Best for
- Security teams to monitor company-wide agent supply chain risk
- Developers to quickly assess security of their MCP servers and skills
- Evaluating third-party MCP configs in sandboxed environments
Agent Scan is a security scanning tool by Snyk focused on detecting vulnerabilities in AI agents and MCP servers. It supports multiple agents and provides a detailed detection coverage matrix. The tool emphasizes the risk of executing commands during MCP config scanning and recommends sandboxing. Due to experimental CLI output, it is not suitable for automated dependencies.
Agent Scan is a security scanning tool that discovers and scans agent components on your machine, including MCP servers and skills, for common threats such as prompt injections, sensitive data handling, or malware payloads hidden in natural language. It automatically discovers configurations for various agents including Claude Code/Desktop, Cursor, Gemini CLI, and Windsurf. The tool supports Scan Mode (CLI scan with report) and Background Mode (periodic scans reported to Snyk Evo). Note: scanning MCP configurations executes the commands defined in them, so it is recommended to run in a sandbox and carefully review consent prompts.
Or download a standalone binary from GitHub Releases.