Skip to content

Releases: sunilgentyala/QuantumAgentGuard

v0.2.0

Choose a tag to compare

@sunilgentyala sunilgentyala released this 28 Sep 02:05

Found by running v0.1.0 against 6 real public agent-framework repositories (see EVALUATION.md).

Added

  • AG004: detects subprocess.*([interpreter, "-c", code], ...) code execution — the same risk class as eval()/exec(), invisible to AG001/AG002. Found in a real llama_index MCP tool integration.
  • .ipynb notebook support: code cells are now scanned by the same rules as .py files. Two real eval()/exec()-on-agent-output findings existed only in notebook cells in public repos and were invisible to v0.1.0.

Fixed

  • Framework/PQC marker matching now uses word-boundary matching instead of plain substring search, closing a false-positive vector (autogen matching inside autogenerated).

30 tests passing (was 22). Full writeup: EVALUATION.md.

v0.1.0: Initial release

Choose a tag to compare

@sunilgentyala sunilgentyala released this 27 Sep 16:19

First release of QuantumAgentGuard: a static-analysis CLI (qag) that scans AI agent codebases for both agentic vulnerability patterns and quantum-readiness/PKI gaps, in one pass, with zero runtime dependencies.

Detectors

  • AG001-AG003: unsafe eval/exec, shell injection, insecure deserialization in agent tool-calling code.
  • PQ001-PQ003: RSA/ECDSA key generation, deprecated TLS protocol constants.
  • PQ004: cross-file escalation when an agent framework (LangChain, Semantic Kernel, AutoGen, CrewAI, LlamaIndex, MCP) is present with zero post-quantum crypto dependency anywhere in the project.

Usage

pip install -e .
qag scan /path/to/agent/project
qag scan /path/to/agent/project --fail-on HIGH   # for CI

See the README and site for the full detector table and a real (non-mocked) scan output.

Full changelog: CHANGELOG.md