Metadata-Version: 2.5
Name: mylonite
Version: 0.10.1
Summary: Open-source AI-layer security testing — probes your AI agent for weaknesses and writes a validated regression test for each one it finds, gating CI.
Project-URL: Homepage, https://github.com/Abidemialade/mylonite
Project-URL: Documentation, https://abidemialade.github.io/mylonite/
Project-URL: Source, https://github.com/Abidemialade/mylonite
Project-URL: Issues, https://github.com/Abidemialade/mylonite/issues
Project-URL: Changelog, https://github.com/Abidemialade/mylonite/blob/main/CHANGELOG.md
Author-email: Abidemi Alade <hello.mylonite@gmail.com>
Maintainer-email: Abidemi Alade <hello.mylonite@gmail.com>
License: 
                                         Apache License
                                   Version 2.0, January 2004
                                http://www.apache.org/licenses/
        
           TERMS AND CONDITIONS FOR USE, REPRODUCTION, AND DISTRIBUTION
        
           1. Definitions.
        
              "License" shall mean the terms and conditions for use, reproduction,
              and distribution as defined by Sections 1 through 9 of this document.
        
              "Licensor" shall mean the copyright owner or entity authorized by
              the copyright owner that is granting the License.
        
              "Legal Entity" shall mean the union of the acting entity and all
              other entities that control, are controlled by, or are under common
              control with that entity. For the purposes of this definition,
              "control" means (i) the power, direct or indirect, to cause the
              direction or management of such entity, whether by contract or
              otherwise, or (ii) ownership of fifty percent (50%) or more of the
              outstanding shares, or (iii) beneficial ownership of such entity.
        
              "You" (or "Your") shall mean an individual or Legal Entity
              exercising permissions granted by this License.
        
              "Source" form shall mean the preferred form for making modifications,
              including but not limited to software source code, documentation
              source, and configuration files.
        
              "Object" form shall mean any form resulting from mechanical
              transformation or translation of a Source form, including but
              not limited to compiled object code, generated documentation,
              and conversions to other media types.
        
              "Work" shall mean the work of authorship, whether in Source or
              Object form, made available under the License, as indicated by a
              copyright notice that is included in or attached to the work
              (an example is provided in the Appendix below).
        
              "Derivative Works" shall mean any work, whether in Source or Object
              form, that is based on (or derived from) the Work and for which the
              editorial revisions, annotations, elaborations, or other modifications
              represent, as a whole, an original work of authorship. For the purposes
              of this License, Derivative Works shall not include works that remain
              separable from, or merely link (or bind by name) to the interfaces of,
              the Work and Derivative Works thereof.
        
              "Contribution" shall mean any work of authorship, including
              the original version of the Work and any modifications or additions
              to that Work or Derivative Works thereof, that is intentionally
              submitted to Licensor for inclusion in the Work by the copyright owner
              or by an individual or Legal Entity authorized to submit on behalf of
              the copyright owner. For the purposes of this definition, "submitted"
              means any form of electronic, verbal, or written communication sent
              to the Licensor or its representatives, including but not limited to
              communication on electronic mailing lists, source code control systems,
              and issue tracking systems that are managed by, or on behalf of, the
              Licensor for the purpose of discussing and improving the Work, but
              excluding communication that is conspicuously marked or otherwise
              designated in writing by the copyright owner as "Not a Contribution."
        
              "Contributor" shall mean Licensor and any individual or Legal Entity
              on behalf of whom a Contribution has been received by Licensor and
              subsequently incorporated within the Work.
        
           2. Grant of Copyright License. Subject to the terms and conditions of
              this License, each Contributor hereby grants to You a perpetual,
              worldwide, non-exclusive, no-charge, royalty-free, irrevocable
              copyright license to reproduce, prepare Derivative Works of,
              publicly display, publicly perform, sublicense, and distribute the
              Work and such Derivative Works in Source or Object form.
        
           3. Grant of Patent License. Subject to the terms and conditions of
              this License, each Contributor hereby grants to You a perpetual,
              worldwide, non-exclusive, no-charge, royalty-free, irrevocable
              (except as stated in this section) patent license to make, have made,
              use, offer to sell, sell, import, and otherwise transfer the Work,
              where such license applies only to those patent claims licensable
              by such Contributor that are necessarily infringed by their
              Contribution(s) alone or by combination of their Contribution(s)
              with the Work to which such Contribution(s) was submitted. If You
              institute patent litigation against any entity (including a
              cross-claim or counterclaim in a lawsuit) alleging that the Work
              or a Contribution incorporated within the Work constitutes direct
              or contributory patent infringement, then any patent licenses
              granted to You under this License for that Work shall terminate
              as of the date such litigation is filed.
        
           4. Redistribution. You may reproduce and distribute copies of the
              Work or Derivative Works thereof in any medium, with or without
              modifications, and in Source or Object form, provided that You
              meet the following conditions:
        
              (a) You must give any other recipients of the Work or
                  Derivative Works a copy of this License; and
        
              (b) You must cause any modified files to carry prominent notices
                  stating that You changed the files; and
        
              (c) You must retain, in the Source form of any Derivative Works
                  that You distribute, all copyright, patent, trademark, and
                  attribution notices from the Source form of the Work,
                  excluding those notices that do not pertain to any part of
                  the Derivative Works; and
        
              (d) If the Work includes a "NOTICE" text file as part of its
                  distribution, then any Derivative Works that You distribute must
                  include a readable copy of the attribution notices contained
                  within such NOTICE file, excluding those notices that do not
                  pertain to any part of the Derivative Works, in at least one
                  of the following places: within a NOTICE text file distributed
                  as part of the Derivative Works; within the Source form or
                  documentation, if provided along with the Derivative Works; or,
                  within a display generated by the Derivative Works, if and
                  wherever such third-party notices normally appear. The contents
                  of the NOTICE file are for informational purposes only and
                  do not modify the License. You may add Your own attribution
                  notices within Derivative Works that You distribute, alongside
                  or as an addendum to the NOTICE text from the Work, provided
                  that such additional attribution notices cannot be construed
                  as modifying the License.
        
              You may add Your own copyright statement to Your modifications and
              may provide additional or different license terms and conditions
              for use, reproduction, or distribution of Your modifications, or
              for any such Derivative Works as a whole, provided Your use,
              reproduction, and distribution of the Work otherwise complies with
              the conditions stated in this License.
        
           5. Submission of Contributions. Unless You explicitly state otherwise,
              any Contribution intentionally submitted for inclusion in the Work
              by You to the Licensor shall be under the terms and conditions of
              this License, without any additional terms or conditions.
              Notwithstanding the above, nothing herein shall supersede or modify
              the terms of any separate license agreement you may have executed
              with Licensor regarding such Contributions.
        
           6. Trademarks. This License does not grant permission to use the trade
              names, trademarks, service marks, or product names of the Licensor,
              except as required for reasonable and customary use in describing the
              origin of the Work and reproducing the content of the NOTICE file.
        
           7. Disclaimer of Warranty. Unless required by applicable law or
              agreed to in writing, Licensor provides the Work (and each
              Contributor provides its Contributions) on an "AS IS" BASIS,
              WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or
              implied, including, without limitation, any warranties or conditions
              of TITLE, NON-INFRINGEMENT, MERCHANTABILITY, or FITNESS FOR A
              PARTICULAR PURPOSE. You are solely responsible for determining the
              appropriateness of using or redistributing the Work and assume any
              risks associated with Your exercise of permissions under this License.
        
           8. Limitation of Liability. In no event and under no legal theory,
              whether in tort (including negligence), contract, or otherwise,
              unless required by applicable law (such as deliberate and grossly
              negligent acts) or agreed to in writing, shall any Contributor be
              liable to You for damages, including any direct, indirect, special,
              incidental, or consequential damages of any character arising as a
              result of this License or out of the use or inability to use the
              Work (including but not limited to damages for loss of goodwill,
              work stoppage, computer failure or malfunction, or any and all
              other commercial damages or losses), even if such Contributor
              has been advised of the possibility of such damages.
        
           9. Accepting Warranty or Additional Liability. While redistributing
              the Work or Derivative Works thereof, You may choose to offer,
              and charge a fee for, acceptance of support, warranty, indemnity,
              or other liability obligations and/or rights consistent with this
              License. However, in accepting such obligations, You may act only
              on Your own behalf and on Your sole responsibility, not on behalf
              of any other Contributor, and only if You agree to indemnify,
              defend, and hold each Contributor harmless for any liability
              incurred by, or claims asserted against, such Contributor by reason
              of your accepting any such warranty or additional liability.
        
           END OF TERMS AND CONDITIONS
        
           APPENDIX: How to apply the Apache License to your work.
        
              To apply the Apache License to your work, attach the following
              boilerplate notice, with the fields enclosed by brackets "[]"
              replaced with your own identifying information. (Don't include
              the brackets!)  The text should be enclosed in the appropriate
              comment syntax for the file format. We also recommend that a
              file or class name and description of purpose be included on the
              same "printed page" as the copyright notice for easier
              identification within third-party archives.
        
           Copyright [yyyy] [name of copyright owner]
        
           Licensed under the Apache License, Version 2.0 (the "License");
           you may not use this file except in compliance with the License.
           You may obtain a copy of the License at
        
               http://www.apache.org/licenses/LICENSE-2.0
        
           Unless required by applicable law or agreed to in writing, software
           distributed under the License is distributed on an "AS IS" BASIS,
           WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
           See the License for the specific language governing permissions and
           limitations under the License.
License-File: LICENSE
License-File: NOTICE
Keywords: agentic-security,ai-security,llm-security,mcp,mitre-atlas,nist-ai-rmf,owasp,red-team,test-generation
Classifier: Development Status :: 4 - Beta
Classifier: Intended Audience :: Developers
Classifier: Intended Audience :: Information Technology
Classifier: License :: OSI Approved :: Apache Software License
Classifier: Operating System :: OS Independent
Classifier: Programming Language :: Python :: 3
Classifier: Programming Language :: Python :: 3.11
Classifier: Programming Language :: Python :: 3.12
Classifier: Programming Language :: Python :: 3.13
Classifier: Topic :: Security
Classifier: Topic :: Software Development :: Testing
Classifier: Typing :: Typed
Requires-Python: <3.14,>=3.11
Requires-Dist: aiohttp>=3.14.0
Requires-Dist: httpx>=0.27
Requires-Dist: json-repair>=0.30
Requires-Dist: jsonschema>=4.22
Requires-Dist: litellm>=1.83.10
Requires-Dist: mcp<2.0,>=1.0
Requires-Dist: pydantic-settings>=2.3
Requires-Dist: pydantic>=2.7
Requires-Dist: pytest>=8.2
Requires-Dist: python-dotenv>=1.2.2
Requires-Dist: pyyaml>=6.0
Requires-Dist: rich>=13.7
Requires-Dist: truststore>=0.9
Requires-Dist: typer>=0.12
Provides-Extra: demo
Requires-Dist: mcp-kitchen-sink==0.2.0; extra == 'demo'
Provides-Extra: dev
Requires-Dist: mypy>=1.10; extra == 'dev'
Requires-Dist: pre-commit>=3.7; extra == 'dev'
Requires-Dist: pytest-asyncio>=0.23; extra == 'dev'
Requires-Dist: pytest-cov>=5.0; extra == 'dev'
Requires-Dist: ruff==0.16.7; extra == 'dev'
Requires-Dist: types-jsonschema>=4.22; extra == 'dev'
Requires-Dist: types-pyyaml>=6.0; extra == 'dev'
Provides-Extra: docs
Requires-Dist: mkdocs-material>=9.5; extra == 'docs'
Requires-Dist: mkdocs>=1.6; extra == 'docs'
Provides-Extra: enterprise
Requires-Dist: truststore>=0.9; extra == 'enterprise'
Description-Content-Type: text/markdown

# Mylonite

> **A safe model is not the same thing as a safe app.** A top-tier model can shrug off
> every generic prompt-injection you throw at it and still hand an attacker a win — because
> the weakness is in how your app is *wired*, not in how the model behaves. Mylonite checks
> whether your app's own safeguards are what stop an attack, writes a test for every
> weakness it finds, and wires that test into CI so a future model upgrade cannot quietly
> remove the protection.

[![CI](https://github.com/Abidemialade/mylonite/actions/workflows/ci.yml/badge.svg)](https://github.com/Abidemialade/mylonite/actions/workflows/ci.yml)
[![PyPI](https://img.shields.io/pypi/v/mylonite.svg)](https://pypi.org/project/mylonite/)
[![GitHub release](https://img.shields.io/github/v/release/Abidemialade/mylonite)](https://github.com/Abidemialade/mylonite/releases/latest)
[![License](https://img.shields.io/badge/license-Apache--2.0-blue.svg)](./LICENSE)

**For teams shipping MCP or agentic apps who want CI-enforced regression coverage on the AI
layer.**

Point Mylonite at any MCP (Model Context Protocol) app, whatever model or framework sits
behind it. It attacks the part an ordinary code scanner cannot see — the system prompt and
the tool descriptions your agent reads — finds weaknesses specific to your app, and turns
each one into a **`pytest` test that gates your CI**.

Mylonite deliberately does *not* review your ordinary application code. That is what
SAST/DAST tools are for.

## How it works

The idea is simple: **run the same attack twice.**

1. Once against your app as it is.
2. Once with the safeguard in place.

A weakness is only reported if the attack **succeeds** the first time and is **stopped** the
second — repeated several times over, so that a model having a good or bad day cannot
decide the outcome. (In the codebase and the docs this is the *differential*, or
control-efficacy check.)

That answers a question a one-off scan cannot: **is your safeguard doing the work, or is
the model's current good behaviour doing it?** Only one of those survives a model upgrade.

### Two levels of proof

Mylonite always tells you which one you got.

| What plays the "safeguard" role | What a kept finding tells you | How to get it |
|---|---|---|
| **Your own safeguard**, switched off and on | Your implementation is doing the work. The stronger result. | Declare `control_env` in your `target.yaml` |
| **A standard safeguard** Mylonite applies at the boundary | The attack is real, and this kind of safeguard closes it — but what stopped it was Mylonite's stand-in, not your code | The default; works on any app, no setup |

The second is genuinely useful, and it is what runs against most real apps. It is a weaker
statement than the first, and no Mylonite output will dress it up as the stronger one.

## How it has been tested

Mylonite ships an [independent verification harness](./docs/verification.md) that scores it
against material it did not write — runnable third-party MCP servers and published academic
benchmarks. The harness is in this repository and you can run it yourself.

### Results against third-party targets

- **A kept finding on a third-party MCP email server.** The attack succeeded **5 times out
  of 5** against the server as shipped, and **0 times out of 5** with the safeguard in
  place. Scope of that run: the server needed two fixes before it would start at all (a
  launch wrapper, and a one-line bug in its own `send_email`), the weakness only appears
  when the app's system prompt tells the agent to send without asking, and the safeguard
  was Mylonite's boundary stand-in rather than a second build of the server. Full detail in
  [the capability matrix](./verification/CAPABILITY_MATRIX.md).
- **No false alarms** on a third-party server with nothing wrong with it (Enkrypt's
  `echo_mcp`). Running the same comparison against a *hardened* third-party server is still
  outstanding — see
  [verification](./docs/verification.md#layer-3--precision-false-positives-on-known-good-targets).
- **A real weakness found in a published vulnerable-MCP corpus** (MCPSecBench). When that
  finding was re-run to confirm it, it failed to reproduce (0 of 3 runs), so Mylonite
  discarded it instead of shipping a flaky test.
- **The judge checked against real third-party examples** — AgentDojo transcripts from
  models that genuinely fell for attacks, not examples we wrote ourselves.
- **The safety rails hold under test.** A check that could not be run is never reported as
  a pass; a score with nothing to measure is labelled as such; work outside the tool's
  scope is marked rather than graded.

### Results that came back negative

Published for the same reason the positive ones are.

- **0 out of 8 found** on one external challenge set (DVMCP, using Claude Haiku 4.5).
- **On InjecAgent** (100 cases per split, using a local `llama3.2:3b`) the judge scored
  **F1 1.000** on the direct-harm split and **F1 0.400 at 0.25 recall** on the
  data-stealing split. The gap between those two is the finding, so both are published.
- **Judge agreement of F1 0.41** against AgentDojo's own labels. Mylonite's judge asks "did
  harm actually happen?"; AgentDojo asks "was the exact goal achieved?". Some of that gap
  is a genuine difference in question, which we have not resolved.
- **No model-fooling weakness found in an external app.** A robust model resisted every
  generic injection. The one thing that landed was a flaw in how the app was built.

### Current limits

- **Against a single-build app, only the weaker statement is available.** With no
  `control_env` to switch, the safeguard is Mylonite's stand-in rather than your code, and
  no output will claim otherwise.
- **Finding nothing is the normal outcome** for a well-built app on a robust model. See
  [below](#finding-nothing-is-also-a-result).
- **The evidence rests largely on one model** — Claude Haiku 4.5 — at small, deliberately
  cost-capped sample sizes.
- **The published figures were measured between 25 June and 29 August 2026.** The
  benchmark results carry the version they were measured against
  (`verification/results/0.9.0/`); the run logs in the capability matrix do not. Figures
  have not been re-measured for every release since, so read them as a floor rather than a
  current reading. Per-release re-measurement is planned.
- **Run transcripts are not published.** The harness and its scorers are, so you can
  produce your own numbers; you cannot yet audit ours.
- **No third party has built a plugin** against the extension points yet.

Full scorecard with caveats: [docs/verification.md](./docs/verification.md). Everything that
limits the tool's reach is collected in [docs/limitations.md](./docs/limitations.md).

## Finding nothing is also a result

Worth knowing before you run it. Against a well-built app on a robust model, Mylonite will
often correctly find **nothing** — that is the tool working, not failing. Proving a
safeguard carries the security requires a weakness that actually lands, which in practice
means a design flaw (an action with real consequences and no approval step, an unrestricted
outbound request) or an app configured to act on its own.

That is why [Try it](#try-it) starts with the bundled practice app rather than your code.
That app is deliberately insecure, so it finds something every time and you can watch the
machinery work before pointing it somewhere the honest answer may be "nothing".

## Where this sits

Static scanners read your tool descriptions and flag whatever looks risky, leaving you to
judge which flags matter. Model-eval harnesses swap models and score which behaves best.
Mylonite includes a quick structural check of that first kind (`mylonite check`), but its
purpose is the step neither of those takes: run the attack against your app, then hold the
model constant and switch only your safeguard. The result is evidence about **your
safeguard**, not about how a description reads or how a model scored today.

## Project status

**Beta, and essentially a single maintainer** — one outside contribution to date, the rest
of the history from the maintainer and Dependabot. Over 2,300 tests, with CI (ruff, mypy,
pytest, pre-commit) enforced on every pull request. The extension points are versioned
public API, but nobody outside the project has built against them yet. If you are weighing
this as a dependency in a security pipeline, pin a version — and read
[Known limitations](./docs/limitations.md) first.

## Install

```bash
pip install mylonite                      # the CLI, from PyPI
pip install "mylonite[demo]"              # ...plus the bundled practice app
```

Python 3.11–3.13. (3.14 is not supported yet: `litellm` caps itself below it.)

The `[demo]` extra installs the bundled practice app, and you need it for **any**
`reference:...` command — `demo`, `check reference:...` and `scan reference:...` alike.

Scanning your own app needs a model: an API key for a hosted provider, or no key at all for
one you host yourself (Ollama, vLLM, or a LiteLLM proxy — see
[self-hosted models](./docs/self-hosted-models.md)). `check`, `scan --scaffold` and `report`
never need a model at all, and `demo` replays recorded responses rather than calling one.

## Try it

**No API key, one command:**

```bash
mylonite demo
```

That runs the comparison against the bundled practice app — deliberately insecure, runs
in-process, opens no network ports — and prints what got through on the unguarded build
next to what was stopped on the guarded one. Same attacks, two builds, different outcomes.
**That contrast is the point of the tool.**

`demo` replays model responses recorded against those bundled apps, so it is offline and
gives the same answer every time. The scan, the adapters, the checks and the comparison are
all the real ones; only the model's replies are pre-recorded, and the output tells you which
model produced them and when. Treat the numbers as a demonstration of the machinery rather
than a fresh measurement of today's model — `mylonite demo --live` is the fresh measurement,
and it does call a model (by default one you host locally). Where a cell could not be
decided either way the table says so rather than showing it as a pass, and if a recording is
ever missing or out of date the command fails and explains why instead of reporting a clean
result it did not earn.

The next step also needs no key, and works against your own server too:

```bash
mylonite check reference:vulnerable   # structural report, no model call
```

Then, with a model configured, the real thing:

```bash
mylonite scan reference:vulnerable   # finds the weaknesses built into it
mylonite scan reference:guarded      # same attacks, comes up clean
```

See [the practice app](./docs/quarry.md) for what is built into it and why.

### Then point it at your own app

**The first two steps are free** — no API key, no model call, no spend.

```bash
# 1. Inspect a server and write a starter target.yaml
mylonite scan --command "python" --arg "my_server.py" --scaffold app.yaml --scope my-app

# 2. Structural pre-check of that tool surface
mylonite check --target-file app.yaml
```

`--scaffold` connects to your server, lists its tools, says which weakness classes apply to
it, and flags the tools whose actions have real consequences. It works from the names,
descriptions and schemas your server advertises, matching them against keyword patterns, so
treat everything it suggests as a hint to confirm rather than a verdict.

`check` reports structural exposure: consequential tools with no approval step, descriptions
that steer the agent, tools that take a network destination, content-processing tools that
could be injection routes, and descriptions that are not pinned. `--enforce` turns it into a
CI gate — it fails on the substantive findings and treats "unpinned descriptions" (which
fires on every tool of every server the first time) as advice rather than a gate, so you can
adopt it on day one.

Proving which weaknesses actually *land*, and which of your safeguards stops them, is the
scan itself. That needs a model:

```bash
mylonite scan --target-file app.yaml --authorize my-app
```

Expect this to find less than the practice app did — often nothing. See
[Finding nothing is also a result](#finding-nothing-is-also-a-result) above, and
[docs/limitations.md](./docs/limitations.md) for where the tool's reach genuinely ends.

## From a scan to a pull request that gates CI

`mylonite gate` runs the whole sequence — find a weakness, write a test for it, confirm the
test is meaningful, and optionally open a pull request that makes CI depend on it:

```bash
mylonite gate reference:vulnerable                                   # find -> test -> confirm
mylonite gate --target-file app.yaml --authorize my-app --open-pr    # ...and open the PR
```

**`gate` does not touch your repository unless you ask it to.** By default it writes its
files under `.mylonite/gate/` — the test, the weakness record, the confirmation report — and
prints the exact `git` and `gh` commands so you can commit and open the PR yourself. Add
`--open-pr` to have it create the branch, commit and open the PR; add `--workflows` to also
write two CI templates (a cheap per-PR gate and a nightly discovery run).

The pull request carries the finding, its OWASP/ASI/ATLAS/NIST tags, the supporting
evidence, and a recommended fix that names the actual tool and argument the attack used.
Full guide: [docs/ci-gating.md](./docs/ci-gating.md). Behind a corporate network, see
[docs/enterprise-networking.md](./docs/enterprise-networking.md).

## Commands

| Command | What it does | Needs a model? |
|---|---|---|
| `mylonite demo` | Replays the unguarded-vs-guarded comparison on the bundled practice app, offline. | No (`--live` does) |
| `mylonite check` | Structural pre-check of a tool surface. Takes `reference:vulnerable` or `--target-file`. `--enforce` makes it a CI gate. | No |
| `mylonite scan` | The weakness-finding loop. `--scaffold` inspects a server and writes a starter `target.yaml`. | Yes (except `--scaffold`) |
| `mylonite generate` | Writes the `pytest` test from a confirmed weakness. | No |
| `mylonite validate` | Confirms a test is meaningful by running the comparison. `--fast` makes it cheaper. | Yes |
| `mylonite gate` | End to end: scan → generate → validate → optionally open a gating PR. | Yes |
| `mylonite ablate` | Scores each safeguard as load-bearing, redundant, security theatre, untested, or inconclusive. Needs a target file. | Yes |
| `mylonite report` | Terminal summary, **SARIF 2.1.0**, or a JSON bundle — each carrying the supporting evidence and compliance tags. | No |
| `mylonite plugins` | Lists installed plugins across all five extension points. | No |
| `mylonite version` | Prints the installed version. | No |

`--fast` trades thoroughness for cost, and what it skips depends on the target: against
your own app it skips the safeguard comparison itself, leaving a weaker check; against the
bundled practice app the comparison is not optional, so it reduces the robustness checks
instead.

Exit codes are a documented contract (`0` success · `1` findings · `2` configuration ·
`3` budget · `4` provider · `5` not confirmed · `6` generate failed · `7` validate failed ·
`8` PR step failed). Full details in the [CLI reference](./docs/cli-reference.md).

Remote MCP transport (SSE / streamable-HTTP), the versioned extension points, and
entry-point plugins are covered in the [architecture guide](./docs/architecture.md).

## Compliance metadata

Every test and every finding carries tags from four frameworks: **OWASP LLM Top 10 2025**,
**OWASP ASI 2026**, **MITRE ATLAS**, and **NIST AI RMF**. They ride into the pytest markers,
the SARIF output and the JSON bundle, so a finding traces back to the control catalogue your
auditors already use. See [docs/standards-mapping.md](./docs/standards-mapping.md).

## Documentation

**Full docs site:** [abidemialade.github.io/mylonite](https://abidemialade.github.io/mylonite/)
(or `mkdocs serve` from a checkout). Highlights:

- [Quickstart](./docs/quickstart.md) · [Test your own app](./docs/test-your-app.md) — install and point it at your MCP server.
- [Weakness classes](./docs/weakness-classes.md) · [Attack modes](./docs/attack-modes.md) — what is tested, and how the attacks work.
- [The validation engine](./docs/validation.md) — how the safeguard comparison works.
- [Independent verification](./docs/verification.md) — the full scorecard against material Mylonite did not write.
- [Known limitations](./docs/limitations.md) — where the tool's reach ends, in one place.
- [Reading the results](./docs/reading-results.md) · [CLI reference](./docs/cli-reference.md) · [target.yaml](./docs/target-file.md).
- [CI gating](./docs/ci-gating.md) · [Re-validate on a new model](./docs/model-upgrade.md) — keep the gate proving your safeguard as models change.
- [Architecture](./docs/architecture.md) · [Plugin authoring](./docs/plugin-authoring.md) · [Threat model](./docs/threat-model.md).
- [ROADMAP.md](./ROADMAP.md) · [CONTRIBUTING.md](./CONTRIBUTING.md) · [GOVERNANCE.md](./GOVERNANCE.md) · [SECURITY.md](./SECURITY.md).

## Responsible use

Mylonite reproduces working attacks against AI agents. **Use it only against targets you
control or are contractually authorised to test.** Every command that drives a real target —
`scan`, `gate`, `validate` and `ablate` — refuses to run without an explicit `--authorize`
flag naming that target: the value must match the target's declared `scope`, or its family
name where no scope is declared. The bundled insecure practice app runs in-process and opens
no network ports.

Full policy: [SECURITY.md](./SECURITY.md).

## Contributing

Bug reports, adapter requests and attack-pattern submissions are welcome — see
[CONTRIBUTING.md](./CONTRIBUTING.md) for development setup, how to write a plugin, and the
pull-request conventions. The five extension points (attack modules, test generators,
validators, target adapters, compliance mappers) are versioned public API with reference
implementations in this repository.

## License

Apache License 2.0. See [LICENSE](./LICENSE) and [NOTICE](./NOTICE).
