v0.1.0: Initial release
First release of QuantumAgentGuard: a static-analysis CLI (qag) that scans AI agent codebases for both agentic vulnerability patterns and quantum-readiness/PKI gaps, in one pass, with zero runtime dependencies.
Detectors
AG001-AG003: unsafe eval/exec, shell injection, insecure deserialization in agent tool-calling code.PQ001-PQ003: RSA/ECDSA key generation, deprecated TLS protocol constants.PQ004: cross-file escalation when an agent framework (LangChain, Semantic Kernel, AutoGen, CrewAI, LlamaIndex, MCP) is present with zero post-quantum crypto dependency anywhere in the project.
Usage
pip install -e .
qag scan /path/to/agent/project
qag scan /path/to/agent/project --fail-on HIGH # for CI
See the README and site for the full detector table and a real (non-mocked) scan output.
Full changelog: CHANGELOG.md