Ross ROSS = Recommend OSS · open-source software intelligence for agents

snyk/agent-scan

Security scanner for AI agents, MCP servers and agent skills. observed · 2026-08-28

github.com/snyk/agent-scan · Python · Apache-2.0 (permissive) observed · 2026-08-28

Health v2 · maintenance only

82/100

  • Activity 99
  • Release rhythm 86
  • Longevity 36
How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: 3
  • age_days: 513
  • days_rel: 14
  • days_push: 7
  • n_releases_24m: 66

Full methodology

Adoption not part of the score

2958 stars · 260 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

Snyk Agent Scan is a Python-based CLI security scanner that discovers installed AI agent components (agent harnesses, MCP servers, and agent skills) on a machine and scans them for threats like prompt injections, sensitive data handling, and malware hidden in natural language. It is developed by Snyk and distributed via uvx or standalone binaries.

Use cases

  • scan MCP servers for prompt injection vulnerabilities
  • audit installed agent skills for malware payloads
  • discover AI agent components on my machine
  • check agent harnesses for sensitive data handling risks
  • security scan my model context protocol setup
  • vet third-party agent skills before installing them

When to choose

  • you install or develop MCP servers or agent skills and want to detect prompt injections and hidden malware
  • you want a quick local CLI audit of all agent components on a machine
  • you are evaluating AI agent supply-chain risk before adopting tools

When to avoid

  • you need stable CLI output fields or issue codes for production automation, since output is experimental and may change
  • you need continuous enterprise-scale agent security management rather than local scanning
  • you need a non-Python or npm-distributed tool

Facets

cli-tool · maturity experimental

security vulnerability-scanning cli developer-tools security developer-tools large-language-models cli python cross-platform windows mcp agent-security prompt-injection sast ai-supply-chain snyk ai-agents macos linux

1 source

Member repositories

RepositoryRoleHealth v2
snyk/agent-scanmain82

For agents

markdown · JSON · MCP: product_card(name="snyk/agent-scan")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem