v0.2.0 · early-stage research tool MIT licensed Zero runtime dependencies
🛡️

QuantumAgentGuard

Agentic-AI vulnerability scanning + quantum-readiness/PKI auditing, in one pass.

LLM red-teaming tools test whether an agent's behavior can be manipulated. Post-quantum crypto tools test whether a primitive is quantum-safe. Nothing checks both for the same project, at the same time, and escalates one when the other is missing. QuantumAgentGuard does.

AI Security Agentic AI LLM Security Post-Quantum Cryptography PKI MCP Static Analysis
8
detector rules
30
passing tests
0
runtime deps
2
vuln classes, one scan

The gap this fills

A 2026 CVE in Microsoft Semantic Kernel (CVE-2026-26030) showed that current agent frameworks fail from ordinary architecture bugs, an eval() reachable from LLM-influenced input, a blocklist filter that's trivially bypassed, not from anything exotic about the model. Microsoft's own conclusion: the LLM can't be treated as a security boundary. Meanwhile, the entire Web PKI, root CAs down to every end-entity certificate, is still RSA/ECDSA-based, and every agent framework built on top of it inherits that exposure whether or not anyone thought to check.

What exists today

Agentic red-teaming tools (e.g. DeepTeam, ~3k★) test prompt injection and unsafe tool use. Post-quantum tooling (e.g. liboqs, ~3.1k★) tests cryptographic primitives. They don't talk to each other, and neither one flags a project that's dangerously exposed in both dimensions at once.

What QuantumAgentGuard adds

One scan, one report: known agentic-vulnerability shapes and classical-crypto/PKI exposure together, with an explicit cross-file rule that escalates crypto findings to HIGH the moment it sees an agent framework with zero PQC dependency anywhere in the project.

Detectors

Every rule is a documented AST/pattern heuristic you can read in full, not a benchmark score.

RuleCategoryFires onPrecedent
AG001Agenticeval()/exec(), HIGH if arg looks agent/LLM-derivedCVE-2026-26030
AG002Agenticos.system/popen, subprocess with shell=TrueCommand injection via tools
AG003Agenticpickle.load(s), unguarded yaml.load()Insecure agent-state deserialization
AG004Agenticsubprocess.*([interpreter, "-c", code], ...) with a non-literal code argSame risk as eval/exec, via a subprocess
PQ001QuantumRSA key generationNo PQ migration path
PQ002QuantumECDSA key generationNo PQ migration path
PQ003QuantumDeprecated ssl.PROTOCOL_TLSv1*/SSLv2*/SSLv23Blocks hybrid PQ key exchange
PQ004QuantumAgent framework marker + zero PQC marker anywhere in projectCross-file escalation

Real output, not a mockup

Scanned against examples/vulnerable_agent_demo/, a small fixed target shaped after CVE-2026-26030, included in the repo. Reproduce with qag scan examples/vulnerable_agent_demo.

$ qag scan examples/vulnerable_agent_demo
QuantumAgentGuard scan: examples/vulnerable_agent_demo
Files scanned: 1
Findings: 6  |  Risk score: 45/100

-- AGENTIC VULNERABILITIES (3) --
  [HIGH  ] AG001 tool.py:17: Dynamic code execution via eval()  [CVE-2026-26030]
  [HIGH  ] AG002 tool.py:21: Shell command execution via os.system
  [MEDIUM] AG003 tool.py:25: Unsafe deserialization via pickle.loads

-- QUANTUM-READINESS GAPS (3) --
  [HIGH  ] PQ004 (project-wide): Agent framework detected with zero post-quantum crypto dependencies
  [MEDIUM] PQ001 tool.py:33: RSA key generated at 2048 bits
  [MEDIUM] PQ003 tool.py:29: Deprecated TLS protocol constant ssl.PROTOCOL_TLSv1

Tested against real repos, not just the demo

v0.1.0 was run against 6 real public repositories (CrewAI examples, MCP servers, Semantic Kernel, AutoGen, LlamaIndex tool integrations, plus a negative control). Every PQ004 finding it produced was a true positive — but it also missed two real findings entirely: an eval()/exec() call hidden inside a Jupyter notebook cell (no .ipynb support), and a subprocess.run([sys.executable, "-c", code]) call in a real MCP tool integration (no rule covered it). Both are fixed in v0.2.0, verified against the exact files that exposed them. Full methodology and results: EVALUATION.md.

Quickstart

1

Install

pip install -e . from a clone. Zero runtime dependencies.

2

Scan

qag scan /path/to/agent/project, or add --json for machine-readable output.

3

Gate CI

qag scan . --fail-on HIGH to fail a pipeline on any HIGH finding.