One scan.
Every artifact.
Pre-generated from the repository's E2E fixture skills. Open any file to inspect — or copy the CLI command to regenerate it against your own project.
Four formats.
One scan.
Pick the format that fits the audience. All four come from a single agentsec audit run — or re-render any of them from the JSON with agentsec report.
Plain-text summary, no ANSI codes — diffable and log-friendly.
Self-contained HTML — shareable, printable, opens in any browser.
Full machine-readable audit — skills, findings, scores, metadata.
SARIF 2.1 — inline findings in VS Code and GitHub Advanced Security.
The flags behind every example.
Each sample was generated by composing these four. Swap --path with your repo and you'll get the same set of artifacts.
More configuration examples.
A README describing every artifact, a ready-to-copy CI workflow, and a typed config template. Mirrors the repository's examples/ directory.
Overview of every file in this folder and how to regenerate each report.
GitHub Actions workflow running AgentSec on push and pull-request with SARIF upload.
Typed policy and scanner configuration template — copy as your entry point.
Reference config — not produced by audit.
Run it on your own project.
Run npx agentsec in your project and you'll get the same four artifacts in seconds.