Architecture

One engine. Five kits.
Defense in depth.

Grey Panda is built on four principles and implemented as a single, tested, zero-dependency engine that every surface — CLI, IDE, CI, and the module kits — shares. Here's how the pieces fit.

Principles

Five ideas, held as constraints

1

Secure path = easy path

Every control is a drop-in. Adding the core guardrails to an existing LLM call takes under two minutes and never requires rewriting the call.

2

Honest about limits

Every capability ships with a confidence level and a failure condition. A tool that's honest about what it can't do is one you can trust.

3

Defense in depth, not prevention theatre

No single layer stops everything. Known patterns are blocked at input; data is quarantined even if injection succeeds; blast radius is limited by least-privilege agents; every action is auditable.

4

Standards-anchored, not opinion-driven

Every rule, checklist item, and SDK control cites a specific OWASP / AISVS / ACS ID. No bare assertions.

5

Works for one dev or ten thousand

Profiles scale the process, not the safety floor. A solo dev and an enterprise get the same protection, sized differently.

System

One engine, many front doors

A single knowledge pack feeds one engine; the engine powers every surface and every module kit. No duplication, no drift.

STANDARDS KNOWLEDGE PACK OWASP LLM · DSGAI · Agentic · AISVS · MCP · Agent Control Standard › single source of truth ENGINE · src/greypanda · zero dependencies Scanner26 rules SDK7 controls VerifyAISVS L1–L3 MCP serverstdio JSON-RPC SURFACES CLI · gp MCP server GitHub Action IDE skill MODULE KITS 🧰 DeveloperModule 1 🛡️ ReviewerModule 2 🔍 Scanner/CIModule 3 🤖 MCP/AgentModule 4 📚 StandardsModule 5
The scanner, SDK, gp verify, the MCP server, and the AI skill all cite from one machine-readable standards pack.
Runtime

The 7-step request pipeline

Grey Panda wraps your existing LLM call. Untrusted input is screened and redacted on the way in; the response is scanned and neutralised on the way out; every decision is audited without logging raw text.

Grey Panda wraps your call — you never rewrite it user input STEP 1PromptGuardrail STEP 2DLPScanner STEP 3SecureContext STEP 4LLM callunchanged STEP 5DLPScanner STEP 6OutputGuardrail STEP 7AuditLogger safe output Building an agent? Add AgentSecurityWrapper — the Rule of Two enforced at construction, deny-by-default tools, HITL gates, per-session call budgets, and a kill switch.
Steps 1–3 protect the input, step 4 is your unchanged call, steps 5–7 protect the output and the audit trail.
Trust boundaries

Where the controls sit

Untrusted inputs never reach your trusted app or data stores without passing a Grey Panda control. When the model is fooled — and it will be — the blast radius is bounded.

UNTRUSTED GREY PANDA YOUR APP · trusted End user input External APIs /3rd-party MCP tools Retrieved / RAG content PromptGuardrail+ DLPScanner McpServerGuardpin · schema · scope SecureContexttrust-tag as data LLM inference Agent orchestratorAgentSecurityWrapper · HITL · kill switch Tool executor OutputGuardrail + DLPScanner scans the response on the way back to the user AuditLogger structured events · zero raw text · SIEM-ready
Every crossing from untrusted to trusted passes a control; the return path is scanned and sanitised; all of it is audited.
Layout

The repository

Five audience-facing module kits at the root, all powered by one shared engine under src/greypanda/.

grey-panda/
├── Module 1 - Developer Kit/ quickstart, SDK how-tos
├── Module 2 - Security Reviewer Kit/ reviewer guide, AISVS, threat-models
├── Module 3 - Scanner and CI-CD Kit/ rules catalog, CI + SARIF how-tos
├── Module 4 - MCP and Agent Security Kit/ MCP + agent how-tos
├── Module 5 - Standards and Governance Kit/ can/cannot, mappings
├── src/greypanda/ ← the shared engine (installable)
│   ├── sdk/ guardrails · dlp · context · agent · audit · mcp · acs
│   ├── scanner/ rules · engine · reporters · profiles
│   ├── verify/ aisvs
│   ├── mcpserver/ stdio MCP server
│   ├── cli/ gp
│   └── data/ standards/*.json + checklist
├── examples/ · tests/ · skill/ · docs/ (this site)
Dig in

Read the code, run the tests.