OWASP AppSec Agent is an open-source TypeScript library and CLI that automates everyday application security work — security code review, pull-request analysis, STRIDE threat modeling, fix generation, and test verification — using purpose-built AI agents that return structured, schema-validated outputs. It runs from the command line, embeds in CI pipelines or internal platforms, and powers a companion web dashboard (AI Threat Modeler) for teams that prefer a UI.
The package includes specialized agent roles:
a Code Reviewer that scans repositories or pull-request diffs and produces structured security reports with CWE and OWASP Top 10 references;
a Threat Modeler that generates an ASCII data-flow diagram, runs a STRIDE analysis, and produces a risk registry;
a Code Fixer that proposes minimal, targeted security fixes as structured JSON;
a QA Verifier that runs the project’s test suite to confirm a fix does not break functionality; and a Simple Query agent for interactive AppSec Q&A.
Unlike rigid rule-based scanners or ad-hoc chat prompts, every agent returns structured JSON outputs (findings, fixes, threat models, QA verdicts) suitable for automation, while still using AI to reason over real code and deployment context. The library is thread-safe for concurrent web applications, validates paths against directory traversal, and offers optional Anthropic-to-OpenAI failover.
For users who prefer a UI to the CLI, the recommended companion is AI Threat Modeler, the first open-source AI for threat modeling. It runs with a single docker-compose command and provides a Next.js dashboard with authentication, GitHub repository import, an interactive threat-aware data-flow-diagram canvas, sortable threat tables, a Risk Registry, PDF/CSV/JSON exports, and a chat interface backed by appsec-agent. It is the easiest way to evaluate AppSec Agent without writing code.
Quick start:
$ npm install appsec-agent
$ export ANTHROPIC_API_KEY="YOUR API KEY"
$ npx agent-run -r code_reviewer -s ./src.
Companion App
Contributions are welcome — especially AppSec domain expertise (CWE, STRIDE, secure SDLC) to refine agent prompts and reduce false positives.