Prompt injection
Flag hidden instructions in prompts, docs, tool descriptions, and retrieved context.
Local scanner · Coding agent security
Scan Claude Code, Codex, Cursor, Windsurf, Cline, OpenCode, MCP servers, prompts, skills, and AI-suggested dependencies before your agent trusts them.
Claude Code
Coding agent
Codex
OpenAI coding agent
Cursor
AI editor
Windsurf
AI editor
Cline
Coding agent
OpenCode
Coding agent
MCP servers
Tools and resources
Prompts
Instructions and context
Skills
Agent extensions
AI dependencies
Suggested packages
One local security gate
Inputs
Detection engine
Run from the developer workstation, CI, or as an MCP tool.
npx agent-security-scanner-mcp scan-project .Findings
Agent-specific coverage
Flag hidden instructions in prompts, docs, tool descriptions, and retrieved context.
Check AI-suggested imports before an attacker can claim a fabricated package name.
Find credentials, tokens, and sensitive configuration before they reach a commit.
Inspect tool poisoning, spoofed names, command execution, and excessive permissions.
Detect injection, unsafe execution, tainted data flows, and insecure generated code.
Start on your laptop
Install the open-source scanner and add a security gate to your coding-agent workflow.
Download open source