AgentLint:AI代理配置的靜態安全掃描器

AgentLint:AI代理配置的靜態安全掃描器

Hacker News·

AgentLint是一款新推出的靜態安全掃描器,旨在審核AI代理的配置,特別針對Claude Code、Cursor和CLAUDE.md文件,以在執行前偵測到命令注入和洩漏機密等風險模式。

Navigation Menu

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

To see all available qualifiers, see our documentation.

Supply-chain security for AI agent configurations. Scan Claude Code, Cursor, and CLAUDE.md files for risky patterns.

License

Uh oh!

There was an error while loading. Please reload this page.

akz4ol/agentlint

Folders and files

Latest commit

History

Repository files navigation

AgentLint

Supply-chain security for AI agent configurations

Image

Image

Image

AgentLint helps developers and security teams audit AI agent configurations before they execute—catching curl | bash, secret leaks, and privilege escalation in Claude Code, Cursor, and CLAUDE.md files.

Why AgentLint?

AI coding agents are powerful—but their configuration files are a new attack surface:

AgentLint treats agent configs like code: scan, diff, and gate them in CI.

Quick Start

Expected output (clean project):

Expected output (risky config):

How It Works

Examples

Try AgentLint on our example configs:

See examples/ for full details.

What It Detects

Run agentlint rules list to see all rules, or agentlint rules explain EXEC-001 for details.

CI/CD Integration

GitHub Actions

Findings appear as code annotations in PRs via GitHub Code Scanning.

Exit Codes

Configuration

Create agentlint.yaml to customize behavior:

Generate a starter config:

Auto-Fix

Automatically fix simple issues:

Currently fixable rules:

Baseline

Suppress known findings to focus on new issues:

Diff Mode

Detect behavioral changes between versions:

Comparison with Alternatives

AgentLint is purpose-built for AI agent configs. General linters miss agent-specific risks.

Integrations

Roadmap

Documentation

Contributing

We welcome contributions! See CONTRIBUTING.md for:

License

Apache 2.0 — see LICENSE

Built to secure the AI agent ecosystem

About

Supply-chain security for AI agent configurations. Scan Claude Code, Cursor, and CLAUDE.md files for risky patterns.

Topics

Resources

License

Code of conduct

Contributing

Security policy

Uh oh!

There was an error while loading. Please reload this page.

Stars

Watchers

Forks

Releases

  1

Packages

  0

Contributors

  2

Image

Image

Languages

Footer

Footer navigation

Hacker News

相關文章

  1. Show HN:用於 CI/CD 中 AI/LLM 安全掃描的 GitHub Action

    4 個月前

  2. Show HN:AI Code Guard – AI 生成程式碼的安全掃描器

    3 個月前

  3. Squads CLI:AI 代理的 Looker 工具

    4 個月前

  4. Skillkit:AI 代理技能的套件管理器

    Product Hunt - AI · 3 個月前

  5. Show HN:AgentShield,Cowork 與 AI Agent 的缺失安全層

    3 個月前