Local scanner · Coding agent security

Make your Coding Agents secure.

Scan Claude Code, Codex, Cursor, Windsurf, Cline, OpenCode, MCP servers, prompts, skills, and AI-suggested dependencies before your agent trusts them.

Open source MIT licensed Local scan path

Claude Code

Coding agent

Codex

OpenAI coding agent

Cursor

AI editor

Windsurf

AI editor

Cline

Coding agent

OpenCode

Coding agent

MCP servers

Tools and resources

Prompts

Instructions and context

Skills

Agent extensions

AI dependencies

Suggested packages

One local security gate

Agents and artifacts in. Prioritized findings out.

Inputs

Coding agents
MCP servers
Prompts and skills
Code and packages

Detection engine

agent-security-scanner-mcp

Run from the developer workstation, CI, or as an MCP tool.

npx agent-security-scanner-mcp scan-project .

Findings

Severity
Affected file
Rule and evidence
Remediation

Agent-specific coverage

Catch what conventional code scanning misses.

Prompt injection

Flag hidden instructions in prompts, docs, tool descriptions, and retrieved context.

Hallucinated packages

Check AI-suggested imports before an attacker can claim a fabricated package name.

Exposed secrets

Find credentials, tokens, and sensitive configuration before they reach a commit.

Unsafe MCP tools

Inspect tool poisoning, spoofed names, command execution, and excessive permissions.

Vulnerable code

Detect injection, unsafe execution, tainted data flows, and insecure generated code.

Start on your laptop

Scan before the next agent action.

Install the open-source scanner and add a security gate to your coding-agent workflow.

Download open source