Snyk Agent Scan
Major security vendor (Snyk) backing gives enterprise credibility. Auto-discovers all agent configurations on a machine and scans skills and MCP servers.
Auto-discovers agent configurations across Claude Code, Cursor, Gemini CLI, and Windsurf. Detects 15+ security risks including prompt injection, tool poisoning, and toxic flows.
- Scan all AI agent configurations on developer machines for security risks
- Detect prompt injection and tool poisoning in skills before installation
- Monitor agent configurations continuously for security drift
Major security vendor (Snyk) backing gives enterprise credibility. Auto-discovers all agent configurations on a machine and scans skills and MCP servers.
Security teams responsible for approving AI tools across developer workstations.
https://github.com/snyk/agent-scan
By Snyk
How to Get It
uvx snyk-agent-scan@latest
Tip: Paste this into a Claude Code conversation. Verify command matches your Claude Code version.
After installing, paste this into Claude:
Help me scan all AI agent configurations on developer machines for security risks
Trust Signals Auto-scanned
Data & Access
Community Pulse Active
Discussed on Hacker News, Reddit
- 10.27.2025 - West Chicago: ICE Agents Scan Driver's Biometrics Without Warrant, — Reddit · 42873 pts
- ICE agents chased down these two kids on their bikes and asked them where they w — Reddit · 21449 pts
- ICE agents chased down these two kids on their bikes and asked them where they w — Reddit · 3835 pts
3 mentions across 1 sources
Reviewer notes
Auto-scanned review. These are observations, not a security certification.
catalog_hygiene stale-eval refresh: Scored from trust signals (evidence-eval-v1): 2,761 GitHub stars; 15 contributors; last commit 1d ago; license Apache-2.0.
Things to check
- Scanning MCP configurations executes the commands defined in them — Agent Scan starts each stdio MCP server to retrieve tool descriptions for analysis. Snyk recommends running scans in a sandbox (container or VM) when evaluating untrusted configs; interactive runs ask consent per server. CLI output format is experimental and may change between releases. Detection covers configuration artifacts and tool descriptions, not live runtime behavior.
How to evaluate tools before deploying →
Data shown here comes from public APIs and automated scanning. Reviewer notes reflect one person's experience. This is not a security certification or legal recommendation. Always evaluate tools according to your own organization's policies.
Evaluation
catalog_hygiene stale-eval refresh: Scored from trust signals (evidence-eval-v1): 2,761 GitHub stars; 15 contributors; last commit 1d ago; license Apache-2.0.