Repository navigation
Home
A deterministic, fail-closed runner that proves a static surface makes no unexpected network calls, checked against the live deployment rather than against a promise. It implements AGSSH-STD-001: 57 rules across 9 families, three cumulative profiles and three strictness levels.
The README is the reference, RULES.md is the browsable rule index, and the PDF standard carries the normative why, check, fix, tool per rule. This wiki covers the decisions those documents leave to you.
- Choosing a profile and level: the one decision that shapes everything else, and the most common way to get it wrong
- Reading a report: what the verdict, the score, INCONCLUSIVE and UNSCANNABLE each mean, and why the medal is the claim and the number is not
- Fixing the first run: your first scan will be non-conformant. The order that gets you conformant fastest
- Waivers: what they can and cannot suppress, and the debt ceiling as a forcing function
- FAQ
Nothing is green unless proven. A rule the runner cannot conclusively verify returns INCONCLUSIVE, and the gate treats that exactly as it treats FAIL. A missing scanner blocks. A check not implemented in this build blocks. A surface that cannot be fetched at all is reported UNSCANNABLE and produces no score at all, so an unreachable host can never masquerade as a low one.
That posture is the whole product. Most scanners fail open and reward you for a broken environment; this one refuses to.
| Family | Rules | Theme |
|---|---|---|
AG-NET |
9 | Egress and air-gap |
AG-CSP |
6 | Content Security Policy |
AG-HDR |
9 | Transport and response headers |
AG-DNS |
3 | DNS and issuance trust anchors |
AG-SUP |
8 | Supply chain and build integrity |
AG-CI |
6 | Build pipeline hardening |
AG-PRV |
6 | Privacy and consent |
AG-OUT |
3 | Output and document hygiene |
AG-GOV |
7 | Governance and conformance integrity |
agssh -config .airgap.yml # the binary
uses: fabriziosalmi/agssh@v1 # the Action, from a prebuilt image
claude mcp add agssh -- agssh-mcp # the MCP server, for an agentSame engine in all three. The MCP server reuses the runner in-process, with an SSRF guard that refuses loopback and private targets unless you pass allow_private_targets.
In this wiki
Reference
Project