Skip to main content
Glama

"Stop trying to build a model that cannot be fooled. Build the system around it, so that when the model is fooled — and it will be — nothing important breaks."

Grey Panda makes the secure path the easy path for anyone building LLM-powered, agentic, or Model Context Protocol (MCP) features — from a solo indie developer to an enterprise AppSec team.

⚡ Quick start

pip install grey-panda        # pure Python, zero dependencies
gp scan .                     # scan your repo — real findings, beautiful report

Add drop-in guardrails to an existing LLM call in under two minutes — you never rewrite the call, you wrap it:

from greypanda import PromptGuardrail, DLPScanner, OutputGuardrail

guard, dlp, out = PromptGuardrail(), DLPScanner(), OutputGuardrail()

safe   = guard.assert_safe(user_input)        # block known injection + strip invisible Unicode
clean  = dlp.redact(safe)                       # remove PII & secrets before the model sees them
reply  = call_your_llm(clean)                   # ← your existing call, unchanged
answer = out.sanitize(reply).sanitized_text     # neutralise XSS constructs + exfil URLs (escape_html=True to fully escape)

Related MCP server: VSGuard MCP

🎯 Why this exists

Prompt injection is the #1 AI attack pattern and it needs no authentication (OWASP LLM01). Agentic systems can take an irreversible action from a single injected instruction. And MCP has opened a whole new surface — tool poisoning and rug pulls. Your existing AppSec tools don't see any of it.

🐼 The idea: one calm guardian

Grey Panda keeps two rare qualities as non-negotiable: intellectual honesty (a whole doc on what it can and cannot do) and standards-anchoring (every rule cites an OWASP ID). No neon-hacker theatre — just controls that are a joy to adopt.

📦 What's in the bundle

Five audience-facing module kits, all powered by one shared, zero-dependency engine:

Kit

For

Start here

🧰 Module 1 — Developer Kit

Building AI features

Drop-in SDK + IDE integration

🛡️ Module 2 — Security Reviewer Kit

Reviewing / gating

AISVS verify, threat models, sign-off

🔍 Module 3 — Scanner & CI/CD Kit

Platform / DevOps

26 rules, SARIF, GitHub Action

🤖 Module 4 — MCP & Agent Security Kit

Agents & MCP

Rule of Two, HITL, manifest pinning, ACS

📚 Module 5 — Standards & Governance Kit

Everyone / compliance

Knowledge pack, mappings, Can/Cannot-Do

⚙️ How it works

Defense in depth, not prevention theatre. Full walkthrough: HOW-TO-add-guardrails · architecture: docs/ARCHITECTURE.md.

🔐 Standards-anchored

Every rule, checklist item, and SDK control cites a specific ID. Explore any control from the CLI:

gp standards LLM01:2026      # explain a control + its Grey Panda fix
gp standards                 # list every standard and control ID

Full mapping tables: Module 5 → mappings/.

✅ Proof

See the before/after for yourself — the same app, insecure vs. rebuilt with Grey Panda controls:

gp scan examples/vulnerable_app --profile enterprise    # 🔴 findings
gp scan examples/secure_app     --profile enterprise    # ✅ clean

👥 For everyone

gp scan . --profile solo          # high-signal core, fail on CRITICAL
gp init  . --profile team         # scaffold config + GitHub Action + pre-commit
gp verify . --level 2             # AISVS Level 2 verification report

More: Module 1 → PROFILES.

🚀 Get started

pip install grey-panda           # from PyPI
pipx install grey-panda          # isolated CLI
uvx grey-panda scan .            # zero-install run

Command

Does

gp scan [path]

Scan for AI/agent/MCP issues (--profile, --format md/json/sarif, --fail-on)

gp init [path]

Scaffold config, GitHub Action, and pre-commit into a repo

gp verify [path]

AISVS Level 1/2/3 verification report

gp checklist

Print the AI security checklist

gp standards [id]

List or explain standards / control IDs

gp agbom <agent>

Emit an Agent Bill of Materials

gp mcp

Run Grey Panda as an MCP server (stdio)

gp doctor

Environment self-check + honest-limits pointer

🤝 In your IDE

Grey Panda secures MCP — and ships as an MCP server, so Claude Code, Cursor, Windsurf, or VS Code can call it while you code:

{ "mcpServers": { "grey-panda": { "command": "gp", "args": ["mcp"] } } }

Then ask your assistant to "review this file with grey panda" or "explain LLM03". Details: Module 1 → HOW-TO-use-in-your-ide and Module 4 → HOW-TO-run-the-mcp-server.

🧭 Honest about limits

Grey Panda is a strong floor, not a ceiling. Pattern matching cannot stop all prompt injection; regex DLP is language-specific; static analysis has false positives and negatives. We ship a whole document — with a confidence level and failure condition for every capability: WHAT_IT_CAN_AND_CANNOT_DO.md. Read it before you rely on the tool.

🌱 Contributing

Adding a scanner rule is editing one dataclass with a bad + good example — see CONTRIBUTING.md and Module 3 → HOW-TO-write-a-rule. Everyone is welcome under our Code of Conduct. Found a vulnerability in Grey Panda itself? See SECURITY.md.

Build from source:

git clone https://github.com/dibakshya01/grey-panda && cd grey-panda
pip install -e ".[dev]"
python -m unittest discover -s tests        # zero-dependency test suite
gp scan . --profile enterprise --fail-on HIGH   # Grey Panda scans itself, clean

📄 License

Apache-2.0. Standards cited are the property of their respective authors (see NOTICE). OWASP® is a registered trademark of the OWASP Foundation; Grey Panda is an independent, community project and is not affiliated with or endorsed by OWASP.

Related MCP Connectors

Related MCP Servers

  • A
    license
    B
    quality
    D
    maintenance
    Allows developers to query security findings (SAST issues, secrets, patches) using natural language within AI-assisted tools like Claude Desktop, Cursor, and other MCP-compatible environments.
    17
    9
    MIT
  • A
    license
    Not graded
    quality
    D
    maintenance
    Provides real-time OWASP ASVS security guidance and vulnerability scanning for AI coding agents. Enables proactive security during code generation by checking security requirements, scanning code for vulnerabilities, and suggesting secure code fixes.
    3
    MIT
  • A
    license
    Not graded
    quality
    B
    maintenance
    Provides AI coding assistants with real-time security scanning superpowers, including SAST, secrets detection, dependency CVE scanning, and web vulnerability assessment.
    19 npm
    Apache 2.0