🛡️ Security scanner for AI agent skills, configs, and MCP tools. Vet before you trust.
Stars
3
Forks
0
Watchers
3
Open Issues
3
Overall repository health assessment
^8.17.1^3.0.1^2.8.2^25.2.0^9.0.0^8.5.1^5.9.314
commits
fix: tool-risk-no-allowlist pattern now matches multi-statement LLM tool invocation (v0.21.1)
f2176ddView on GitHubfeat: add 4 new rule modules for 2026 agent security threats
82c56b6View on GitHubfeat: add coding-agent-config rules module (21 rules for AI IDE config attacks)
bb64571View on GitHubfeat(multi-agent-trust): add 5 new rules (session hijacking, A2A callback injection, result tampering, tool whitelist bypass, memory poisoning)
508340dView on GitHubfeat(rules): add resource-exhaustion module (9ルール: infinite-loop/recursive-spawn/unbounded-calls/context-flood/prompt-amplification/rate-limit-bypass/denial-of-wallet/memory-write-loop/external-flood, +55テスト, v0.20.17)
464484eView on GitHubfeat(rules): add resource-exhaustion module (8ルール: infinite-loop/recursive-self-spawn/unbounded-tool-calls/context-flooding/prompt-amplification/rate-limit-bypass/denial-of-wallet/memory-write-loop/external-service-flood, +55テスト, total 2185)
6234639View on GitHubfeat(computer-use): add VPN credential harvest + password manager access rules (+9 tests, v0.20.15)
bfcb54cView on GitHubfeat(agent-memory): add reflection-loop + cross-session-leak rules and tests (+16 tests, v0.20.14)
dbcb6c9View on GitHubfeat(a2a): add encryption & OIDC advanced tests (+24 tests, 2137 total) — TLS/HTTP/internal-endpoint/port/OIDC-scheme coverage
f6378dbView on GitHubfeat(mcp-supply-chain): batch 10 — auto-approval/checksum/update-url/CORS/timeout (+24 tests, 2113 total) — Issue #15 complete!
03c5a85View on GitHubfeat(mcp-supply-chain): batch 9 — eval-injection/deserialization/token-stuffing/no-auth/world-readable (+22 tests, 2089 total)
2c3dffaView on GitHubfeat(mcp-supply-chain): batch 8 — secret-in-name/SSRF/tool-spoofing/IPC-socket/debug-mode (+20 tests, 2067 total)
79c79b7View on GitHubfeat(mcp-supply-chain): batch 7 — excessive-scopes/persistent-storage/inter-agent/redirect/shadow-registry (+24 tests, 2047 total)
03d06cdView on GitHub