AgentStack
Browse Sign in
Browse Why AgentStack Sell Docs
Sign in
MCP unreviewed Apache-2.0 Self-run

SafeAI

mcp-ikaruscareer-safeai · by ikaruscareer

Static analysis and attack-surface scanner for AI agents — SAST for prompts, tools, MCP servers, and agent workflows. Detects capabilities, prompt risks, tool permissions, and governance gaps before deployment.

No reviews yet
0 installs
14 views
0.0% view→install

Install

$ agentstack add mcp-ikaruscareer-safeai

Open-source listing, not yet scanned by AgentStack. Follow the source repository for install instructions.

Security review

⚠ Flagged

1 finding(s); flagged for manual review. · v0.1.0 How review works →

  • Prompt-injection patterns
  • Secret / credential exfiltration
  • Dangerous shell & filesystem operations
  • Untrusted network calls
  • Known-malicious package signatures
  • high Dangerous shell/eval execution.

What it can access

  • Network access No
  • Filesystem access No
  • Shell / process execution Used
  • Environment & secrets No
  • Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

View the full security report →

Reliability & compatibility

Not yet reviewed
0 installs to date
no reviews yet
23d ago

Declared compatibility

Claude CodeClaude DesktopCursorWindsurf

Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.

Preview Execution monitoring

We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.

How agent discovery & health will work →
Are you the author of SafeAI? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

SafeAI — Static AI Capability & Risk Analyzer

[](https://github.com/ikaruscareer/SafeAI/actions/workflows/ci.yml) [](https://scorecard.dev/viewer/?uri=github.com/ikaruscareer/SafeAI) [](https://safeai-analyzer.ikaruscareer.com) [](https://github.com/ikaruscareer/SafeAI/releases/tag/v1.9.0) [](https://www.bestpractices.dev/en/projects/14126)

SafeAI is a static analysis tool that scans AI application source code for security risks, capability exposure, and governance gaps. It runs entirely offline, never executes agents or calls LLMs, and integrates into CI/CD pipelines.

> 🌐 safeai-analyzer.ikaruscareer.com — project landing page


Know Your Agent (KYA)

SafeAI now turns static scan results into a private, historical inventory of AI agents and their findings.


Why SafeAI?

Traditional application security tools (SAST, SCA, IaC scanning) are not designed for AI agent systems. AI applications introduce new risk surfaces:

  • Prompt injection — untrusted input flows into model prompts
  • Agent tool misuse — agents with filesystem, shell, or database access
  • Capability sprawl — frameworks expose capabilities without visibility
  • MCP exposure — Model Context Protocol endpoints and tools
  • Governance gaps — missing authentication, permissions, audit trails

SafeAI fills this gap by analyzing frameworks, agents, tools, capabilities, and MCP integrations at rest—before deployment.

SafeAI analyzes AI applications without executing them, helping developers discover capabilities, identify potential risks, and improve governance early in the software lifecycle.

Designed to be lightweight, explainable, and community-driven, SafeAI aims to become an open foundation for AI capability and risk analysis.

SafeAI sits before runtime guardrails and red-teaming tools in the security lifecycle. It scans agent source code at commit time — detecting framework-specific capabilities, MCP misconfigurations, and prompt injection patterns — before you ever deploy an agent to staging. It does not replace runtime tools (Microsoft AGT), evaluation frameworks (LangSmith, DeepEval), or red-teaming scanners (Promptfoo, Garak). It complements them: find the risk in code first, then validate at runtime.


Key Features

| Feature | Description | |---------|-------------| | Framework Detection | Detects and parses 16 AI agent frameworks (AST + config + regex, no mutual exclusion) | | Tool Identity & Access Modes | Capabilities attributed to named tools (agent / MCP server / skill / tool / workflow node) on an access scale `none


Supported Frameworks

| Framework | Detection | Discovery | Capability Analysis | Risk Analysis | Status | |-----------|-----------|-----------|-------------------|---------------|--------| | LangGraph | ✔ | Partial | Partial | Partial | Partial | | CrewAI | ✔ | Partial | Partial | Partial | Partial | | AutoGen | ✔ | Partial | Minimal | Minimal | Experimental | | LangChain | ✔ | Partial | Partial | Partial | Partial | | Semantic Kernel | ✔ | Partial | Partial | Partial | Partial | | OpenAI Agents SDK | ✔ | Partial | Partial | Partial | Partial | | Microsoft Agent Framework | ✔ | Partial | Minimal | Minimal | Experimental | | Azure AI Foundry | ✔ | Minimal | Minimal | Minimal | Experimental | | Bedrock Agent | ✔ | Minimal | Minimal | Minimal | Experimental | | Claude Code | ✔ (deep) | Deep | Partial | Partial | Partial | | Google ADK | ✔ | Partial | Minimal | Minimal | Experimental | | Mastra | ✔ | Partial | Minimal | Minimal | Experimental | | Haystack | ✔ | Partial | Minimal | Minimal | Experimental | | LlamaIndex | ✔ | Partial | Minimal | Minimal | Experimental | | Dify | ✔ | Minimal | Minimal | Minimal | Experimental | | n8n | ✔ | Partial | Minimal | Minimal | Experimental |

Framework Support Details

  • LangGraph — detects StateGraph, add_edge, bind_tools, nodes, models
  • CrewAI — detects Agent, Task, tools, models
  • AutoGen — detects AssistantAgent, UserProxyAgent, register_for_llm, register_function, models
  • LangChain — detects AgentExecutor, Chain, Tool, PromptTemplate, models
  • Semantic Kernel — detects Kernel.invoke, plugins, functions, skills, memory
  • OpenAI Agents SDK — detects Agent, tools, handoffs, MCP references
  • Microsoft Agent Framework — detects AgentClient, tools, workflows, Azure models
  • Azure AI Foundry — detects YAML configurations with Azure resources
  • Bedrock Agent — detects JSON configurations with Bedrock resources
  • Claude Code — structural analysis of .claude/settings.json, permission

grants, .mcp.json, slash commands, subagent definitions, and lifecycle hooks

  • Google ADK — detects ADK agent, workflow, tool, and model patterns
  • Mastra — detects Mastra agents, workflows, tools, and model references
  • Haystack — detects Haystack pipelines, agents, tools, and retrievers
  • LlamaIndex — detects agents, tools, indexes, and model references
  • Dify — detects Dify workflow and agent configuration files
  • n8n — detects n8n workflow exports, nodes, and connections

Maturity is on the scale defined in [FRAMEWORK_SUPPORT.md](FRAMEWORK_SUPPORT.md): Partial = reliable detection and discovery with capability/risk analysis over common patterns; Experimental = detection and basic artifact discovery with limited framework-specific analysis. No framework is rated fully Supported yet — SafeAI is in early preview and deliberately does not overclaim coverage.

Framework Test Coverage (v1.8.0)

Representative test fixtures and validation tests for framework detection:

| Framework | Test | Fixture | Contributor | |-----------|------|---------|-------------| | LangGraph | test_langgraph_framework.py | fixtures/langgraph/representative/graph.py | @adnqcr7-code [#63] | | LlamaIndex | test_llamaindex_framework.py | fixtures/llamaindex/representative/agent.py | @adnqcr7-code [#61] | | CrewAI | test_crewai_framework.py | fixtures/crewai/representative/crew.py | @adnqcr7-code [#62] | | Claude Code | test_claude_code_deep.py | fixtures/claude_code/compatibility/ | @adnqcr7-code [#59] |


Supported Capabilities

SafeAI fingerprints capabilities at the framework object level and via fallback regex patterns. Each capability includes evidence, confidence score, resolved definition, and provenance.

| Capability | Category | Risk Impact | |------------|----------|-------------| | Shell Execution | Shell | Command injection, host compromise | | Filesystem Access | Filesystem | Data exfiltration, file tampering | | Browser Automation | Browser | UI-based attacks, credential theft | | Planning / Orchestration | Planner | Autonomous decision chain risk | | Agent Delegation | Delegation | Unchecked sub-agent authority | | Memory / Checkpoint | Memory | Data retention across sessions | | RAG / Retrieval | RAG | Document exfiltration, prompt injection via documents | | GitHub Integration | GitHub | Repository access, secret leakage | | Slack Integration | Slack | Channel monitoring, message injection | | Email Integration | Email | Phishing, data exfiltration | | Database Access | Databases | SQL injection, data breach | | Cloud Services | Cloud | Cloud resource abuse, cost escalation | | External APIs | External APIs | Third-party data exfiltration | | MCP Services | MCP | Exposed endpoints, unauthorized tool access | | Human Approval | Human Approval | Approval bypass risk | | Multi-Agent | Multi-Agent | Delegation-based privilege escalation | | Container | Container | Container orchestration abuse (Docker, Kubernetes) | | Collaboration | Collaboration | Cross-system coordination risk | | Untrusted Input | Untrusted Input | Injection surface into agent pipelines |

> Note: A capability is detected wherever the evidence lives — through a > framework adapter, a direct pattern detector (for example Docker, > Kubernetes, S3, Slack, Jira, browser automation, GCP), or MCP > configuration analysis. Capabilities that only MCP configuration exposes > today (e.g. email, human approval gates) are still flagged — the tool is > reported with an unattributed identity rather than a guessed owner.


Know Your Agent (KYA) — Shared Registry

Every scan automatically builds a private "Know Your Agent" registry of scan-derived agent records — no server, no account, no network call, no source upload. Scans from every project accumulate in one shared SQLite database (SAFEAI_REGISTRY env var or ~/.safeai/registry.db), so safeai registry list shows the whole organization's agents from any folder.

safeai scan .                              # scan + accumulate into the shared registry
safeai scan . --manifest safeai-manifest.json   # also write the canonical KYA manifest
safeai scan . --html report.html                # interactive HTML report (risk gauge, escalations)
safeai registry list                       # agents/workflows from every scanned project
safeai registry list --format html > registry.html   # shareable HTML inventory
safeai registry show             # latest KYA record
safeai registry history          # all scans for an agent
safeai registry diff  --from previous --to latest
safeai registry export --format json --output inventory.json
safeai registry export --format html --output inventory.html

What you get on the first run:

  • A static scan ran successfully.
  • The shared registry was initialized (SAFEAI_REGISTRY or

~/.safeai/registry.db).

  • One or more KYA agent records were created with stable identities.
  • Findings carry confidence, provenance, remediation, and stable fingerprints.
  • No source code or secrets are uploaded or stored in output artifacts.

KYA records static evidence, not runtime truth. It answers "what does the source/configuration say this agent can do?" — never "what is this agent doing in production?" See [REGISTRY.md](REGISTRY.md), [KYAMANIFEST.md](KYAMANIFEST.md), and [LIMITATIONS.md](LIMITATIONS.md).

CI note: registry persistence is auto-disabled for bare CI jobs (the CI env var). Use --registry "$RUNNER_TEMP/registry.db", set SAFEAI_REGISTRY to a shared path, or use --no-registry for ephemeral scans.


Installation

Requirements

  • Python 3.11, 3.12, or 3.13
  • PyYAML (for YAML configuration parsing)

Install from source

git clone https://github.com/ikaruscareer/SafeAI.git
cd SafeAI
pip install -e .

Install development dependencies

pip install -e ".[dev]"

Privacy & Telemetry

SafeAI collects no data by default. Usage telemetry is opt-in, anonymous, and fully documented in [PRIVACY.md](PRIVACY.md). If you do nothing, nothing is ever sent. See PRIVACY.md for the complete data contract, what is never collected, and how to disable telemetry.


CLI Usage

python -m safeai scan  [options]
python -m safeai registry  [options]

Options

| Option | Default | Description | |--------|---------|-------------| | directory | required | Path to scan | | --sarif | report.sarif | SARIF output path (empty string to skip) | | --json | — | JSON output path | | --html | — | HTML report output path | | --manifest | — | Canonical KYA manifest output path (safeai-manifest.json) | | --baseline | — | Prior manifest/report for new/existing comparison | | --fail-on-new | off | With --baseline: fail only on new/regressed findings | | --policy | .safeai/policy.yml | Policy-as-code YAML file | | --suppressions | .safeai/suppressions.yml | Suppressions YAML file | | --registry | shared (SAFEAI_REGISTRY/~/.safeai/registry.db) | Registry database path | | --no-registry | off | Skip registry persistence | | --strict-registry | off | Fail the scan if registry persistence fails | | --pr-comment | — | Write a reviewer-facing Markdown summary of capability escalations to this path (never posted anywhere) | | --pr-comment-stdout | off | Print the PR comment Markdown to stdout | | --fail-on-escalation | — | Fail if a capability escalation at or above critical, high, or medium is detected (requires --baseline) | | --scorecard / --scorecard-md | — | Write the SafeAI Security Scorecard as Markdown to this path | | --scorecard-json | — | Write the SafeAI Security Scorecard as JSON (conforms to safeai/scorecard-schema.json) | | --scorecard-summary | — | Append the Security Scorecard to the GitHub Actions step summary ($GITHUB_STEP_SUMMARY) | | --scorecard-fail-under | — | Fail the scan if the Security Scorecard score is below this value (010) | | --rules | built-in | Custom rules directory | | --fail-on | critical | Exit code threshold: critical, high, medium | | --verbose | — | Enable verbose output |

Exit Codes

| Code | Condition | |------|-----------| | 0 | No findings at or above threshold; policy outcome not deny | | 1 | Finding at or above threshold, or policy outcome deny | | 2 | Operational error (e.g. --strict-registry persistence failure) |

Suppressed findings never trigger exit code 1. With --fail-on-new, only findings classified new or regressed against the baseline are gated.

Common 1.4 Workflows

# canonical manifest + baseline seed
python -m safeai scan . --manifest safeai-manifest.json

# CI/PR scan: fail only for new or regressed findings
python -m safeai scan . --baseline safeai-manifest.json --fail-on-new --fail-on high

# CI/PR scan: fail on capability escalations and render a PR comment
python -m safeai scan . --baseline safeai-manifest.json \
  --fail-on-escalation high --pr-comment comment.md

# inspect the shared KYA registry
python -m safeai registry list
python -m safeai registry show 
python -m safeai registry history 
python -m safeai registry diff  --from previous --to latest
python -m safeai registry export --format json --output safeai-kya-inventory.json

Example Output

> See [REPORTINGGUIDE.md](./REPORTINGGUIDE.md) for a complete guide to > interpreting each output format (HTML, JSON, SARIF, PR comments, scorecard, > registry) and triaging findings.

Terminal

SafeAI Scan Summary
Files: 12
Frameworks: langgraph, crewai
MCP assets: 2
Overall AI Risk Score: 73
critical: 1
high: 3
medium: 5
Findings:
[critical] app.py:10 - Untrusted input interpolated into prompt
[high] app.py:22 - Capability detected: shell_execution
[high] mcp.json:1 - MCP configuration does not define authentication

Example: LangGraph agent with MCP

{
  "Framework": "LangGraph",
  "Capabilities": ["Planner", "Memory", "Filesystem", "MCP"],
  "Risk Score": 73,
  "Findings": 9,
  "Critical": 1,
  "High": 3
}

CI/CD Integration

GitHub Actions — SafeAI Static Analysis

[](https://github.com/marketplace/actions/safeai-static-analysis)

SafeAI ships a ready-to-use composite action for GitHub-hosted runners. The action is a thin, pure-Python driver: it installs the SafeAI-Static-Analyzer PyPI distribution into the runner's Python, runs python -m safeai scan on your repository, preserves the tool's native exit codes, and always writes a SARIF 2.1.0 artifact (even when the scan fails). It never evaluates any input through a shell, never executes your agent code, and makes no network calls beyond installing the PyPI package.

Use it with uses: ikaruscareer/SafeAI@ (see [Version pinning](#version-pinning)).

name: safeai-scan
on:
  push:
  pull_request:

permissions:
  contents: read

jobs:
  safeai-scan:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4

      - uses: actions/setup-python@v5
        with:
          python-version: '3.12'

      - name: Scan with SafeAI
        id: safeai
        uses: ikaruscareer/SafeAI@v1.0.0
        with:
          path: .
          fail-on: critical

      - name: Upload SARIF to GitHub Advanced Security

…

## Source & license

This open-source MCP server is cataloged on AgentStack and links to its original source — we do not rehost the code.

- **Author:** [ikaruscareer](https://github.com/ikaruscareer)
- **Source:** [ikaruscareer/SafeAI](https://github.com/ikaruscareer/SafeAI)
- **License:** Apache-2.0
- **Homepage:** https://safeai-analyzer.ikaruscareer.com/

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet, be the first.

Versions

  • v0.1.0 Imported from the upstream source.