BrowseFull catalogOutcomesSolve a specific problemRolesStack by teamTrustFilter by risk tier
← Back to the Claude Observatory

Snyk Agent Scan

Skill Security Solid
Works inClaude Code
Solid Scanned — metadata only

Major security vendor (Snyk) backing gives enterprise credibility. Auto-discovers all agent configurations on a machine and scans skills and MCP servers.

Auto-discovers agent configurations across Claude Code, Cursor, Gemini CLI, and Windsurf. Detects 15+ security risks including prompt injection, tool poisoning, and toxic flows.

2,798 starsApache-2.0 (commercial OK)FreeQuick setup
Official tool maintained by Snyk.

Major security vendor (Snyk) backing gives enterprise credibility. Auto-discovers all agent configurations on a machine and scans skills and MCP servers.

Security teams responsible for approving AI tools across developer workstations.

Claude Code Claude Cowork Claude Chat

https://github.com/snyk/agent-scan

By Snyk

How to Get It

Option 1: Claude Desktop App (Code Mode)Click the + button next to the prompt box → PluginsAdd plugin. Search and click Install. Skills work in Claude Code only.
Option 2: Paste into Claude CodeCopy the command below and paste it into your conversation. Claude will install it.
Command
uvx snyk-agent-scan@latest

Tip: Paste this into a Claude Code conversation. Verify command matches your Claude Code version.

First thing to try

After installing, paste this into Claude:

Help me scan all AI agent configurations on developer machines for security risks
PrerequisitesSnyk account with an API token (export SNYK_TOKEN before scanning); uv installed — the tool runs via uvx, no separate install step.CostFree

Trust Signals Auto-scanned

Stars2,798Contributors17Last updated2026-07-21LicenseApache-2.0 (OK for commercial use)Known CVEsNone foundSources: GitHub Advisory Database + OSV.dev · Scanned 2026-07-21 · scanner v1

Data & Access

Connects toSnyk servers (official integration)

Community Pulse Active

Discussed on Hacker News, Reddit

3 mentions across 1 sources

Reviewer notes

Auto-scanned review. These are observations, not a security certification.

catalog_hygiene stale-eval refresh: Scored from trust signals (evidence-eval-v1): 2,761 GitHub stars; 15 contributors; last commit 1d ago; license Apache-2.0.

Things to check

  • Scanning MCP configurations executes the commands defined in them — Agent Scan starts each stdio MCP server to retrieve tool descriptions for analysis. Snyk recommends running scans in a sandbox (container or VM) when evaluating untrusted configs; interactive runs ask consent per server. CLI output format is experimental and may change between releases. Detection covers configuration artifacts and tool descriptions, not live runtime behavior.

How to evaluate tools before deploying →

Data shown here comes from public APIs and automated scanning. Reviewer notes reflect one person's experience. This is not a security certification or legal recommendation. Always evaluate tools according to your own organization's policies.

Evaluation

Ease of Use
4/5
Versatility
5/5
Reliability
4/5
Security
4/5
Overall score4.25 / 5.00 SolidEvaluatedJul 2026
catalog_hygiene stale-eval refresh: Scored from trust signals (evidence-eval-v1): 2,761 GitHub stars; 15 contributors; last commit 1d ago; license Apache-2.0.

← Back to the Claude Observatory

Rolling Claude out in your org? Let's talk.

Start a conversation →