# Palisade (palisade-sec)

> A linter for LLM security: statically detects prompt-injection paths -
> untrusted input → LLM → dangerous sink (exec/eval, shell, raw SQL, URL
> fetch) - in Python and JavaScript/TypeScript codebases, in CI. Pure static
> analysis: never executes scanned code. The offline core (`scan`, `map`,
> `baseline`, `fix`, `redteam` synthesis) makes no network calls and needs no
> API key. Install: `pip install palisade-sec` (add `[js]` for JS/TS). Run:
> `palisade-sec scan . --json`. Exit codes: 0 ok or nothing new; 1 a gate
> tripped (new HIGH under `scan`/`review --ci`, BLOCK under `audit --ci`, a
> landed attack under `redteam --execute --ci`); 2 usage/target error (bad
> path, missing explicit `--config`/`--rules`, a `--ci` run that scanned 0
> files, judgment layer missing its `[judge]` extra or key, refused symlinked
> output path, errored attacks under `redteam --execute --ci`); 3 internal
> error (a bug, not a finding). JSON schema_version: 1.

Key facts for tools and agents: findings require a complete
source→LLM→sink data-flow path (near-zero false positives by design);
denylists/confirmation gates and sanitizers-in-name-only downgrade findings
to MED "risky" rather than suppressing them; `palisade-sec fix` emits
guardrail templates + regression tests without modifying code;
`--assume-params-untrusted` enables library mode (public function params
become sources); `baseline` + `scan --ci --baseline` gates CI on NEW
findings only. `map` inventories the AI surface offline. The optional
judgment layer - `audit`, the judged checks in `review`, and `redteam
--execute` - needs `pip install 'palisade-sec[judge]'` plus an endpoint and
key in the environment or a `.env` in the current directory; without them
`review` runs taint-only. `review --ci` gates only on deterministic taint
findings; `audit --ci` is an explicit opt-in gate on BLOCK decisions.
Each JSON finding carries `cwe` (e.g. CWE-94, CWE-1426, CWE-1427) and
`owasp_llm` (e.g. LLM01:2025, LLM05:2025); `--sarif` emits SARIF 2.1.0 with
GitHub CWE tags and `security-severity`. Integrations: the GitHub Action
`uses: arpankernel/palisade@v0.5.2` (SARIF upload + gate) and the pre-commit
hook `id: palisade-sec`. Measured on a pinned 26-repo corpus: precision 1.000
(0 false positives), recall 0.200 on 10 hand-verified paths.

## Docs

Hosted documentation (human-readable, searchable): https://arpankernel.github.io/palisade/docs/

- [Agent contract](https://raw.githubusercontent.com/arpankernel/palisade/main/docs/agents.md): exact commands, JSON parsing rules, remediation policy - start here if you are an AI agent
- [CLI reference](https://raw.githubusercontent.com/arpankernel/palisade/main/docs/cli-reference.md): all commands, flags, exit codes, config keys, full JSON + baseline schemas
- [Rules reference](https://raw.githubusercontent.com/arpankernel/palisade/main/docs/rules-reference.md): the six builtin rules, pattern semantics, sanitizer tiers, custom rules
- [End-to-end tutorial](https://raw.githubusercontent.com/arpankernel/palisade/main/docs/tutorial.md): scan → fix → verify → baseline → CI on a sample app
- [Architecture](https://raw.githubusercontent.com/arpankernel/palisade/main/docs/architecture.md): frontends → taint IR → engine → rules; precision decisions; safety contract
- [Judgment layer](https://raw.githubusercontent.com/arpankernel/palisade/main/docs/judgment-layer.md): which commands are keyless, the `[judge]` extra, and `.env` setup for audit/review/redteam --execute

## Optional

- [Getting started](https://raw.githubusercontent.com/arpankernel/palisade/main/docs/getting-started.md): 5-minute human onboarding
- [Proof scans](https://raw.githubusercontent.com/arpankernel/palisade/main/docs/proof-scans.md): evidence vs. real CVE repos (Vanna CVE-2024-5565 caught; misses documented)
- [Roadmap](https://raw.githubusercontent.com/arpankernel/palisade/main/docs/roadmap.md): Phases 0–6, Measure → Remediate, with current status
- [Contributor agent instructions](https://raw.githubusercontent.com/arpankernel/palisade/main/AGENTS.md): build/test commands and invariants for changing Palisade itself
- [README](https://raw.githubusercontent.com/arpankernel/palisade/main/README.md): project front page
- [Changelog](https://raw.githubusercontent.com/arpankernel/palisade/main/CHANGELOG.md): release history
