
opensource repo for validating agentic AI applications: redteam, behavior, supply-chain, static analysis
NuGuard is an open source AI application security toolkit. Its goal is to provide the most extensive redteaming and behavioral validation of Agentic AI applications.
With NuGuard, AI developers can focus on building their applications while NuGuard continuously tests and validates them against a wide range of security risks, including supply chain attacks, prompt injection, MCP tool misuse, API Attacks, data exfiltration, and more. NuGuard allows the developers to accelerate their security workflows and get to production faster with confidence.
A commercial version of NuGuard is available as a SaaS product with additional features and support, check it at http://nuguard.ai.
Implemented and usable today:
nuguard sbomnuguard analyzenuguard scannuguard policynuguard behaviornuguard redteamuv for the recommended local workflowPython CLI:
pip install nuguard
The steps below describe how to set up a local development environment. This is recommended if you want to run the latest code, contribute to the project, or run the CLI with LLM-assisted features that require local environment variable configuration.
uv sync --dev
Run the CLI with:
uv run nuguard --help
Or, from the virtual environment:
. .venv/bin/activate
nuguard --help
Follow the instructions in docs/plugin-guide.md to set up the NuGuard plugin for Claude and use it to run commands like /nuguard-sbom, /nuguard-analyze, and /nuguard-redteam directly from your conversations with Claude.
nuguard sbom generate --source . --output app.sbom.json
You can also scan a remote repository:
nuguard sbom generate \
--from-repo https://github.com/org/repo \
--ref main \
--output app.sbom.json
nuguard analyze --sbom app.sbom.json --format markdown
Typical outputs:
markdown for human reviewjson for automationsarif for code scanning pipelinesnuguard behavior \
--sbom app.sbom.json \
--target http://localhost:3000 \
--format markdown
nuguard redteam \
--config nuguard.yaml \
--output reports/redteam.md \
--format markdown
For richer red-team coverage, you can also provide:
--policy--canary--confignuguard scan \
--source . \
--output-dir nuguard-reports
By default this runs SBOM generation plus static analysis in one pass. To include policy and red-team validations, opt in to those steps and provide the required inputs:
nuguard scan \
--source . \
--steps sbom,analyze,policy,redteam \
--policy cognitive_policy.md \
--target http://localhost:3000 \
--output-dir nuguard-reports
NuGuard supports project configuration through nuguard.yaml. A ready-to-edit example lives at nuguard.yaml.example.
Key areas in the example config:
sbom: existing SBOM pathsource: source directory for generationpolicy: cognitive policy pathllm: model settings for LLM-assisted featuresbehavior: target URL, endpoint, and test profile settings for behavioral testingredteam: target URL, endpoint, canary file, profiles, scenario filters, guided conversation settings, and finding trigger controls (finding_triggers.*)analyze: minimum severity thresholddatabase: SQLite or Postgres-backed storage settingsoutput: output format and failure thresholdCLI flags take precedence over nuguard.yaml, which takes precedence over environment variables and built-in defaults.
NuGuard can watch for seeded canary values during dynamic testing to produce high-confidence exfiltration findings. Start from canary.example.json, create your local canary.json, seed those values into the target system, then point nuguard redteam at that file with --canary.
More detail is available in docs/redteam-engine.md.
Install dev dependencies:
make dev
Run tests:
make test
Run linting and type checks:
make lint
Format the codebase:
make fmt
This repo includes GitHub Actions workflows for Trusted Publishing to TestPyPI and PyPI:
Before the workflows can publish, configure Trusted Publishers in TestPyPI and PyPI for the nuguard project with:
NuGuardAInuguardpublish-testpypi.yml or publish-pypi.ymltestpypi or pypiRecommended release flow:
Before publishing to TestPyPI or PyPI, run the quick multi-app sanity gate.
One-shot runner:
bash tests/apps/prepublish-sanity.sh
This runner performs:
nuguard --help plus critical local tests)intent_happy_path workflowprofile: ciPrepublish config files used by the runner:
tests/apps/openai-cs-agents-demo/nuguard.prepublish.yamltests/apps/Gemini-Auto-app/nuguard.prepublish.yamltests/apps/pinnacle-bank-app/nuguard-azure.prepublish.yamlRun manually per app (if needed):
# OpenAI CS agents demo
uv run nuguard sbom generate --config tests/apps/openai-cs-agents-demo/nuguard.prepublish.yaml --format json -o tests/apps/openai-cs-agents-demo/openai-cs.sbom.json
uv run nuguard behavior --config tests/apps/openai-cs-agents-demo/nuguard.prepublish.yaml --mode dynamic --format json --format markdown --output tests/apps/openai-cs-agents-demo/reports/openai-cs-prepublish-behavior --verbose
uv run nuguard redteam --config tests/apps/openai-cs-agents-demo/nuguard.prepublish.yaml --format json --format markdown --output tests/apps/openai-cs-agents-demo/reports/openai-cs-prepublish-redteam --verbose
# Gemini Auto app
uv run nuguard sbom generate --config tests/apps/Gemini-Auto-app/nuguard.prepublish.yaml --format json -o tests/apps/Gemini-Auto-app/gemini-auto.sbom.json
uv run nuguard behavior --config tests/apps/Gemini-Auto-app/nuguard.prepublish.yaml --mode dynamic --format json --format markdown --output tests/apps/Gemini-Auto-app/reports/gemini-auto-prepublish-behavior --verbose
uv run nuguard redteam --config tests/apps/Gemini-Auto-app/nuguard.prepublish.yaml --format json --format markdown --output tests/apps/Gemini-Auto-app/reports/gemini-auto-prepublish-redteam --verbose
# Pinnacle Bank app
uv run nuguard sbom generate --config tests/apps/pinnacle-bank-app/nuguard-azure.prepublish.yaml --format json -o tests/apps/pinnacle-bank-app/pinnacle-bank.sbom.json
uv run nuguard behavior --config tests/apps/pinnacle-bank-app/nuguard-azure.prepublish.yaml --mode dynamic --format json --format markdown --output tests/apps/pinnacle-bank-app/reports/pinnacle-bank-prepublish-behavior --verbose
uv run nuguard redteam --config tests/apps/pinnacle-bank-app/nuguard-azure.prepublish.yaml --format json --format markdown --output tests/apps/pinnacle-bank-app/reports/pinnacle-bank-prepublish-redteam --verbose
Important:
|| true in publish-gating runs.2 can indicate findings or policy gates; treat it as a signal and rely on report-quality checks to decide pass/fail.tests/output/License information is available in the LICENSE file.