Install once, then scan, guard, and verify — from the terminal, your IDE, or CI. Zero dependencies, Python 3.9+.
Each kit has a friendly README plus focused how-to guides. Same engine underneath.
Drop-in SDK guardrails and IDE integration for anyone building AI features.
The AppSec gate: turn "is this safe to ship?" into a signable decision.
26 high-precision rules, SARIF output, and an automated PR gate.
Least privilege by construction, plus rug-pull detection for MCP tools.
The knowledge pack, the mappings, and the honest limits doc.
How the pieces fit: the pipeline, the trust boundaries, and the one-engine design — with diagrams.
gp command line| gp scan [path] | Scan for AI/agent/MCP issues (--profile, --format md/json/sarif, --fail-on). |
| gp init [path] | Scaffold config, a GitHub Action, and pre-commit into a repo. |
| gp verify [path] | AISVS Level 1/2/3 verification report. |
| gp checklist | Print the AI security checklist. |
| gp standards [id] | List or explain standards / control IDs. |
| gp agbom <agent> | Emit an Agent Bill of Materials. |
| gp mcp | Run Grey Panda as an MCP server (stdio). |
| gp doctor | Environment self-check + honest-limits pointer. |
Grey Panda ships as an MCP server, so Claude Code, Cursor, Windsurf, or VS Code can call it directly.
Then ask your assistant to "review this file with grey panda" or "explain LLM03".