-2.0
- Stars
- 0
- Forks
- 0
- Added to OSRepos
- October 6, 2026
- Last analyzed
- October 6, 2026
Topics
Click on any tag to explore related repositories
Use at your own risk
OSRepos shares public repositories for knowledge and discovery only. Any installation, execution, configuration, or use of code from these repositories is the user's own responsibility. Always review the repository, source code, dependencies, licenses, and security implications before running or installing anything. OSRepos is not responsible for issues, damages, or losses resulting from third-party repositories.
Overview
AgentSec is a Python tool for assessing the security of AI agent workflows without executing them. It builds a graph of agents, tools, and handoffs, then checks what each agent can do and whether untrusted content can reach risky capabilities.
It is useful when a per-file code scan misses risks created by connections between agents. Its analysis covers LangGraph, CrewAI, OpenAI Agents, Autogen, and n8n workflows, with reports intended to help developers and security teams prioritize review and remediation.
Key Features
- Analyzes workflow structure across supported agent frameworks and represents agents, tools, and handoffs as a graph.
- Assigns capabilities such as shell execution, file access, database access, and network communication to agents.
- Uses Python AST inspection to identify capabilities in custom tools, in addition to matching tool names and categories.
- Flags excessive agency and the combination of private-data access, untrusted-content exposure, and external communication.
- Traces whether untrusted input can reach dangerous sinks, including across agent handoffs, with confidence labels.
- Produces HTML reports with workflow visualizations and JSON exports for machine-readable review.
- Provides a local dashboard with SQLite-backed run history.
Use Cases
- Agent developers can review a LangGraph or CrewAI workflow before deployment to spot agents with broader capabilities than their tasks require.
- Security engineers can assess whether user-provided or retrieved content can reach shell, code execution, database, file-write, or exfiltration capabilities.
- Teams maintaining multi-agent systems can examine risk paths that cross agent handoffs and are difficult to see in isolated file scans.
- CI maintainers can export audit results as JSON and incorporate workflow checks into an existing review process.
Getting Started
Python 3.9 or later is specified in the README. Install the core package from a clone:
pip install -e .
Then run agentsec scan langgraph -i <workflow-directory> -o report.html. See the README for framework-specific usage, optional dashboard dependencies, and further setup details.
Considerations
- This is static analysis: it parses workflow code and does not execute it. Findings therefore depend on the patterns and capabilities the analyzers recognize, and should not be treated as a substitute for runtime testing or a full security review.
- The README describes high confidence for tracing within one agent and medium confidence across handoffs, so cross-agent paths warrant human validation.
- Python 3.9 or later is required. The README presents the dashboard as an optional installation extra.
- The repository lists 0 stars and 0 forks, so there is little public adoption signal in the supplied metadata. Check the project and test results against your own workflows before relying on it in a security process.
Found this useful?
Share it with someone who would like AgentSec.
Source repository
Open the original repository on GitHub.
Related repositories
Similar repositories that may be relevant next.

lilbee: Run Local AI and Search Your Files
October 6, 2026
lilbee is a local AI model manager and search engine for files, code, and crawled websites. It offers cited answers through a terminal app, CLI, MCP server, REST API, and Python library.

seclab-taskflow-agent: Define AI Workflows in YAML
October 6, 2026
A Python framework and CLI for building multi-agent workflows from YAML, with MCP tools and configurable model backends. It is aimed at security research, code auditing, and other repeatable agent tasks.

omnigent: Orchestrate AI Coding Agents Across Harnesses
October 5, 2026
Omnigent provides a shared orchestration layer for AI coding agents, with policies, sandboxing, and team collaboration. It suits developers who want to combine agent runtimes and access sessions across devices without tying workflows to one harness.

agentevals: Evaluate AI Agents from OpenTelemetry Traces
October 4, 2026
agentevals scores AI agent behavior from existing OpenTelemetry traces, without rerunning agents or making extra model calls. It suits teams building instrumented agents that need local evaluation, golden-set checks, or CI quality gates.