{"name":"AgentSec: Audit AI Agent Workflows for Security Risks","description":"AgentSec statically analyzes AI agent workflows for excessive permissions and paths from untrusted input to dangerous capabilities. It is aimed at developers and security teams reviewing supported agent frameworks before deployment or as part of CI.","github":"https://github.com/yohanguez/AgentSec","url":"https://osrepos.com/repo/yohanguez-agentsec","source":"osrepos.com","sourceDescription":"This repository profile is provided by osrepos.com, an open source repository discovery platform.","repositoryProfile":"https://osrepos.com/repo/yohanguez-agentsec","generatedFor":"open source discovery and AI-assisted research","markdown":"https://osrepos.com/repo/yohanguez-agentsec.md","json":"https://osrepos.com/repo/yohanguez-agentsec.json","topics":["python","ai-agents","security","cli","static-analysis","agent-workflow-security"],"keywords":["python","ai-agents","security","cli","static-analysis","agent-workflow-security"],"stars":null,"summary":"AgentSec statically analyzes AI agent workflows for excessive permissions and paths from untrusted input to dangerous capabilities. It is aimed at developers and security teams reviewing supported agent frameworks before deployment or as part of CI.","content":"## Overview\n\nAgentSec is a Python tool for assessing the security of AI agent workflows without executing them. It builds a graph of agents, tools, and handoffs, then checks what each agent can do and whether untrusted content can reach risky capabilities.\n\nIt is useful when a per-file code scan misses risks created by connections between agents. Its analysis covers LangGraph, CrewAI, OpenAI Agents, Autogen, and n8n workflows, with reports intended to help developers and security teams prioritize review and remediation.\n\n## Key Features\n\n- Analyzes workflow structure across supported agent frameworks and represents agents, tools, and handoffs as a graph.\n- Assigns capabilities such as shell execution, file access, database access, and network communication to agents.\n- Uses Python AST inspection to identify capabilities in custom tools, in addition to matching tool names and categories.\n- Flags excessive agency and the combination of private-data access, untrusted-content exposure, and external communication.\n- Traces whether untrusted input can reach dangerous sinks, including across agent handoffs, with confidence labels.\n- Produces HTML reports with workflow visualizations and JSON exports for machine-readable review.\n- Provides a local dashboard with SQLite-backed run history.\n\n## Use Cases\n\n- **Agent developers** can review a LangGraph or CrewAI workflow before deployment to spot agents with broader capabilities than their tasks require.\n- **Security engineers** can assess whether user-provided or retrieved content can reach shell, code execution, database, file-write, or exfiltration capabilities.\n- **Teams maintaining multi-agent systems** can examine risk paths that cross agent handoffs and are difficult to see in isolated file scans.\n- **CI maintainers** can export audit results as JSON and incorporate workflow checks into an existing review process.\n\n## Project Facts\n\n- Language: Python\n- License: Apache-2.0\n- Stars: 0\n- Forks: 0\n- Topics: none listed\n- Archived: no\n\n## Getting Started\n\nPython 3.9 or later is specified in the README. Install the core package from a clone:\n\n```bash\npip install -e .\n```\n\nThen run `agentsec scan langgraph -i <workflow-directory> -o report.html`. See the [README](https://github.com/yohanguez/AgentSec#readme) for framework-specific usage, optional dashboard dependencies, and further setup details.\n\n## Considerations\n\n- This is static analysis: it parses workflow code and does not execute it. Findings therefore depend on the patterns and capabilities the analyzers recognize, and should not be treated as a substitute for runtime testing or a full security review.\n- The README describes high confidence for tracing within one agent and medium confidence across handoffs, so cross-agent paths warrant human validation.\n- Python 3.9 or later is required. The README presents the dashboard as an optional installation extra.\n- The repository lists 0 stars and 0 forks, so there is little public adoption signal in the supplied metadata. Check the project and test results against your own workflows before relying on it in a security process.","metrics":{"detailViews":0,"githubClicks":2},"dates":{"published":null,"modified":"2026-10-06T11:45:22.000Z"}}