Vibe Coding Discover

AI Tools

agent-scan

View on GitHub

Security scanner for AI agents, MCP servers and agent skills.

★ 3.1K278 forksPythonApache-2.0snyk

Snyk Agent Scan is a Python CLI that discovers installed AI agent components (agents, MCP servers, and skills) on a machine and scans them for prompt injection, tool poisoning, malware payloads, and secret leakage. It auto-detects configs from Claude, Cursor, Copilot, Windsurf, Gemini CLI, and others.

Use Cases

Scan local MCP server configs for prompt injection and tool poisoningAudit installed agent skills for malware payloads and unsafe credential handlingDiscover agent components (harnesses, MCP servers, skills) across Claude, Cursor, Copilot, Windsurf, Gemini CLI, CodexDetect hardcoded secrets and sensitive data exposure in agent configsRun agent supply chain security checks in CI pipelinesSandboxed evaluation of untrusted third-party MCP configurationsEnterprise-wide agent security risk management with Snyk Evo

Built With

Language
Python
Frameworks
MCP · pydantic · rich · aiohttp · lark · pytest

Tags

security · supply-chain-security · mcp · prompt-injection · agent-skills · scanner · cli · llm-security · ai-security · static-analysis · secrets-detection · tool-poisoning · vulnerability-scanning · python