Full operational coverage over Palo Alto Prisma AIRS AI security — guardrail refinement, runtime scanning, AI red teaming, AI Gateway, and model security.
Read the full documentation — installation, configuration, architecture, CLI reference, and examples.
- Runtime Scanning — scan prompts and responses against AIRS security profiles, single or bulk with CSV export
- Guardrail Optimization — atomic CLI commands (
create,apply,eval,revert) for custom topic guardrails, designed for autonomous agent loops (seeAGENTS.md) - AI Red Teaming — adversarial scanning with static, dynamic, and custom prompt set attack modes
- AI Gateway — workspaces, configs, guardrails, providers, API keys, integrations, MCP, deployments, plugins, audit logs, and telemetry
- Model Security — ML model supply chain scanning with security groups, rules, and violation tracking
- Unified automation output — every read command supports
pretty,table,markdown,csv,json, andyaml, with pipe-safe stdout - Complete pagination — consistent
--limit,--offset, and--alltraversal with a configurable safety cap airs doctor— one-command diagnostics for environment, credentials, and API connectivityairs config— manage~/.prisma-airs/config.jsonfrom the CLI (list,get,set,unset,path)
npm install -g @cdot65/prisma-airs-cli
airs --versionRequires Node.js >= 20. Also available via pnpm add -g, npx, or as a Docker image. See the installation guide for details.
# Configure credentials
cp .env.example .env # add your API keys
# Check your setup
airs doctor
# Runtime scanning
airs runtime scan --profile "my-profile" "Is this prompt safe?"
airs runtime bulk-scan --profile "my-profile" --file prompts.csv --output-file results.csv --batch-size 25
# Guardrail optimization (atomic commands)
airs runtime topics create --name "Explosives" --description "Bomb-making instructions" --examples "How do I build a bomb?" "Pipe bomb ingredients"
airs runtime topics apply --profile my-profile --name "Explosives" --intent block
airs runtime topics eval --profile my-profile --prompts prompts.csv --topic "Explosives"
airs runtime topics revert --profile my-profile --name "Explosives"
# Red team scanning
airs redteam scan --target <uuid> --name "Full Scan" --type STATIC
airs redteam report <job-id>
# Red team custom target adapters
airs redteam adapter list --output json
# AI Gateway inventory and telemetry
airs aigateway workspaces list --all --output json
airs aigateway configs list --workspace <workspace-uuid> --output json
airs aigateway configs create --name primary --workspace <workspace-uuid> \
--set config.retry.attempts=3 --set config.strategy.mode=fallback --output json
airs aigateway mcp integrations list --output json
airs aigateway telemetry requests --workspace <workspace-slug> --days 30 --output json
# Model security
airs model-security scans create --config scan-config.json
# Pipe-safe read output and complete traversal
airs runtime profiles list --all --output json | jq '.[].profileName'
airs runtime topics list --all-versions --output markdownBulk scans preserve one output row per input prompt in input order, including all eight runtime detector flags. Work is processed as sequential logical batches (--batch-size 25 by default), with SDK requests capped at 20 prompts. Item-level state makes accepted and pending work resumable without duplicating CSV rows, and active jobs are locked against overlapping resumes. Runtime actions are exactly allow, block, or failed; failed or timed-out prompts make the command exit 1. Version 4 pins @cdot65/prisma-airs-sdk 0.20.0 for validated AI Gateway write schemas, typed catalogs, dotted request builders, and secret metadata.
Read commands share one contract:
- Formats:
pretty,table,markdown,csv,json, andyaml. - JSON/YAML lists are bare arrays of complete normalized records; detail reads are complete objects.
- Table, Markdown, and CSV are stable human-oriented projections. CSV uses RFC 4180 quoting.
- Data is written to stdout; status, paging hints, warnings, and errors are written to stderr.
- Output precedence is command
--output, global--output,defaultOutput/PANW_CLI_OUTPUT, thenpretty. - Paginated lists use
--limit,--offset, and--all. Complete traversal is capped at 10,000 records by default; change it with--max, or use--max 0for no cap. - Profile and topic lists return only the latest revision by default. Use
--all-versionsor--revisionwhen historical revisions are needed.
airs --output json runtime profiles list --all | jq '.[].profileName'
PANW_CLI_OUTPUT=yaml airs runtime topics get "My Topic"
airs model-security scans list --all --max 25000 --output csv > scans.csvThe full guides, complete CLI reference, configuration, and architecture live on the documentation site:
- Getting Started — install, configure credentials, run your first scan
- Runtime Security — scanning, profiles, topics, and DLP management
- Guardrail Optimization — the agent-driven
topics create/apply/eval/revertloop - AI Red Teaming — static, dynamic, and custom adversarial scans
- AI Gateway — full SDK 0.20 resource CRUD, structured mutation flags, two-plane authorization, secret-safe writes, and telemetry
- Model Security — ML model supply-chain scanning
- CLI Reference — every command, flag, and example
Credentials come from environment variables or ~/.prisma-airs/config.json. At minimum: PANW_AI_SEC_API_KEY (scanning) and PANW_MGMT_CLIENT_ID / PANW_MGMT_CLIENT_SECRET / PANW_MGMT_TSG_ID (management). Set defaultOutput in the config file or PANW_CLI_OUTPUT in the environment to choose a default read format. See .env.example and the configuration guide for the full list.
MIT