Grey Panda is open-source and community-built. Whether you've found a bug, have an idea, want to contribute a rule, or need to report a vulnerability โ here's how to reach us.
Open an issue with our templates โ bug report, feature request, or propose a new scanner rule.
Open an issue โDiscussions is the place for questions, show-and-tell, and design conversations with the community.
Start a discussion โFound a security issue in Grey Panda itself? Please report it privately via a GitHub Security Advisory โ never a public issue.
Open a private advisory โAdding a scanner rule is editing one dataclass with a bad + good example. New contributors welcome โ look for good first issue.
The fastest way to help: star the repo so more developers and reviewers discover it.
Star on GitHub โpip install grey-panda โ pure Python, zero dependencies, Python 3.9+.
Grey Panda is a defensive security tool and a strong floor, not a ceiling. It helps you find and fix AI/agent/MCP risks โ it does not certify compliance or replace a human review or red-team for high-stakes systems. Please read what it can & cannot do before relying on it.