Metadata-Version: 2.4
Name: orithos-cli
Version: 0.1.0
Summary: Orithos CLI — AI agent security testing from the terminal: scan deployed agents, MCP servers, and skill/plugin artifacts.
Author: Orithos
License: Proprietary
Project-URL: Homepage, https://orithos.com
Project-URL: Documentation, https://orithos.com/docs
Project-URL: Repository, https://github.com/nishkmg/TraceShield
Keywords: ai-security,agent-security,red-team,mcp,llm,security
Classifier: Development Status :: 4 - Beta
Classifier: Environment :: Console
Classifier: Intended Audience :: Developers
Classifier: Intended Audience :: Information Technology
Classifier: Programming Language :: Python :: 3
Classifier: Programming Language :: Python :: 3.12
Classifier: Topic :: Security
Requires-Python: >=3.12
Description-Content-Type: text/markdown
Requires-Dist: click>=8.1.0
Requires-Dist: httpx>=0.27.0
Requires-Dist: pydantic>=2.0.0
Requires-Dist: pyyaml>=6.0
Provides-Extra: dev
Requires-Dist: pytest>=8.0.0; extra == "dev"
Requires-Dist: pytest-mock>=3.14.0; extra == "dev"
Requires-Dist: types-PyYAML>=6.0; extra == "dev"

# Orithos CLI

AI agent security testing from the terminal. Scan deployed agents and MCP
servers against the Orithos probe catalog, vet skill/plugin artifacts before
they run, and pull findings, compliance reports, and evidence packages — all
from the command line.

## Install

```bash
pip install orithos-cli
```

## Quick start

```bash
# Point the CLI at your Orithos account (or use ORITHOS_API_KEY / ORITHOS_API_URL env vars)
orithos configure

# Vet a skill or plugin before installing it — no account needed, fully offline
orithos skill scan ./some-agent-skill

# Scan a registered agent
orithos scan run --agent-id <AGENT_ID>
orithos scan status <SCAN_ID>
orithos scan findings <SCAN_ID> --format sarif
```

## `orithos skill scan`

Static vetting for agent skills, plugins, and MCP packages. Runs offline with
zero outbound calls; archives (zip/tar.gz) are unpacked with traversal
protection.

```bash
orithos skill scan <path|url> [--format text|json|sarif] [--fail-on critical|high|medium|low]
```

Seven check classes: manifest hygiene · declared-vs-implied permissions ·
outbound destinations (exfil-prone endpoints, IP literals) · shell & install
hooks · credential access · obfuscation · known-bad signatures. Every finding
cites file, line, and evidence.

Exit codes: `0` clean · `1` findings at/above `--fail-on` (default `high`) ·
`2` error — ready for CI gates.

## Commands

- `orithos agent ...` — register and manage agent endpoints
- `orithos scan ...` — run scans, fetch findings (`summary`/`json`/`sarif`/`junit`)
- `orithos skill scan ...` — static skill/plugin vetting
- `orithos mcp ...` — interact with the Orithos MCP policy server
- `orithos compliance ...` — compliance mappings and reports
- `orithos verify <package>` — offline evidence-package integrity check (hashes + Merkle root)
- `orithos connection / discovery / graph / guardrail / probes / remediation / runtime ...` — platform workflows

## Environment variables

| Variable | Default | Description |
|----------|---------|-------------|
| `ORITHOS_API_KEY` | — | API key (`tsk_...`); overrides the config file |
| `ORITHOS_API_URL` | `https://api.orithos.com` | API base URL |
| `ORITHOS_ORG_ID` | — | Organisation ID (optional override) |
| `ORITHOS_TIMEOUT` | `30` | Request timeout in seconds |

## Development

```bash
pip install -e "apps/cli[dev]"
pytest -q
```
