dev-machine-guard
Unvetted AI agents and extensions in developer environments create supply-chain and credential-exposure risks that traditional security scanning misses.
Scan your dev machine for AI agents, MCP servers, IDE extensions, and suspicious packages - in seconds.
- Scan your development machine for unauthorized AI agents and MCP servers quickly
- Identify suspicious IDE extensions and malicious packages before they cause damage
- Audit your team's dev machines for security risks during onboarding or compliance reviews
Unvetted AI agents and extensions in developer environments create supply-chain and credential-exposure risks that traditional security scanning misses. This tool surfaces those blind spots quickly, reducing unauthorized access vectors before they reach production systems.
Security teams and engineering leads auditing developer workstations for third-party tool integrations and dependency risks.
https://github.com/step-security/dev-machine-guard
By step-security
How to Get It
claude plugins install step-security/dev-machine-guard
Tip: Paste this into a Claude Code conversation. Verify command matches your Claude Code version.
Auto-generated from the tool's public listing — not hands-on verified. Cross-check against the source repo's README before running.
After installing, paste this into Claude:
Help me scan my development machine for unauthorized AI agents and MCP servers quickly
Trust Signals Auto-scanned
Community Pulse Growing
Discussed on Hacker News
- Show HN: Scan your dev machine for AI agents, MCP servers, and IDE extensions — Hacker News · 9 pts
1 mentions across 1 sources
Reviewer notes
Auto-scanned review. These are observations, not a security certification.
Scored from trust signals (evidence-eval-v1): 175 GitHub stars; contributors unknown; last commit 0d ago; license Apache-2.0.
Things to check
- Scanned, not hands-on tested — this entry was auto-scanned from public metadata (GitHub metrics, license, security flags). No reviewer has run it, and no tool-specific limitations have been documented yet.
How to evaluate tools before deploying →
Data shown here comes from public APIs and automated scanning. Reviewer notes reflect one person's experience. This is not a security certification or legal recommendation. Always evaluate tools according to your own organization's policies.
Evaluation
Scored from trust signals (evidence-eval-v1): 175 GitHub stars; contributors unknown; last commit 0d ago; license Apache-2.0.