Documentation

Everything you need to ship safely.

Install once, then scan, guard, and verify — from the terminal, your IDE, or CI. Zero dependencies, Python 3.9+, and deterministic — no LLM in the loop, so the same code always yields the same verdict, fully offline.

$ pip install grey-panda
Start here

Two-minute quick start

# 1. install (pure Python, zero dependencies)
pip install grey-panda

# 2. scan your repo — real findings, beautiful report
gp scan .

# 3. add drop-in guardrails — you never rewrite your LLM call, you wrap it
from greypanda import PromptGuardrail, DLPScanner, OutputGuardrail
safe  = guard.assert_safe(user_input)
clean = dlp.redact(safe)
answer = out.sanitize(call_your_llm(clean)).sanitized_text
The five kits

Pick your front door

Each kit has a friendly README plus focused how-to guides. Same engine underneath.

Reference

The gp command line

gp scan [path]Scan for AI/agent/MCP issues (--profile, --format md/json/sarif, --fail-on).
gp init [path]Scaffold config, a GitHub Action, and pre-commit into a repo.
gp verify [path]AISVS Level 1/2/3 verification report.
gp checklistPrint the AI security checklist.
gp standards [id]List or explain standards / control IDs.
gp agbom <agent>Emit an Agent Bill of Materials.
gp mcpRun Grey Panda as an MCP server (stdio).
gp doctorEnvironment self-check + honest-limits pointer.
In your IDE

Call Grey Panda while you code

Grey Panda ships as an MCP server, so Claude Code, Cursor, Windsurf, or VS Code can call it directly.

// Claude Code / Cursor / Windsurf MCP config
{ "mcpServers": { "grey-panda": { "command": "gp", "args": ["mcp"] } } }

Then ask your assistant to "review this file with grey panda" or "explain LLM03".

Ready?

Scan your repo now.

$ pip install grey-panda && gp scan .