by sinewaveai
Security scanner MCP server for AI coding agents. Prompt injection firewall, package hallucination detection (4.3M+ packages), 1000+ vulnerability rules with AST & taint analysis, auto-fix.
# Add to your Claude Code skills
git clone https://github.com/sinewaveai/agent-security-scanner-mcpGuides for using ai agents skills like agent-security-scanner-mcp.
Last scanned: 5/30/2026
{
"issues": [
{
"type": "npm-audit",
"message": "express-rate-limit: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "ip-address: ip-address has XSS in Address6 HTML-emitting methods",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "path-to-regexp: path-to-regexp vulnerable to Denial of Service via sequential optional groups",
"severity": "high"
},
{
"type": "npm-audit",
"message": "picomatch: Picomatch: Method Injection in POSIX Character Classes causes incorrect Glob Matching",
"severity": "high"
},
{
"type": "npm-audit",
"message": "qs: qs has a remotely triggerable DoS: qs.stringify crashes with TypeError on null/undefined entries in comma-format arrays when encodeValuesOnly is set",
"severity": "medium"
}
],
"status": "WARNING",
"scannedAt": "2026-05-30T16:38:17.441Z",
"npmAuditRan": true,
"pipAuditRan": false
}agent-security-scanner-mcp is an open-source ai agents skill for AI coding assistants such as Claude Code, Codex CLI, and ChatGPT, built by sinewaveai. Security scanner MCP server for AI coding agents. Prompt injection firewall, package hallucination detection (4.3M+ packages), 1000+ vulnerability rules with AST & taint analysis, auto-fix. It has 115 GitHub stars.
agent-security-scanner-mcp returned warnings in SkillsLLM's automated security scan. It has no critical vulnerabilities, but review the flagged issues in the Security Report section before adding it to your workflow.
Clone the repository with "git clone https://github.com/sinewaveai/agent-security-scanner-mcp" and add it to your Claude Code skills directory (see the Installation section above).
agent-security-scanner-mcp is primarily written in JavaScript. It is open-source under sinewaveai on GitHub, so you can review or fork the full source.
Yes. SkillsLLM lists many other AI Agents skills you can browse and compare side by side. Open the AI Agents category from the badge at the top of this page, or use the Related Skills and comparison links further down to weigh agent-security-scanner-mcp against similar tools.
No comments yet. Be the first to share your thoughts!
Requires a passing catalog security scan. Resolve the flagged issues and resubmit to enable featuring.
npm audit for AI agents and MCP servers
Scan code, MCP tools, prompts, skills, and AI-suggested dependencies before your agent trusts them. Built for Claude Code, Cursor, Windsurf, Cline, OpenClaw, and CI/CD.
Run the agent security smoke test on any repo:
npx agent-security-scanner-mcp scan-project . --verbosity compact
Or get repo-specific next steps first:
npx agent-security-scanner-mcp quickstart --client claude-code
Generate public-safe copy for a launch post, GitHub issue, or directory listing:
npx agent-security-scanner-mcp share-kit --client claude-code
Install it into your AI coding client:
npx agent-security-scanner-mcp init claude-code
Replace claude-code with cursor, claude-desktop, windsurf, cline, kilo-code, opencode, or cody.
Add the GitHub Actions workflow:
npx agent-security-scanner-mcp init-ci github
# Check the whole project and get an A-F security grade
npx agent-security-scanner-mcp scan-project . --verbosity compact
# Audit an MCP server before adding it to Claude/Cursor/Windsurf
npx agent-security-scanner-mcp scan-mcp ./path/to/mcp-server --verbosity compact
# Try an MCP audit demo with tool poisoning and command-exec findings
npx agent-security-scanner-mcp demo --type mcp --no-prompt
# Verify AI-suggested imports are real packages, not hallucinations
npx agent-security-scanner-mcp scan-packages ./src/app.ts npm --verbosity compact
# Check one package before installing it
npx agent-security-scanner-mcp check-package express npm
# Add a local environment health check
npx agent-security-scanner-mcp doctor
# Add the scanner to your AI client
npx agent-security-scanner-mcp init claude-code
Ultra-fast, zero-Python security scanner — 81.5KB package, 4-second install
npm install -g @prooflayer/security-scanner
Enterprise-grade scanner with AST analysis, taint tracking, cross-file analysis, and LLM-powered semantic review
npm install -g agent-security-scanner-mcp
Continue reading below for full version documentation →
New in v4.4.11 (2026-07-11): Share kit generator — run
npx agent-security-scanner-mcp share-kit --client cursorto generate public-safe launch copy, a GitHub issue template, directory listing text, and repo-specific commands for sharing an agent-security smoke test.New in v4.4.10 (2026-07-10): Quickstart planner — run
npx agent-security-scanner-mcp quickstart --client cursorto get repo-specific scan, MCP audit, SBOM, CI, and AI-client setup commands before choosing what to run.New in v4.4.9 (2026-07-08): MCP audit demo — run
npx agent-security-scanner-mcp demo --type mcp --no-promptto create and scan a tiny MCP server with tool poisoning, tool-name spoofing, command execution, secret exposure, and missing-validation findings.New in v4.4.8 (2026-07-07): Package hallucination demo — run
npx agent-security-scanner-mcp demo --type packages --no-promptto create and scan a tiny import file with real and fake npm packages. README examples now show both single-package verification and import scanning.New in v4.4.7 (2026-07-07): CI adoption improvements — added
init-ci githubto install the GitHub Actions workflow from the CLI, and scheduled GitHub Action runs now automatically scan the full project instead of only the latest diff. Package hallucination checks also use all tracked source files during full-project runs.New in v4.3.0 (2026-05-05): Critical security and reliability fixes — GitHub Actions now fail closed instead of fail-open when scanner output is invalid (preventing security gate bypass), patched 8 Hono CVEs (XSS, path traversal, authentication bypass), fixed confidence threshold filtering case sensitivity, and corrected SARIF generation for GitHub Code Scanning. All fixes include comprehensive regression tests. Upgrade recommended for production use. See Full Changelog.
New in v4.2.0: Compliance evidence collection — evaluate projects against SOC2-Technical (8 controls) and GDPR-Technical (6 controls) frameworks. Collects evidence from code scans, SBOM, vulnerability checks, and hallucination detection, then evaluates controls with pass/partial/fail/not_evaluated status. Supports evidence persistence for audit trails. See Compliance Evaluation.
New in v4.1.0: SBOM generation and dependency vulnerability analysis — generates CycloneDX v1.5 SBOMs, scans against OSV.dev for CVEs, detects hallucinated packages, compares baselines, and generates HTML audit reports. Supports 8 lock file formats and 7 manifest formats across npm, Python, Go, Rust, Ruby, and Java ecosystems. See SBOM Tools.
New in v4.0.0: LLM-powered semantic code review agent with intent profiling — understands what your project is supposed to do and flags patterns that violate that intent. Same
eval()call = safe in a build tool, dangerous in an e-commerce app. Supports Claude CLI (no API key needed!), Anthropic, and OpenAI. See code-review-agent.New in v3.11.0: ClawHub ecosystem security scanning — scanned all 16,532 ClawHub skills and found 46% have critical vulnerabilities. New
scan-clawhubCLI for batch scanning, 40+ prompt injection patterns, jailbreak detection (DAN mode, dev mode), data exfiltration checks. See ClawHub Security Dashboard.Also in v3.10.0: ClawProof OpenClaw plugin — 6-layer deep skill scanner (
scan_skill) with ClawHavoc malware signatures (27 rules, 121 patterns covering reverse shells, crypto miners, info stealers, C2 beacons, and OpenClaw-specific attacks), package supply chain verification, and rug pull detection.OpenClaw integration: 30+ rules targeting autonomous AI threats + native plugin support. See setup.
| Tool | Description | When to Use |
|---|---|---|
scan_security |
Scan code for vulnerabilities (1700+ rules, 12 languages) with AST and taint analysis | After writing or editing any code file |
fix_security |
Auto-fix all detected vulnerabilities (120 fix templates) | After scan_security finds issues |
scan_git_diff |
Scan only changed files in git diff | Before commits or in PR reviews |
scan_project |
Scan entire project with A-F security grading | For project-wide security audits |
check_package |
Verify a package name isn't AI-hallucinated (4.3M+ packages) | Before adding any new dependency |
scan_packages |
Bulk-check all imports in a file for hallucinated packages | Before committing code with new imports |
scan_agent_prompt |
Detect prompt injection with bypass hardening (59 rules + multi-encoding) | Before acting on external/untrusted input |
scan_agent_action |
Pre-execution safety check for agent actions (bash, file ops, HTTP). Returns ALLOW/WARN/BLOCK | Before running any agent-generated shell command or file operation |
scan_mcp_server |
Scan MCP server source for vulnerabilities: unicode poisoning, name spoofing, rug pull detection, manifest analysis. Returns A-F grade | When auditing or installing an MCP server |
scan_skill |
Deep security scan of an OpenClaw skill: prompt injection, AST+taint code analysis, ClawHavoc malware signatures, supply chain, rug pull. Returns A-F grade | Before installing any OpenClaw skill |
scanner_health |
Check plugin health: engine status, daemon status, package data availability | Diagnostics and plugin status |
list_security_rules |
List available security rules and fix templates | To check rule coverage for a language |
sbom_generate |
Ge |