OWASP AppSec Agent

OWASP AppSec Agent is an open-source TypeScript library and CLI that automates everyday application security work — security code review, pull-request analysis, STRIDE threat modeling, fix generation, and test verification — using purpose-built AI agents that return structured, schema-validated outputs. It runs from the command line, embeds in CI pipelines or internal platforms, and powers a companion web dashboard (AI Threat Modeler) for teams that prefer a UI.

About OWASP AppSec Agent

The package includes specialized agent roles:

  • a Code Reviewer that scans repositories or pull-request diffs and produces structured security reports with CWE and OWASP Top 10 references;

  • a Threat Modeler that generates an ASCII data-flow diagram, runs a STRIDE analysis, and produces a risk registry;

  • a Code Fixer that proposes minimal, targeted security fixes as structured JSON;

  • a QA Verifier that runs the project’s test suite to confirm a fix does not break functionality; and a Simple Query agent for interactive AppSec Q&A.

    Unlike rigid rule-based scanners or ad-hoc chat prompts, every agent returns structured JSON outputs (findings, fixes, threat models, QA verdicts) suitable for automation, while still using AI to reason over real code and deployment context. The library is thread-safe for concurrent web applications, validates paths against directory traversal, and offers optional Anthropic-to-OpenAI failover.

    For users who prefer a UI to the CLI, the recommended companion is AI Threat Modeler, the first open-source AI for threat modeling. It runs with a single docker-compose command and provides a Next.js dashboard with authentication, GitHub repository import, an interactive threat-aware data-flow-diagram canvas, sortable threat tables, a Risk Registry, PDF/CSV/JSON exports, and a chat interface backed by appsec-agent. It is the easiest way to evaluate AppSec Agent without writing code.

    Quick start:

$ npm install appsec-agent

$ export ANTHROPIC_API_KEY="YOUR API KEY"

$ npx agent-run -r code_reviewer -s ./src.

  • Source

  • Docs

  • npm

  • Companion App

    Contributions are welcome — especially AppSec domain expertise (CWE, STRIDE, secure SDLC) to refine agent prompts and reduce false positives.

Project Resources

Project Leaders

Sam Li

Project Leader

EmailLinkedIn

Project Information

Lab Project
Classification
Tool
Language
TypeScript
License
Apache License 2.0
Contributors
1
GitHub Stars
15
Downloads
0

Requirements

  • Node.js 18.0 or higher
  • npm or yarn
  • Anthropic API key (or OpenAI API key for fallback)
OWASP Logo
OWASP is a nonprofit foundation improving software security through open-source projects, global communities, and education. All resources are free and open to everyone.
OWASP, the OWASP logo, and Global AppSec are registered trademarks and AppSec Days, AppSec California, AppSec Cali, SnowFROC, OWASP Boston Application Security Conference, and LASCON are trademarks of the OWASP Foundation, Inc.
© 2026, OWASP Foundation Inc. All rights reserved.