agent-scan
Scan AI agents, MCP servers, and skills for hidden security threats
All Skills in This Repository (17)
Pure Emerald Level Indicatorstest-skill
Load and process a basic skill unit to verify the execution environment.
theme-factory
Apply pre-designed or custom-generated themes to slides, documents, and HTML pages.
doc-coauthoring
Guide structured co-authoring of technical specs, proposals, and decision docs.
xlsx
Create and edit Excel spreadsheets with formulas and pandas analysis.
Extract text and structured data from PDF documents using pypdf and pdfplumber.
algorithmic-art
Generate p5.js algorithmic art with seeded randomness and interactive parameters.
internal-comms
Generate internal company communications using templates for updates, newsletters, and FAQs.
skill-creator
Guide developers through creating and structuring AI skills with SKILL.md.
canvas-design
Generate original visual art and design philosophies in PNG and PDF formats.
pptx
Automates creation, editing, and analysis of PowerPoint .pptx presentations via OOXML manipulation and HTML-to-PPTX conversion.
slack-gif-creator
Generates Slack-optimized animated GIFs with custom animations, frame composition, and color quantization.
webapp-testing
Test local web applications with Playwright scripts and capture screenshots.
Frequently Asked Questions
FAQPage SchemaHow to install Agent Scan?โผ
Run `npx skills add snyk/agent-scan --all -g -y` in your terminal to install all tools in this suite globally.
What does Agent Scan detect?โผ
It detects over 15 security risks including prompt injection, tool poisoning, malicious code, hardcoded secrets, and insecure credential handling in MCP servers and agent skills.
Which AI agents does Agent Scan support?โผ
It auto-discovers configurations for Claude Code, Claude Desktop, Cursor, VS Code, Windsurf, Gemini CLI, OpenClaw, Kiro, Codex, Amazon Q, and more across macOS, Linux, and Windows.
Is it safe to scan unknown MCP configurations?โผ
Scanning starts the MCP servers defined in a config, so you should run scans inside a sandbox or Docker container when evaluating untrusted third-party configurations.
Do I need a Snyk account to use Agent Scan?โผ
Yes. You need a free Snyk API token from app.snyk.io, which you set as the SNYK_TOKEN environment variable before running any scan.
Related Repositories in Software Engineering
View All in Software Engineeringโopenclaw
Run a personal AI assistant across your devices and chat apps
superpowers
Gives coding agents a disciplined workflow from idea to merged code
react
AI agent skills for building, testing, and porting React core