Grey Panda
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@Grey Pandascan this repo for AI and MCP security issues"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
"Stop trying to build a model that cannot be fooled. Build the system around it, so that when the model is fooled — and it will be — nothing important breaks."
Grey Panda makes the secure path the easy path for anyone building LLM-powered, agentic, or Model Context Protocol (MCP) features — from a solo indie developer to an enterprise AppSec team.
⚡ Quick start
pip install grey-panda # pure Python, zero dependencies
gp scan . # scan your repo — real findings, beautiful reportAdd drop-in guardrails to an existing LLM call in under two minutes — you never rewrite the call, you wrap it:
from greypanda import PromptGuardrail, DLPScanner, OutputGuardrail
guard, dlp, out = PromptGuardrail(), DLPScanner(), OutputGuardrail()
safe = guard.assert_safe(user_input) # block known injection + strip invisible Unicode
clean = dlp.redact(safe) # remove PII & secrets before the model sees them
reply = call_your_llm(clean) # ← your existing call, unchanged
answer = out.sanitize(reply).sanitized_text # neutralise XSS constructs + exfil URLs (escape_html=True to fully escape)Related MCP server: VSGuard MCP
🎯 Why this exists
Prompt injection is the #1 AI attack pattern and it needs no authentication (OWASP LLM01). Agentic systems can take an irreversible action from a single injected instruction. And MCP has opened a whole new surface — tool poisoning and rug pulls. Your existing AppSec tools don't see any of it.
🐼 The idea: one calm guardian
Grey Panda keeps two rare qualities as non-negotiable: intellectual honesty (a whole doc on what it can and cannot do) and standards-anchoring (every rule cites an OWASP ID). No neon-hacker theatre — just controls that are a joy to adopt.
📦 What's in the bundle
Five audience-facing module kits, all powered by one shared, zero-dependency engine:
Kit | For | Start here |
Building AI features | Drop-in SDK + IDE integration | |
Reviewing / gating | AISVS verify, threat models, sign-off | |
Platform / DevOps | 26 rules, SARIF, GitHub Action | |
Agents & MCP | Rule of Two, HITL, manifest pinning, ACS | |
Everyone / compliance | Knowledge pack, mappings, Can/Cannot-Do |
⚙️ How it works
Defense in depth, not prevention theatre. Full walkthrough: HOW-TO-add-guardrails · architecture: docs/ARCHITECTURE.md.
🔐 Standards-anchored
Every rule, checklist item, and SDK control cites a specific ID. Explore any control from the CLI:
gp standards LLM01:2026 # explain a control + its Grey Panda fix
gp standards # list every standard and control IDFull mapping tables: Module 5 → mappings/.
✅ Proof
See the before/after for yourself — the same app, insecure vs. rebuilt with Grey Panda controls:
gp scan examples/vulnerable_app --profile enterprise # 🔴 findings
gp scan examples/secure_app --profile enterprise # ✅ clean👥 For everyone
gp scan . --profile solo # high-signal core, fail on CRITICAL
gp init . --profile team # scaffold config + GitHub Action + pre-commit
gp verify . --level 2 # AISVS Level 2 verification reportMore: Module 1 → PROFILES.
🚀 Get started
pip install grey-panda # from PyPI
pipx install grey-panda # isolated CLI
uvx grey-panda scan . # zero-install runCommand | Does |
| Scan for AI/agent/MCP issues ( |
| Scaffold config, GitHub Action, and pre-commit into a repo |
| AISVS Level 1/2/3 verification report |
| Print the AI security checklist |
| List or explain standards / control IDs |
| Emit an Agent Bill of Materials |
| Run Grey Panda as an MCP server (stdio) |
| Environment self-check + honest-limits pointer |
🤝 In your IDE
Grey Panda secures MCP — and ships as an MCP server, so Claude Code, Cursor, Windsurf, or VS Code can call it while you code:
{ "mcpServers": { "grey-panda": { "command": "gp", "args": ["mcp"] } } }Then ask your assistant to "review this file with grey panda" or "explain LLM03". Details: Module 1 → HOW-TO-use-in-your-ide and Module 4 → HOW-TO-run-the-mcp-server.
🧭 Honest about limits
Grey Panda is a strong floor, not a ceiling. Pattern matching cannot stop all prompt injection; regex DLP is language-specific; static analysis has false positives and negatives. We ship a whole document — with a confidence level and failure condition for every capability: WHAT_IT_CAN_AND_CANNOT_DO.md. Read it before you rely on the tool.
🌱 Contributing
Adding a scanner rule is editing one dataclass with a bad + good example — see CONTRIBUTING.md and Module 3 → HOW-TO-write-a-rule. Everyone is welcome under our Code of Conduct. Found a vulnerability in Grey Panda itself? See SECURITY.md.
Build from source:
git clone https://github.com/dibakshya01/grey-panda && cd grey-panda
pip install -e ".[dev]"
python -m unittest discover -s tests # zero-dependency test suite
gp scan . --profile enterprise --fail-on HIGH # Grey Panda scans itself, clean📄 License
Apache-2.0. Standards cited are the property of their respective authors (see NOTICE). OWASP® is a registered trademark of the OWASP Foundation; Grey Panda is an independent, community project and is not affiliated with or endorsed by OWASP.
Related MCP Connectors
Zero-install security baseline for AI coding agents — OWASP/CWE-cited rules over MCP.
Zero-config MCP security scanner for AI-generated apps. 25K+ vulnerability patterns.
Security reviews, threat models over a repo or website, and remediation tracking, in your editor.
AI-security knowledge as MCP: standards-mapped tools (OWASP, NIST, MITRE) for AI agents.
Related MCP Servers
AlicenseBqualityDmaintenanceAllows developers to query security findings (SAST issues, secrets, patches) using natural language within AI-assisted tools like Claude Desktop, Cursor, and other MCP-compatible environments.179MIT- AlicenseNot gradedqualityDmaintenanceProvides real-time OWASP ASVS security guidance and vulnerability scanning for AI coding agents. Enables proactive security during code generation by checking security requirements, scanning code for vulnerabilities, and suggesting secure code fixes.3MIT
- AlicenseAqualityDmaintenanceEnables AI assistants to scan project dependencies and Infrastructure as Code files for security vulnerabilities and misconfigurations. It also provides automated fixing capabilities to remediate identified security issues.183MIT

Cybrium MCP Serverofficial
AlicenseNot gradedqualityBmaintenanceProvides AI coding assistants with real-time security scanning superpowers, including SAST, secrets detection, dependency CVE scanning, and web vulnerability assessment.19 npmApache 2.0