Open-source · Zero-dependency · OWASP-anchored

The calm guardian for
AI, agent & MCP code.

A standards-anchored AI security toolkit any developer or reviewer can run in seconds — in the IDE, in CI, or from the terminal. You never rewrite your LLM call. You wrap it.

$ pip install grey-panda
Apache-2.0 Python 3.9+ runtime deps 0 26 scanner rules LLM · Agentic · AISVS · MCP
Grey Panda scanning a vulnerable app, then the same app rebuilt clean
The problem

AI ships a new attack surface — mostly unguarded.

Traditional AppSec never covered prompts, tools, agents, or MCP. These are the risks your existing scanners don't see.

LLM01

Prompt injection is #1

The top AI attack pattern — and it needs no authentication. Any user input can hijack the model.

LLM03 · ASI

Agents act irreversibly

One injected instruction can make an agent send money, delete data, or call a tool with your credentials.

AISVS C10

MCP tool poisoning

A tool's description hides instructions, or a trusted tool is silently swapped after you approved it — a "rug pull".

The bundle

Five kits. One zero-dependency engine.

Each audience gets a clear front door — all powered by one shared, tested engine. No duplication, no drift.

How it works

A 7-step request pipeline.

Defense in depth: known patterns blocked at input, data quarantined even if injection succeeds, output cleaned, every action audited.

STEP 1
PromptGuardrail
block injection
STEP 2
DLPScanner
redact PII & secrets
STEP 3
SecureContext
tag trust
STEP 4
LLM call
your call — unchanged
STEP 5
DLPScanner
scan the response
STEP 6
OutputGuardrail
escape → XSS-safe
STEP 7
AuditLogger
zero-raw-text event
Building an agent?

Add AgentSecurityWrapper — the Rule of Two enforced at construction, deny-by-default tools, HITL gates, per-session budgets, and a kill switch. See the architecture →

Credibility

Standards-anchored, not opinion-driven.

Every rule, checklist item, and SDK control cites a specific ID. Also grounded in NIST AI 100-2 and Meta's "Rule of Two".

10
OWASP LLM Top 10 2026
LLM01–LLM10
21
GenAI Data Security
DSGAI01–DSGAI21
10
Agentic Apps Top 10
ASI01–ASI10
12
AISVS
C1–C12 · L1/L2/L3
2
MCP Security Guides
dev + third-party
5
Agent Control Standard
hooks · dispositions · AgBOM
Proof

Spotless by construction.

Grey Panda scans its own repository clean in CI. It practices exactly what it preaches.

26
scanner rules
0
runtime dependencies
76
tests, all green
3
formats: md·json·sarif
20 findings → 0 ✓ the same app, rebuilt with Grey Panda controls
For everyone

Same safety floor. Scaled process.

One tool, three profiles — from a solo indie dev to a regulated enterprise. Nobody is priced out of safety.

solo

Indie

Prototypes & side projects
  • High-signal core rules
  • Drop-in SDK
  • Fail on CRITICAL
team

Startup

Teams shipping fast
  • + DLP, RAG, MCP, shadow-AI
  • + CI gate & pre-commit
  • Fail on HIGH
enterprise

Regulated

Large / compliance-bound
  • Every rule on
  • + AppSec gate & AISVS L1/L2/L3
  • Fail on HIGH

🧭 Honest about limits

Grey Panda is a strong floor, not a ceiling. Pattern matching can't stop all prompt injection; regex DLP is language-specific; static analysis has false positives and negatives. We ship a whole document — with a confidence level and failure condition for every capability. Read what it can & cannot do →

Get started

Two minutes to safer AI.

$ pip install grey-panda && gp scan .