Project overview
Snyk Agent Scan finds MCP configurations and Agent Skills used by tools such as Claude, Cursor, Windsurf, and Gemini CLI, then checks for prompt injection, tool poisoning, tool shadowing, malicious payloads, unsafe credential handling, and hardcoded secrets. It runs directly through uvx. Scanning a stdio MCP server executes its configured command, so review the command and approve it only through the consent prompt.
Repository facts
- Primary language
- Python
- License
- Apache-2.0
- Repository updated
- Jul 14, 2026
- Default branch
- main
Resource types
CLI app
Use cases
Security and privacy
Platforms
Claude CodeCursorGemini CLIOpenClawVS Code
Runtime
Command lineLocal
Protocols & integrations
Model Context Protocol
Capabilities
Security guardrail
Audience
Security engineers