BrowseFull catalogOutcomesSolve a specific problemRolesStack by teamTrustFilter by risk tier
← Back to the Claude Observatory

dev-machine-guard

Skill Development Usable
Works inClaude Code
Usable Scanned — metadata only

Unvetted AI agents and extensions in developer environments create supply-chain and credential-exposure risks that traditional security scanning misses.

Scan your dev machine for AI agents, MCP servers, IDE extensions, and suspicious packages - in seconds.

175 starsApache-2.0 (commercial OK)FreeQuick setup
Usable rating — This tool is functional but has notable gaps. Review the evaluation notes below before deploying.

Unvetted AI agents and extensions in developer environments create supply-chain and credential-exposure risks that traditional security scanning misses. This tool surfaces those blind spots quickly, reducing unauthorized access vectors before they reach production systems.

Security teams and engineering leads auditing developer workstations for third-party tool integrations and dependency risks.

Claude Code Claude Cowork Claude Chat

https://github.com/step-security/dev-machine-guard

By step-security

How to Get It

Option 1: Claude Desktop App (Code Mode)Click the + button next to the prompt box → PluginsAdd plugin. Search and click Install. Skills work in Claude Code only.
Option 2: Paste into Claude CodeCopy the command below and paste it into your conversation. Claude will install it.
Command
claude plugins install step-security/dev-machine-guard

Tip: Paste this into a Claude Code conversation. Verify command matches your Claude Code version.

Auto-generated from the tool's public listing — not hands-on verified. Cross-check against the source repo's README before running.

First thing to try

After installing, paste this into Claude:

Help me scan my development machine for unauthorized AI agents and MCP servers quickly
CostFree

Trust Signals Auto-scanned

Stars175Contributors8Last updated2026-09-11LicenseApache-2.0 (OK for commercial use)Known CVEsNone foundSources: GitHub Advisory Database + OSV.dev · Scanned 2026-09-11 · scanner v1

Community Pulse Growing

Discussed on Hacker News

1 mentions across 1 sources

Reviewer notes

Auto-scanned review. These are observations, not a security certification.

Scored from trust signals (evidence-eval-v1): 175 GitHub stars; contributors unknown; last commit 0d ago; license Apache-2.0.

Things to check

  • Scanned, not hands-on tested — this entry was auto-scanned from public metadata (GitHub metrics, license, security flags). No reviewer has run it, and no tool-specific limitations have been documented yet.

How to evaluate tools before deploying →

Data shown here comes from public APIs and automated scanning. Reviewer notes reflect one person's experience. This is not a security certification or legal recommendation. Always evaluate tools according to your own organization's policies.

Evaluation

Ease of Use
3/5
Versatility
3/5
Reliability
3/5
Security
3/5
Overall score3.00 / 5.00 UsableEvaluatedSep 2026
Scored from trust signals (evidence-eval-v1): 175 GitHub stars; contributors unknown; last commit 0d ago; license Apache-2.0.

← Back to the Claude Observatory

Rolling Claude out in your org? Let's talk.

Start a conversation →