Skip to content
Back to the index

nhi-scan

PyPIInfrastructure

PulseGate's liveness check found it on 26 Sep 2026; it is registered on GitHub and PyPI and has been in the index since 26 Sep 2026. How this is checked

nhi-scan is an open-source command-line tool that inventories non-human and agent identities and assigns risk tiers using the OWASP NHI Top 10. It is intended for security and IAM teams managing service accounts, automation identities, and AI agents.

Inferred · not functionally tested

Open SourceMITCLISelf-hosted
Visit PyPI

Overview

5 features

Purpose: Identifying and prioritizing security risks across non-human and AI-agent identities.

Inferred · not functionally tested

Audience: security engineers and identity and access management teams

Inferred · not functionally tested

Functions: data_extraction

Inferred · not functionally tested

Interfaces: API: unknown · MCP: unknown · CLI: indicated (inferred, not tested) · Self-hosting: indicated (inferred, not tested)

Recorded constraints: pricing: open_source · license: MIT · platforms: CLI · deployment: cli, self_hosted

Constraint provenance is unknown; confirm requirements with the publisher.

Record sources: pypi.org · github.com. These links do not verify the individual claims.

In the AI & LLM security space, nhi-scan takes a focused approach. Inferred · not functionally tested: It focuses on identifying and prioritizing security risks across non-human and AI-agent identities. Inferred · not functionally tested: nhi-scan is an open-source project aimed at security engineers and identity and access management teams. Basis unknown · not verified: nhi-scan is open source under the MIT license. Basis unknown · not verified: nhi-scan is available on the command line, and it can be self-hosted.

It is developed by rpmsft9, and it first shipped in 2026. Development happens publicly on GitHub with 28 commits in the last 90 days. Inferred · not functionally tested: Among its 5 catalogued features are identity inventory, risk tiering, and NHI assessment.

Summary written by a language model from the project’s public pages.

Tasks: Inferred · not functionally tested

  • Identity inventory
  • Risk tiering
  • NHI assessment
  • Agent identity scanning
  • OWASP NHI mapping

Topics: Inferred · not functionally tested

Tags
non-human-identitiesagentic-identityiam-securityowasp-nhi

JSON profile · Text profile · Access guide

Built with & integrations

Written with
Claude Code
Runs on
CLISelf-hosted
Written with — evidence
Claude Code
commit 91d4caa0c708 · since Aug 2026

Trust & compliance

License
MIT
Public signals
HTTPSOpen SourceFree tierGitHubActive maintenance

Indexing history

2

What PulseGate has recorded for this listing

  1. Indexed26 Sep · 22:02 UTC
    nhi-scan seen via PyPI Fresh Feed
    Source: PyPI Fresh Feed · Open
  2. Indexed26 Sep · 21:46 UTC
    nhi-scan seen via PyPI Bulk Enumerator
    Source: PyPI Bulk Enumerator · Open

Frequently asked questions about nhi-scan

What is nhi-scan?
Inferred · not functionally tested: Nhi-scan focuses on identifying and prioritizing security risks across non-human and AI-agent identities. It is catalogued under AI & LLM security on PulseGate.
Who should use nhi-scan?
Inferred · not functionally tested: nhi-scan is an open-source project built for security engineers and identity and access management teams.
Does nhi-scan have a free plan?
Basis unknown · not verified: Yes — nhi-scan is open source under the MIT license and free to use.
What platforms does nhi-scan run on?
Basis unknown · not verified: nhi-scan runs on the command line. It can also be self-hosted.
Is nhi-scan still active?
PulseGate's liveness check found it on 26 Sep 2026. Its GitHub repository shows 28 commits in the last 90 days.
What are alternatives to nhi-scan?
Similar projects tracked by PulseGate include mcp-latchpoint, configwarden, and AiDren.mcp-latchpointconfigwardenAiDren
Who makes nhi-scan?
nhi-scan is developed by rpmsft9.
How long has nhi-scan been around?
nhi-scan first shipped in 2026.

Also in AI & LLM security

Same category — not a similarity match