Install once, then scan, guard, and verify — from the terminal, your IDE, or CI. Zero dependencies, Python 3.9+, and deterministic — no LLM in the loop, so the same code always yields the same verdict, fully offline.
Each kit has a friendly README plus focused how-to guides. Same engine underneath.
Drop-in SDK guardrails and IDE integration for anyone building AI features.
The AppSec gate: turn "is this safe to ship?" into a signable decision.
26 high-precision rules, SARIF output, and an automated PR gate.
Least privilege by construction, plus rug-pull detection for MCP tools.
The knowledge pack, the mappings, and the honest limits doc.
How the pieces fit: the pipeline, the trust boundaries, and the one-engine design — with diagrams.
gp command line| gp scan [path] | Scan for AI/agent/MCP issues (--profile, --format md/json/sarif, --fail-on). |
| gp init [path] | Scaffold config, a GitHub Action, and pre-commit into a repo. |
| gp verify [path] | AISVS Level 1/2/3 verification report. |
| gp checklist | Print the AI security checklist. |
| gp standards [id] | List or explain standards / control IDs. |
| gp agbom <agent> | Emit an Agent Bill of Materials. |
| gp mcp | Run Grey Panda as an MCP server (stdio). |
| gp doctor | Environment self-check + honest-limits pointer. |
Grey Panda ships as an MCP server, so Claude Code, Cursor, Windsurf, or VS Code can call it directly. The model does the reasoning; Grey Panda hands back deterministic, OWASP-cited findings.
Six tools — scan, review-snippet, verify, explain-risk, list-standards, checklist. Then ask your assistant to "review this file with grey panda", "are we AISVS Level 2 ready?", or "explain LLM01:2026".