$npx skillfedfor your agent

demisto-sdk

"A Python library for the Demisto SDK"

With conditionsPyPI Build ToolsReleased Aug 2026114.2K downloads / moMITPure Python

Decision gist · record as of 2026-08-14

pure-Python wheel — demisto_sdk-1.39.6-py3-none-any.whl
v1.39.6 · released 2026-08-03 · Python <3.15,>=3.10 · 67 runtime deps: autopep8, click, bandit, mypy, pylint, vulture, beautifulsoup4, chardet

Yes, if you are developing integrations or content packs for Cortex XSOAR or Cortex XSIAM. The SDK is actively maintained, has no known vulnerabilities, uses a permissive MIT license, and provides a comprehensive CLI and Python API for the full development lifecycle. Install only on Unix-like systems (Linux, macOS, or WSL2); Windows is not supported. The large dependency tree (67 runtime packages) is typical for a mature development tool and should not be a blocker.AI-flagged interpretation of the facts on this page — verify before relying

Before you install

  • Requires Python 3.10–3.14, git, and a Unix-like environment (Linux, macOS, or WSL2); Windows is not supported.
  • Some commands require Node.js and npm for markdown validation.
  • Low friction installation as a pure Python wheel.

License · maintenance · safety

MIT (permissive) — MIT license permits commercial and private use with minimal restrictions, making it suitable for both open-source and proprietary development workflows.

last release 2026-08-03 (11 days)

0 known vulnerabilities (OSV.dev, 2026-08-14) · 114,197 downloads/mo, #12,309 on PyPI

Verify before relying

pip3 install demisto-sdk
demisto-sdk -h
# Set environment variables for XSOAR/XSIAM connection:
export DEMISTO_BASE_URL=<server-url>
export DEMISTO_API_KEY=<api-key>
demisto-sdk validate
  • Whether the 67 runtime dependencies introduce significant supply-chain risk or maintenance burden for end users.
  • Performance characteristics when validating large content packs or running integration tests.
  • Availability and quality of documentation for each of the 21 supported commands.
Same gist for agents: .md · .json

What it is and what it does

Demisto SDK is a Python library and CLI tool for developing and managing integrations and content packs within the Cortex XSOAR and Cortex XSIAM security orchestration platforms. It provides commands to initialize, validate, format, and upload content; generate documentation and test playbooks; and interact with XSOAR/XSIAM servers via API. The tool is designed to work with content repositories structured like the official Cortex content repository and includes code generators for OpenAPI and Postman specifications.

The SDK supports a large surface of development workflows: entity validation, secret scanning, pre-commit hooks, content preparation, splitting and formatting YAML files, running playbooks and commands on remote servers, downloading existing content, and generating integration code from API specifications. It requires environment variables to connect to an XSOAR or XSIAM instance and runs best from within a git repository or when the content path is explicitly configured.

Use it for

  • Validate integration and playbook YAML files before uploading to Cortex XSOAR or XSIAM.
  • Generate integration code from OpenAPI or Postman API specifications to accelerate integration development.
  • Upload and download integrations, playbooks, and other content entities between your development environment and a live XSOAR/XSIAM instance.
  • Run pre-commit hooks and secret scanning to catch issues early in the development workflow.
  • Generate test playbooks and documentation automatically from integration definitions.
  • Set up and manage environment configuration for multi-instance XSOAR/XSIAM deployments.

Worth the install?

AI-flagged interpretation of the facts on this page. Verify before relying on it.

With conditions

Yes, if you are developing integrations or content packs for Cortex XSOAR or Cortex XSIAM.

The SDK is actively maintained, has no known vulnerabilities, uses a permissive MIT license, and provides a comprehensive CLI and Python API for the full development lifecycle. Install only on Unix-like systems (Linux, macOS, or WSL2); Windows is not supported. The large dependency tree (67 runtime packages) is typical for a mature development tool and should not be a blocker.

Install

demisto-sdk on PyPI

Before you install

Low friction installation as a pure Python wheel. Active maintenance with a recent release. Requires Python 3.10–3.14, git, and a Unix-like environment (Linux, macOS, or WSL2); Windows is not supported directly.

Requires Python 3.10–3.14, git, and a Unix-like environment (Linux, macOS, or WSL2); Windows is not supported. Some commands require Node.js and npm for markdown validation.

License in practice

MIT license permits commercial and private use with minimal restrictions, making it suitable for both open-source and proprietary development workflows.

Quickstart

pip3 install demisto-sdk
demisto-sdk -h
# Set environment variables for XSOAR/XSIAM connection:
export DEMISTO_BASE_URL=<server-url>
export DEMISTO_API_KEY=<api-key>
demisto-sdk validate

Verify before relying

  • Whether the 67 runtime dependencies introduce significant supply-chain risk or maintenance burden for end users.
  • Performance characteristics when validating large content packs or running integration tests.
  • Availability and quality of documentation for each of the 21 supported commands.

Package facts

LicenseMIT permissive
Python supportSupports the current Python release <3.15,>=3.10
Install frictionLow. Pure-Python wheel
Runtime dependencies
67 packages
autopep8clickbanditmypypylintvulturebeautifulsoup4chardetcoloredlogsconfigparsercoveragedecoratordemisto-pydictordockerflatten-dictgitdbgoogle-cloud-storageinflectionjsonschemamergedeepnetworkxnltkprettytablepykwalifypyspellcheckerrequestsruamel.yamlslack-sdktenacity
MaintenanceActively maintained 11 days since the last release
First released
Downloads114,197 / month, #12,309 on PyPI 30-day window, as of 2026-08-14
Known vulnerabilitiesNone known OSV.dev, checked 2026-08-14
Classifiers
Intended Audience :: DevelopersLicense :: OSI Approved :: MIT LicenseNatural Language :: EnglishProgramming Language :: Python :: 3Programming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Programming Language :: Python :: 3.14Programming Language :: Python :: Implementation :: CPython

Evidence: demisto_sdk-1.39.6-py3-none-any.whl

Tags

Capabilities
cortex xsoar development toolsxsiam integration sdkdemisto content pack validationsecurity orchestration automation sdksoar platform development kitintegration code generatorcontent validation cli
Topics
security-orchestrationintegration-developmentcli-tool

Let your AI agent find packages like this

Example. Real query, live index.

You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.

wish › “cortex xsoar development tools”

  • demisto-sdkA command-line SDK and Python library for developing, validating, and…
  • demisto-pyA Python client library for the Demisto API, enabling programmatic…
  • snowflake-labs-mcpA deprecated MCP server that previously integrated Snowflake Cortex…

Give your agent the search over MCP, or paste the wish link into any chat.

More Build Tools packages

packaging Worth it
PyPI · Build Tools · released Aug 2026

Provides reusable utilities for Python packaging interoperability, including version handling, specifiers, markers, requirements, tags, and metadata parsing according to standards like PEP 440 and PEP 425.

Apache-2.0 OR BSD-2-Clausepure Python · 3.9+
2.2Bdownloads / mo
tqdm Worth it
PyPI · Libraries · released Jul 2026

Wraps any iterable to display a real-time progress bar in the terminal or Jupyter notebook, showing iteration count, elapsed time, and estimated time remaining.

copyleftpure Python · 3.8+
648.6Mdownloads / mo
pip Worth it
PyPI · Build Tools · released Aug 2026

pip is the standard installer for Python packages, enabling you to download and install packages from the Python Package Index and other indexes into your Python environment.

MITpure Python · 3.10+
617.5Mdownloads / mo
hatchling Worth it
PyPI · Python Modules · released Aug 2026

Hatchling is a standards-compliant Python build backend that handles packaging, metadata, and distribution of Python projects when configured in a project's pyproject.toml file.

MITpure Python · 3.10+
484.2Mdownloads / mo
grpcio-tools Worth it
PyPI · Build Tools · released Jul 2026

Generates Python gRPC service stubs and message classes from Protocol Buffer definitions, enabling developers to build gRPC clients and servers.

Apache-2.0compiled wheel · 3.10+
278.2Mdownloads / mo
pre-commit Worth it
PyPI · Build Tools · released Aug 2026

pre-commit is a framework for installing and running git hooks written in any language before commits are made, automating code quality and validation checks across multi-language projects.

Install it if your team needs consistent, automated validation at commit time.

permissive licensepure Python · 3.10+
179.9Mdownloads / mo

See also demisto-py · cycode · actions-toolkit · splitio-client · posthog · snowflake-labs-mcp · rasa-sdk · check-jsonschema · definite-sdk · lpc-checksum