No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →
by hugoii · Agent Tool · ★ 62
Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h
🔒 Is llm-agent-audit safe to install? View the security audit →
Action-boundary audits for tool-using AI agents I test whether untrusted content, such as a user message, ticket, email, document, call transcript, or tool response, can push your tool-using AI agent into a high-impact action it should not take: issuing a refund, moving money, changing a vendor's bank account, deleting an account, granting access, disabling MFA, dispatching a job, or exporting data. Want the scenarios I would test for your agent? Email me actionboundary.dev How it works. Your team runs a small set of scenarios against a staging copy of your agent and sends back the tool-call traces. You get an OWASP-mapped report with the evidence and concrete fixes. No production access, no real customer data, no shared credentials. Why it is different. Most AI testing checks what the model says. This checks what the agent does: did it call a tool it should not have been allowed to call? Pass or fail comes from the agent's actual tool-call trace, not from string-matching its re
| Stars | 62 |
| Forks | 9 |
| Language | Python |
| Category | Agent Tool |
| License | MIT |
| Quality Score | 66.512277186913/100 |
| Last Updated | 2026-07-10 |
| Created | 2026-06-04 |
| Platforms | python |
| Est. Tokens | ~15k |
Looking for a llm-agent-audit alternative? If you're comparing llm-agent-audit with other agent tool tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.
Task-scoped authorization for AI agents. Cryptographic warrants constrain tools and arguments, prevent privile
A secure local gateway for AI agents to reliably call approved enterprise APIs, tools, and services.
Security toolkit for AI agents. Scan your machine for dangerous skills and MCP configs, monitor for supply cha
Build Secure and Compliant AI agents and MCP Servers. YC W23
Ask Codex, Gemini, Grok, and 400+ OpenRouter models (Qwen, Kimi, DeepSeek) for second opinions or arbiter-medi
Agent orchestration & security template featuring MCP tool building, agent2agent workflows, mechanistic interp
Explore other popular agent tool tools:
llm-agent-audit is Trace-backed Agent Authorization Reviews for tool-using AI agents. Staging-only evidence for payment, record-change, access, and export actions.. It is categorized as a Agent Tool with 62 GitHub stars.
llm-agent-audit is primarily written in Python. It covers topics such as access-control, agent-security, ai-agents.
You can find installation instructions and usage details in the llm-agent-audit GitHub repository at github.com/hugoii/llm-agent-audit. The project has 62 stars and 9 forks, indicating an active community.
llm-agent-audit is released under the MIT license, making it free to use and modify according to the license terms.
The top alternatives to llm-agent-audit on Agent Skills Hub include tenuo, OctoBus, agentseal. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.
Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.
The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.
Sources & who's responsible: