About this project

Snyk Agent Scan is a security tool designed to discover and scan agent components (AI agents, MCP servers, and agent skills) on a machine for vulnerabilities, including prompt injections, sensitive data handling, and malware payloads. It supports auto-discovery of popular agents like Claude, Cursor, GitHub Copilot, Windsurf, and others across macOS, Linux, and Windows. The tool operates in two modes: interactive scanning with user consent for MCP server connections, and background scanning for enterprise monitoring via Snyk Evo. It provides both issue-code-based output (v0.5.x, planned for deprecation) and risk-based scored output (v0.6+). Users can run it via `uvx` or standalone binaries, with options to scan entire systems, specific configurations, or individual skills. Security warnings emphasize sandboxing untrusted MCP configs and reviewing consent prompts carefully.