What’s new here
ASH is an orchestration layer: it integrates multiple security scanners (Bandit for Python SAST, Checkov for IaC, Grype for SCA, and so on), runs them against your codebase, and merges the results into one report. In v3 it also ships an MCP server, so an AI coding agent can call run_ash_scan, poll progress, and fetch structured findings without ever leaving its tool loop.
What it does
ASH runs in three modes: local (Python plus UV-isolated scanners), container (full tool set via Docker/Finch/Podman), and precommit (fast subset for git hooks).
Built-in scanners cover SAST (Bandit, Semgrep, Opengrep), IaC (Checkov, cfn-nag, cdk-nag), secrets (detect-secrets), and SCA/SBOM (Grype, Syft, npm-audit). Scanner versions are constrained and auto-installed via UV’s tool isolation; offline mode skips the downloads and falls back to system-installed tools.
Output lands in .ash/ash_output/ as SARIF, JUnit XML, HTML, Markdown, CSV, and JSON. The MCP server adds tools for diffing two scan results, drafting suppression entries, scanning every project in a VS Code workspace, and delivering a source tree to a remote server over chunked base64 upload.
Who it’s for
Teams that want a single security gate across mixed codebases (Python services, CloudFormation, CDK, Node packages) without wiring up each scanner separately. Also useful for AI coding agent workflows: the MCP interface lets agents check their own output for vulnerabilities before committing.
Try it
# Install uv on Linux/macOS if it isn't installed already
curl -sSfL https://astral.sh/uv/install.sh | sh
# Create an alias for ASH
alias ash="uvx git+https://github.com/awslabs/automated-security-helper.git@v3.7.0"
# Run a scan in local mode (Python only)
ash --mode local
# Run a scan in container mode (all tools)
ash --mode container
# Run a scan in precommit mode (fast subset of tools)
ash --mode precommitFor pre-commit, add to .pre-commit-config.yaml:
repos:
- repo: https://github.com/awslabs/automated-security-helper
rev: v3.7.0
hooks:
- id: ash-simple-scanHow mature is it
700 stars, 92 forks, 28 contributors, 52 releases. Latest is v3.7.1 (2026-09-03). Over 100 commits in the last 90 days. 3 open issues and 9 open pull requests. Apache-2.0. Last push 2026-10-09.