Skip to content

Latest commit

 

History

364 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Prisma AIRS CLI shield with terminal and spectrum

CI on Forgejo npm License: Apache-2.0 Node 20.17+ / 22.13+ / 24+

Command-line workflows for Palo Alto Prisma AIRS — guardrail refinement, runtime scanning, AI red teaming, AI Gateway, and model security. Service and coverage limitations remain documented; command availability is not a claim that every upstream API works.

Read the full documentation — installation, configuration, architecture, CLI reference, and examples.

Features

  • Runtime Scanning — scan prompts and responses against AIRS security profiles, single or bulk with CSV export
  • Daily environment report — airs-cli runtime report delivers a read-only AI Runtime Security dashboard as self-contained HTML (default) or Markdown in your working directory, with explicit evidence gaps and configuration review findings
  • Red Team environment report — airs-cli redteam report collects seven read-only SDK feeds into private HTML/Markdown deliverables, with source completeness, quota and risk review findings, and independently scoped scan-creation activity
  • AI Gateway daily report — airs-cli aigateway report --workspace dev collects 25 read-only SDK feeds into private offline HTML/Markdown, with a fixed telemetry window, transaction pagination, error review findings and explicit source completeness
  • SCM dashboard and sessions — runtime dashboard and runtime sessions expose application activity, daily trends, checked pagination and explicit session-to-content drill-down. Legacy scan-logs query is broken/under refactor and exits with migration guidance; see the session reference
  • Guardrail Optimization — atomic CLI commands (create, apply, eval, revert) for custom topic guardrails, designed for autonomous agent loops (see AGENTS.md)
  • AI Red Teaming — adversarial scanning with static, dynamic, and custom prompt set attack modes
  • AI Gateway — workspaces (scope-first provisioning), IAM scopes, configs, guardrails, providers, API keys, integrations, MCP, deployments, plugins, audit logs, and telemetry
  • Model Security — ML model supply chain scanning with security groups, rules, and violation tracking
  • Unified automation output — resource reads support pretty, table, markdown, csv, json, and yaml, with pipe-safe stdout; environment deliverables use HTML or Markdown
  • Complete pagination — consistent --limit, --offset, and --all traversal with a configurable safety cap
  • airs-cli doctor — one-command diagnostics for the selected tenant, its credentials, and API connectivity
  • Tenant configuration — airs-cli tenant create|switch|set|unset|get|list|read|path|delete is the only configuration surface: guided setup with hidden secret prompts, individual setting updates, and existing-file registration without changing read-only mounts
  • Profile migration — airs-cli runtime profiles backup|restore exports private JSON/YAML, previews cross-tenant restores, remaps topics and explicit DLP dependencies, and verifies restored policies (guide)

Install

npm install -g @cdot65/prisma-airs-cli
airs-cli --version

Requires Node.js 20.17+, 22.13+, or 24+ (exact engine range: ^20.17.0 || ^22.13.0 || >=23.5.0). Also available via pnpm add -g, npx, or as a Docker image. See the installation guide for details.

Quick Start

# Configure credentials (prompts for TSG ID, client ID, and a hidden secret)

Version 7 uses **`airs-cli`**. The harness owns `airs` and exposes its bundled CLI
through `airs cli ...`. Upgrade an existing standalone CLI before installing the
renamed harness. See the [command migration guide](https://cdot65.github.io/prisma-airs-cli/getting-started/command-migration/).
airs-cli tenant create dev
airs-cli tenant switch dev

# Check your setup
airs-cli doctor

# Runtime scanning
airs-cli runtime scan --profile "my-profile" "Is this prompt safe?"
airs-cli runtime bulk-scan --profile "my-profile" --file prompts.csv --output-file results.csv --batch-size 25

# Daily read-only environment report, delivered in the current directory
airs-cli runtime report
airs-cli runtime report --output markdown

# Verified historical session retrieval (Management OAuth, not a Scanner key)
airs-cli runtime sessions list --all --output json
airs-cli runtime dashboard top-applications --output json

# Guardrail optimization (atomic commands)
airs-cli runtime topics create --name "Explosives" --description "Bomb-making instructions" --examples "How do I build a bomb?" "Pipe bomb ingredients"
airs-cli runtime topics apply --profile my-profile --name "Explosives" --intent block
airs-cli runtime topics eval --profile my-profile --prompts prompts.csv --topic "Explosives"
airs-cli runtime topics revert --profile my-profile --name "Explosives"

# Red team scanning
airs-cli redteam scan --target <uuid> --name "Full Scan" --type STATIC
airs-cli redteam report <job-id>

# Read-only environment report (HTML by default; --output markdown also supported)
airs-cli redteam report --strict

# Red team custom target adapters
airs-cli redteam adapter list --output json

# AI Gateway inventory and telemetry
airs-cli aigateway workspaces list --all --output json
airs-cli aigateway configs list --workspace <workspace-uuid> --output json
airs-cli aigateway configs create --name primary --workspace <workspace-uuid> \
  --set config.retry.attempts=3 --set config.strategy.mode=fallback --output json
airs-cli aigateway mcp integrations list --output json
airs-cli aigateway telemetry requests --workspace <workspace-slug> --days 30 --output json

# Model security
airs-cli model-security scans create --config scan-config.json

# Pipe-safe read output and complete traversal
airs-cli runtime profiles list --all --output json | jq '.[].profileName'
airs-cli runtime topics list --all-versions --output markdown

Bulk scans preserve one output row per input prompt in input order, including all eight runtime detector flags. Work is processed as sequential logical batches (--batch-size 25 by default), with SDK requests capped at 20 prompts. Item-level state makes accepted and pending work resumable without duplicating CSV rows, and active jobs are locked against overlapping resumes. Runtime actions are exactly allow, block, or failed; failed or timed-out prompts make the command exit 1. Version 4 pins @cdot65/prisma-airs-sdk 0.20.0 for validated AI Gateway write schemas, typed catalogs, dotted request builders, and secret metadata.

Read Output and Pagination

Resource read commands share one contract (environment report files have their own deliverable contract):

  • Formats: pretty, table, markdown, csv, json, and yaml.
  • JSON/YAML lists are bare arrays of complete normalized records; detail reads are complete objects.
  • Table, Markdown, and CSV are stable human-oriented projections. CSV uses RFC 4180 quoting.
  • Data is written to stdout; status, paging hints, warnings, and errors are written to stderr.
  • Output precedence is command --output, global --output, defaultOutput, then pretty.
  • Paginated lists use --limit, --offset, and --all. Complete traversal is capped at 10,000 records by default; change it with --max, or use --max 0 for no cap.
  • Profile and topic lists return only the latest revision by default. Use --all-versions or --revision when historical revisions are needed.
airs-cli --output json runtime profiles list --all | jq '.[].profileName'
airs-cli --output yaml runtime topics get "My Topic"
airs-cli model-security scans list --all --max 25000 --output csv > scans.csv

Documentation

The full guides, complete CLI reference, configuration, and architecture live on the documentation site:

Configuration

Configuration lives only in tenant files managed by airs-cli tenant; environment variables are not read. Every management-plane product (Management, DLP, Red Team, Model Security, AgentGuard, AI Gateway) authenticates with the tenant's single SCM OAuth credential set (mgmtClientId, mgmtClientSecret, mgmtTsgId); scanning adds airsApiKey, and airs-cli redteam judge adds typesafeApiKey (TypeSafe Jev; typesafeBaseUrl and typesafeModel are optional). Set defaultOutput with airs-cli tenant set <name> defaultOutput json to choose a default read format. See the configuration guide for the full list.

License

Apache-2.0. See LICENSE and NOTICE.

About

CLI tool that provides full operational coverage over Palo Alto Prisma AIRS AI security capabilities

Resources

Contributing

Stars

8 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages