AI agents have unrestricted access to your filesystem. One prompt injection and your .env, SSH keys, and customer PII are gone. SecurityAgent stops that.
Detects SSN, credit cards, IBAN, passports, DEA numbers, and credentials in plaintext and binary files (PDF, XLSX, DOCX, CSV). Chunked scanning up to 500 MB.
3-layer analysis: regex fast-path, Pydantic rules with negation awareness, and optional local Ollama LLM. Early-return skips deeper layers when results are clear.
Catches 11 multi-step attack patterns by correlating action sequences — credential exfil, split-ticket attacks, supply chain injection, container escape.
Intercepts all shell commands. Blocks dotfile reads, env dumps, exfiltration pipes, cloud CLI uploads, encoded exfil, and suspicious package installs.
Per-session least privilege. Restrict skills, paths, command patterns, rate limits, and TTL for each agent session independently.
Every action logged with session ID, agent ID, trace ID, and reason. AES-256-GCM encryption at rest. Feed into your SIEM.
git clone https://github.com/secure-mind-live/SecurityPlugin_packages.git cd SecurityPlugin_packages pip install securityagent-core ./setup-claude-code.sh
git clone https://github.com/secure-mind-live/SecurityPlugin_packages.git cd SecurityPlugin_packages chmod +x install.sh && ./install.sh