Vibe Coding Discover

AI Tools

Open-source antivirus for AI agents: block risky tools, secret access, prompt injection, malicious packages, MCP servers, plugins, and skills at runtime.

★ 670106 forksPythonApache-2.0hashgraph-online

Local-first runtime security for AI agents: hooks and MCP proxies that classify shell commands, file access, package installs and tool calls, then allow, block or request approval. Also ships plugin-scanner, a CLI/CI scanner for agent plugins, skills and MCP servers.

Use Cases

Block risky shell commands and file access from AI coding agents before executionDetect and redact secret/credential exposure in agent tool callsScreen prompts and tool results for prompt injectionScan and police MCP server configuration and MCP tool callsScan, lint and verify agent plugins, skills and MCP packages before publishingSupply-chain scanning of package installs (npm/PyPI advisories) before installGenerate an AI bill of materials (ABOM) and audit receipts for agent actionsApproval workflows routing risky agent actions to a human approval centerCI/GitHub Actions plugin security scanning with SARIF outputRuntime policy enforcement across Claude Code, Cursor, Codex, Gemini CLI, OpenClaw and OpenCode

Built With

Language
Python
Frameworks
Model Context Protocol (MCP) · Cisco AI Skill Scanner · litellm · FastAPI · Playwright · Vite · hatchling · pytest

Tags

agent-security · mcp-security · ai-antivirus · prompt-injection · secrets-detection · supply-chain-security · runtime-security · devsecops · plugin-security · skill-security · cli · claude-code · cursor · codex · gemini-cli · sarif