#64 · Primary category: Cybersecurity & Decryption Tools
agent-scan
Security scanner for AI agents, MCP servers and agent skills.
Project last updated:08/28/26
GitHub Stars
3.0K
Forks
262
Contributors
20
License
Apache-2.0
Why we included this project
As teams wire more agents and MCP servers into their workflows, the attack surface those components introduce rarely gets checked. Agent Scan, a CLI from Snyk, builds an inventory of the agent components installed on a machine, covering Claude Code, Cursor, VS Code, Gemini CLI, Windsurf, and similar tools, then scans their configs and skills for prompt injections, tool poisoning, hardcoded secrets, and malware payloads hidden in natural language. It auto-discovers components across system, user, project, and extension scopes, which helps you see what is actually present before adopting a third-party skill or sharing an MCP config. One caveat: scanning an MCP configuration executes the server commands it defines, so run scans in a sandbox or read the consent prompt carefully when evaluating untrusted configs. For engineers responsible for securing agent deployments, that gives an audit-style view of exposure that manual code review does not easily provide.
Articles for this project
No articles for this project yet.
To suggest a topic or contribute an article, contact us.
Related projects in this category
reverse-skill
AI-powered skill router for reverse engineering, authorized penetration testing, and security research, with on-demand toolchain bootstrapping and self-evolving knowledge base.
gitleaks
Find secrets with Gitleaks 🔑
osquery
SQL powered operating system instrumentation, monitoring, and analytics.
NeoPass
Your Essential Exam Companion for the Iamneo Portal & NPTEL Exams Disguised as NeoExamShield bypass
anubis
Weighs the soul of incoming HTTP requests to stop AI crawlers