#122 · Primary category: Cybersecurity & Decryption Tools

medusa

agent-security ai-security code-analysis cve-detection devsecops llm-security mcp nextjs open-source python react sast scanner security security-tools static-analysis vulnerability-scanner

AI-first security scanner with 40,000+ patterns for detecting vulnerabilities in AI/ML, LLM agents, MCP servers, and traditional code, including Claude Code compromise and leaked secrets.

Project last updated:08/10/26

GitHub Stars

971

Forks

153

Contributors

2

License

AGPL-3.0

Why we included this project

Anyone shipping code that touches LLM agents, MCP servers, or AI-assisted workflows is trusting a growing pile of third-party components, and that trust carries a class of risk older scanners were never built to catch: poisoned repositories, leaked API keys sitting in prompt history, and compromised coding hooks. MEDUSA is a scanner aimed squarely at that gap, with more than 40,000 detection patterns that cover AI supply chain attacks alongside familiar targets like Log4Shell and Spring4Shell. You can point it at a repository to learn what you are about to clone, scan your Claude or Cursor setup for exposed keys and suspicious hooks, or run a plain scan over an existing codebase with no configuration. It installs from PyPI as a single command-line tool, so a small team without a dedicated security engineer can screen what it is about to rely on without much ceremony.

Articles for this project

No articles for this project yet.

To suggest a topic or contribute an article, contact us.

Related projects in this category