What we still need to verify : 2 points in this profile are not yet confirmed against vendor documentation.
- Exact list of supported agent frameworks and versions: verify against project docs
- Prompt hardening and dynamic testing features: confirm which are present in the open source CLI
Treat these points as unconfirmed. They are open items in the catalog's verification queue, and this note stays until each is checked against the vendor's documentation.
What it does
Agentic Radar takes a directory of source code for an agentic application and walks it statically. It looks for the construction patterns of supported frameworks, identifies each agent definition, the tools registered to that agent, and the control flow edges between agents. The output is a self contained HTML report containing a rendered graph of the workflow plus a per node breakdown of what each agent can reach.
The security value comes from the tool inventory rather than from finding code defects. Agentic systems fail through capability: an agent that can call a shell, write files, or issue arbitrary HTTP requests is a different risk class from one that can only query a read only index, and that distinction is usually buried in framework glue code nobody reviews. The tool separates built in framework tools from custom ones you wrote, flags categories that reach outside the process, and maps observations to public agentic threat taxonomies. Because the analysis is static, it runs against a repository without deploying anything or spending model calls.
Where it fits
This belongs at code review time and in pull requests. It is fast enough to run on every change to an agent definition, and the graph is the artifact you want in front of a reviewer asking whether a new tool registration was intentional. It needs someone who can read that graph and make a judgment call: the tool reports capability, a human decides whether the capability is appropriate. The prerequisite is that agents are defined in code using a supported framework. Agents assembled at runtime from configuration will be largely invisible to it.
Strengths
- Turns an opaque agent graph into an artifact a reviewer can actually read, which is the main barrier to reviewing these systems at all.
- Static and offline, so there is no need to stand up the application or pay for inference to get a report.
- Explicit separation of framework provided tools from custom code focuses attention where review effort pays off.
- Framework aware rather than generic, so it understands what a tool registration means.
Limitations
- Coverage is tied to a short list of frameworks. Custom orchestration or an unsupported framework yields little or nothing.
- Static analysis cannot see dynamically registered tools, runtime prompts, or what an MCP server actually exposes once connected.
- Output is inventory and risk categorization, not proof of exploitability. It will not tell you whether an injection actually succeeds.
Who it suits
Teams building multi agent systems on mainstream Python frameworks who need a review artifact and a capability inventory. Not a fit for teams whose AI exposure is a single hosted assistant with no tool calling, and not a replacement for dynamic red teaming.
Used Agentic Radar? Recommend it under your own name and title.
Recommend this tool