EveryDev.ai
Subscribe
Home
Tools

3,419+ AI tools

  • New
  • Trending
  • Featured
  • Compare
  • Arena
Categories
  • Agents2189
  • Coding1574
  • Infrastructure698
  • Marketing534
  • Projects498
  • Research456
  • Design416
  • Analytics389
  • Testing296
  • MCP290
  • Security286
  • Data262
  • Integration197
  • Prompts189
  • Communication183
  • Extensions173
  • Learning170
  • Voice151
  • Commerce135
  • DevOps123
  • Web86
  • Finance26
AI Tools by Topic
  • AI Coding Assistants
  • Agent Frameworks
  • MCP Servers
  • AI Prompt Tools
  • Vibe Coding Tools
  • AI Design Tools
  • AI Database Tools
  • AI Website Builders
  • AI Testing Tools
  • LLM Evaluations
Follow Us
  • X / Twitter
  • LinkedIn
  • Reddit
  • Discord
  • Threads
  • Bluesky
  • Mastodon
  • YouTube
  • GitHub
  • Instagram
Get Started
  • About
  • Editorial Standards
  • Corrections & Disclosures
  • Community Guidelines
  • Advertise
  • Contact Us
  • Newsletter
  • Submit a Tool
  • Start a Discussion
  • Write A Blog
  • Share A Build
  • Terms of Service
  • Privacy Policy
Explore with AI
  • ChatGPT
  • Gemini
  • Claude
  • Grok
  • Perplexity
Agent Experience
  • llms.txt
Theme
With AI, Everyone is a Dev. EveryDev.ai © 2026
    1. Home
    2. Tools
    3. Snyk Agent Scan
    Snyk Agent Scan icon

    Snyk Agent Scan

    Application Security
    Featured

    An open-source CLI security scanner that discovers and scans AI agent components—including MCP servers, agent harnesses, and skills—for prompt injections, tool poisoning, and other vulnerabilities.

    Visit Website

    At a Glance

    Pricing
    Open Source

    Free to use under the Apache License 2.0. Requires a Snyk API token (free Snyk account) for cloud-backed analysis.

    Engagement

    Available On

    Windows
    macOS
    Linux
    API
    VS Code

    Resources

    WebsiteDocsGitHubllms.txt

    Topics

    Application SecurityMCP ServersAgent Frameworks

    Alternatives

    PanGuard AISkillSpectorSuperagent SDK
    Developer
    SnykBoston, MAEst. 2015$1.32B raised

    Listed Aug 2026

    About Snyk Agent Scan

    Snyk Agent Scan is an open-source command-line tool published by Snyk (originally developed by Invariant Labs AG) under the Apache License 2.0. It auto-discovers AI agent components installed on a machine—MCP servers, agent harnesses, and agent skills—and scans them for security threats including prompt injections, tool poisoning, toxic flows, malware payloads, and hardcoded secrets. The project reached v0.5.16 as of August 2026 and has accumulated over 2,800 GitHub stars.

    What It Is

    Snyk Agent Scan is a security scanner purpose-built for the emerging AI agent supply chain. As developers increasingly install MCP servers and agent skills from third-party sources, those components can carry hidden threats embedded in natural language—tool descriptions, prompts, and skill files that instruct an AI to behave maliciously. Agent Scan addresses this gap by connecting to MCP servers, retrieving their tool descriptions, and running both local checks and cloud-backed analysis via the Snyk Agent Scan API to surface 15+ distinct security risk categories.

    Detection Coverage

    Agent Scan detects a broad set of agent-specific threats across two main component types:

    • MCP servers: Prompt Injection, Tool Poisoning, Tool Shadowing, Toxic Flows
    • Agent skills: Prompt Injection, Malware Payloads, Untrusted Content, Credential Handling, Hardcoded Secrets

    Auto-discovery covers a wide range of popular AI coding environments across macOS, Linux, and Windows, including Windsurf, Cursor, VS Code, Claude Desktop, Claude Code, Gemini CLI, Amp, Amazon Q, Kiro, OpenCode, Antigravity, and Codex. Detection spans system-wide, user, project/workspace, and extension/plugin configuration scopes.

    How Scanning Works

    Agent Scan operates in two modes:

    1. Scan Mode — The default CLI command scans the local machine, auto-discovers agent configurations, connects to MCP servers (executing their startup commands to retrieve tool descriptions), and produces a comprehensive security report.
    2. Background Mode (MDM) — Runs on a schedule and reports results to a Snyk Evo enterprise instance, enabling security teams to monitor the company-wide agent supply chain centrally.

    A key security consideration: scanning MCP configurations requires executing the commands defined in them. By default, Agent Scan prompts for explicit user consent before starting each stdio MCP server, showing the exact command and arguments. For CI/CD pipelines, the --dangerously-run-mcp-servers flag bypasses this prompt and should only be used in fully trusted environments.

    Deployment and Setup

    Agent Scan can be run two ways:

    • Python package via uvx: uvx snyk-agent-scan@latest — requires uv and a Snyk API token set as SNYK_TOKEN
    • Standalone binary: Pre-built binaries for each platform are available on GitHub Releases, with GPG-signed checksums and SBOMs for supply chain verification

    The tool supports scanning specific MCP config files, individual skill files, or entire skill directories in addition to full machine auto-discovery. JSON output mode and CI flags make it suitable for integration into automated pipelines.

    Update: Agent Scan v0.5.16

    The latest release is v0.5.16, published August 3, 2026. Version 0.4 introduced agent skills scanning alongside a published technical report on emerging threats in the agent skill ecosystem. The CLI output is explicitly marked experimental and subject to change between releases, while the underlying enterprise integration with Snyk Evo is described as stable. The project does not accept external code contributions but welcomes bug reports and feature requests via GitHub Issues.

    Snyk Agent Scan - 1

    Community Discussions

    Be the first to start a conversation about Snyk Agent Scan

    Share your experience with Snyk Agent Scan, ask questions, or help others learn from your insights.

    Pricing

    OPEN SOURCE

    Open Source

    Free to use under the Apache License 2.0. Requires a Snyk API token (free Snyk account) for cloud-backed analysis.

    • Auto-discovery of MCP servers and agent skills
    • 15+ security risk detections
    • JSON output and CI/CD integration
    • Standalone binary with GPG-signed checksums
    • SBOM included in releases

    Capabilities

    Key Features

    • Auto-discover MCP configurations, agent tools, and skills
    • Scan for 15+ distinct security risks across MCP servers and agent skills
    • Detect prompt injection, tool poisoning, tool shadowing, and toxic flows
    • Detect malware payloads, hardcoded secrets, and credential handling issues in skills
    • Interactive consent prompt before executing MCP server commands
    • Background MDM mode for enterprise-wide agent supply chain monitoring
    • JSON output for programmatic parsing and CI/CD integration
    • Standalone binary distribution with GPG-signed checksums and SBOM
    • Supports Claude, Cursor, Windsurf, VS Code, Gemini CLI, Amazon Q, and more
    • Inspect mode to view tool descriptions without running security checks
    • Scan specific MCP config files, skill files, or skill directories

    Integrations

    Claude Desktop
    Claude Code
    Cursor
    Windsurf
    VS Code
    Gemini CLI
    Amazon Q
    Amp
    Kiro
    OpenCode
    Antigravity
    Codex
    OpenClaw
    Snyk Evo
    PyPI (snyk-agent-scan)
    uv / uvx
    API Available
    View Docs

    Ratings & Reviews

    No ratings yet

    Be the first to rate Snyk Agent Scan and help others make informed decisions.

    Developer

    Snyk

    Snyk builds an AI-powered application security platform that embeds security into developer workflows and the SDLC. The company combines security research and AI models to deliver fast, accurate vulnerability detection across code, open source, containers, and IaC. Snyk's team includes security researchers and engineers focused on developer-first tooling and automation to simplify remediation and compliance.

    Founded 2015
    Boston, MA
    $1.32B raised
    1,854 employees

    Used by

    Google
    Salesforce
    Intuit
    MongoDB
    +4 more
    Read more about Snyk
    WebsiteGitHubX / Twitter
    2 tools in directory

    Similar Tools

    PanGuard AI icon

    PanGuard AI

    Open-source AI agent security platform that audits skills before install, monitors agent behavior at runtime, and shares threat intelligence via the ATR open standard.

    SkillSpector icon

    SkillSpector

    Open-source security scanner for AI agent skills that detects vulnerabilities, malicious patterns, and security risks before installation using static analysis and optional LLM evaluation.

    Superagent SDK icon

    Superagent SDK

    Open-source SDK for AI agent safety that blocks prompt injections, redacts PII, and scans repositories for threats.

    Browse all tools

    Related Topics

    Application Security

    AI tools for securing software applications and identifying vulnerabilities.

    104 tools

    MCP Servers

    Model Context Protocol servers that extend AI capabilities.

    168 tools

    Agent Frameworks

    Tools and platforms for building and deploying custom AI agents.

    577 tools
    Browse all topics
    Back to all toolsSuggest an edit
    ratings
    discussions