agent-scan
Scan local agents, MCP servers, and skills for security risks.
- Stars
- 2,778
- Forks
- 246
- Updated
- Updated Jul 14, 2026
Scan local agents, MCP servers, and skills for security risks.
Snyk Agent Scan finds MCP configurations and Agent Skills used by tools such as Claude, Cursor, Windsurf, and Gemini CLI, then checks for prompt injection, tool poisoning, tool shadowing, malicious payloads, unsafe credential handling, and hardcoded secrets. It runs directly through uvx. Scanning a stdio MCP server executes its configured command, so review the command and approve it only through the consent prompt.
Resource types
Use cases
Platforms
Scan agent skills for malicious instructions, unsafe code, and supply-chain risks
Audit agent skills for commands, network access, secrets, and tools without executing them.
Runtime
Protocols & integrations
Capabilities
Audience
Public GitHub facts last synced Jul 14, 2026.
Scan Claude Skills for risky network, file, command, and injection patterns.
Prove which AI agent wrote each line of code with signed Git records.