helmwart
v0.5.11
Published
helmwart scan — design-time threat modeling for agentic-AI systems, in your CI. Reads a real agent config (MCP, n8n, LangGraph, CrewAI, and more) and reports its threat model against OWASP Agentic Top 10, MAESTRO, and MITRE ATLAS — including the lethal-tr
Maintainers
Readme
helmwart
Design-time threat modeling for agentic-AI systems, in your CI.
Helmwart reads your agent system's real configuration — MCP servers, n8n, LangGraph, CrewAI, AutoGen, Bedrock, Azure AI Foundry, Dify, and more — and reports its threat model against the OWASP Agentic Top 10, MAESTRO, and MITRE ATLAS, including an automated lethal-trifecta reachability check that the CSA recommends doing by hand.
It runs the same engine as helmwart.com, locally where your code lives. A Helmwart account is required; after sign-in, work commands run without network access for up to 30 days.
Install
npx helmwart scan ./mcp-config.json # zero-install, nothing left behind
npm i -g helmwart # or install the `helmwart` command globallyNo npm? A verified one-line installer that checks the SHA-256:
curl -fsSL https://helmwart.com/install.sh | shRequires Node ≥ 22.12. Everything is bundled, so there are no dependencies to install. Runs anywhere Node runs, including Windows.
Quickstart
helmwart scan ./mcp-config.json # threat-model one config
helmwart scan --repo . # scan every agent config in a repo
helmwart scan ./mcp.json --fail-on critical # a CI gate: exit 1 on a critical or a trifecta
helmwart fix ./mcp.json --target k8s --cloud aws # emit a real fix (here, an AWS-shaped NetworkPolicy)
helmwart explain T51 # what a threat means, and its controlsBy default the scan leads with the findings that discriminate: the reachable lethal
trifecta, attack chains, exposed credentials, over-privilege. Add --audit to also see
the invariant hygiene checks (audit-log gaps, identity gaps) hidden from the default view.
Output formats
Pick with --format <fmt>; save with --output / -o <file>.
| Format | For |
| --- | --- |
| human | the terminal (default) |
| sarif | GitHub code scanning and the Security tab (SARIF 2.1.0) |
| asff | AWS Security Hub (aws securityhub batch-import-findings) |
| gitlab | the GitLab merge-request security widget |
| azure-pipelines | Azure DevOps build summary — native ##vso[task.logissue], no extension |
| json | your own tooling |
| md · html · pdf | a shareable report |
Gate a PR on newly-introduced findings only: --baseline <file> with --fail-on new-critical.
Policy and exemptions — .helmwart.yml
Auto-discovered at the repo root. It sets the gate threshold and the findings you have consciously accepted (they drop from the gate and the SARIF, and stay as an audit record):
fail-on: new-critical
exemptions:
- threat: T43
reason: "stdio subprocess, no network listener"
- threat: TRIFECTA
file: configs/reporting-agent.json
reason: "runs in a sandbox; accepted"Use it from an agent — helmwart mcp
helmwart mcp runs the CLI as an MCP server over
stdio, exposing the engine as tools any MCP client can call (Claude Desktop, n8n, Cursor,
or your own runtime):
| Tool | What it does |
| --- | --- |
| scan_config | threat-model a raw agent config |
| generate_fix | the artifact that severs a reachable trifecta leg |
| explain_threat | a threat's definition, its mitigations, and its Atlas link |
| list_frameworks | the config formats Helmwart recognises |
Wire it into claude_desktop_config.json:
{
"mcpServers": {
"helmwart": { "command": "npx", "args": ["-y", "helmwart", "mcp"] }
}
}All commands
Work commands require a Helmwart account. After helmwart login, scanning and gating
remain local and can run without network access for up to 30 days.
| Command | What it does |
| --- | --- |
| scan <file> · scan --repo <dir> | threat-model one config, or a whole repo |
| fix <file> | emit the artifact that cuts a trifecta leg (--target k8s\|terraform\|rego, --cloud aws\|azure\|gcp) |
| explain <Txx> | what a threat means, and the controls that cover it |
| compliance [file] | regroup findings by framework (--standard soc2\|iso-27001\|nist-ai-rmf\|eu-ai-act\|iso-42001) |
| tm [file] | interactive threat-modeling session, saved as a report |
| report <file> | the full deliverable in md + html + pdf |
| frameworks | the config formats the scanner recognises |
| mcp | run as an MCP server (see above) |
| login · logout · whoami | browser sign-in, local session removal, and active-account status |
Full surface: helmwart --help, or man helmwart. Docs: https://helmwart.com/cli/.
Exit codes
| Code | Meaning |
| --- | --- |
| 0 | clean, or no gate tripped |
| 1 | gate tripped (a reachable trifecta, or a finding at or above --fail-on) |
| 2 | usage or parse error |
| 3 | current terms must be accepted before licensed remediation content can load |
| 4 | sign-in is required before the command can run |
License
Proprietary — free to use, not open source. You may run helmwart for any purpose
at no charge, but you may not copy, modify, or redistribute it. See the bundled LICENSE.
The OWASP-derived threat content is separately licensed CC BY-SA 4.0 (see
LICENSE-CONTENT). MITRE ATLAS content is reproduced under MITRE's terms.
