AI-first security scanner. NEW in v2026.7: Claude Code compromise detection — vet .claude/ hooks, permissions & skills before you clone — plus an always-on AI attack-signature scanner and native Rust & PHP rules. Also: medusa scan --git to vet any repo, medusa secrets scan for leaked API keys. 40,000+ patterns, zero setup.
AI-first security scanner with 40,000+ detection patterns for AI/ML, agents, and LLM applications.
🤖 Works out of the box - no tool installation required.
🚨 200 CVEs: Log4Shell, Spring4Shell, XZ Utils, LangChain RCE, MCP-Remote RCE, React2Shell
🔥 medusa scan --git <URL> — Scan any repo for AI supply chain attacks (repo poisoning, prompt injection, MCP tool poisoning)
🔐 medusa secrets scan — Find leaked API keys in your Claude / Cursor / Copilot / shell history. 21 issuer types. Interactive in-place redaction.
🚀 v2026.7.0: Claude Code compromise detection, an always-on AI attack-signature scanner, native Rust & PHP security rules, and rule-level diagnostics — on top of 40,000+ detection patterns.
MEDUSA is an AI-first security scanner with 40,000+ detection patterns that works out of the box. Simply install and scan - no external tool installation required. MEDUSA's built-in rules detect vulnerabilities in AI/ML applications, LLM agents, MCP servers, RAG pipelines, and traditional code.
medusa scan --git <URL> - Scan any GitHub repo for AI supply chain attacks in secondsmedusa secrets scan + purge - Find API keys / tokens / private keys leaked into Claude Code / Cursor / Copilot / Zed / Gemini chat histories and your bash / zsh / psql / mysql / python REPL history. 21 issuer types (Anthropic, OpenAI, PyPI, GitHub PATs, AWS, GCP, Stripe, Slack…). Interactive [y/n/s/a/q] purge with mandatory byte-identical backup and JSONL-safe redaction. Local-only, no telemetry.pip install - no tool installation needed.medusa.yml for project-specific settingsClaude Code supply-chain detection, broader language coverage, and rule-level observability.
| Change | Details | |
|---|---|---|
| 🛡️ | Claude Code compromise detection | medusa scan --git now structurally vets .claude/ — poisoned hooks (curl|bash, base64→exec, credential exfil, reverse shells), over-broad permissions (Bash(*), bypassPermissions), wildcard-tool subagents, and dropper skills — before you clone. |
| 🎯 | Always-on attack-signature scanner | Closes a false-negative gap — jailbreak / prompt-injection payloads in data files (.jsonl/.csv) and prose are now caught regardless of LLM-context confidence, plus invisible-unicode / bidi (Trojan Source, CVE-2021-42574) recovery. |
| 🦀 | Native Rust security rules | 22 out-of-box rules (no toolchain needed) — TLS verification disabled, command injection, untrusted deserialization, raw SQL, unsafe memory ops, weak crypto, SSRF. |
| 🐘 | Native PHP security rules | 16 out-of-box rules — SQLi, command/eval injection, LFI/RFI, path traversal, unserialize() object injection, unrestricted upload, reflected XSS, SSRF, weak crypto. |
| 🔬 | Rule diagnostics (--trace-rules) | Per-rule firing log + timing (rule-trace.jsonl, slow_rules.csv) and a hang-survivable heartbeat — found & fixed a real catastrophic-backtracking ReDoS, plus a ReDoS/nested-set lint that blocks bad patterns at author time. |
| ⚡ | Engine + accuracy | Scan-engine perf quick-wins, context-aware screening mode for --git target vetting, large-file byte-cap sampling, and a documentation-placeholder secret-FP fix. |
v2026.5.12 — Biggest pattern release: 9,600 → 40,000+ detection patterns harvested from 8,466 AI-security research papers, false-positive-hardened; structural rule-integrity scanner.
v2026.5.10 — Security hardening: VS Code extension command-injection fix, --fail-on cached-findings bug, tool-cache stale-path fix, user-home MCP configs made opt-in.
v2026.5.9 — Agentic-commerce coverage: UCPScanner + AP2Scanner + 45 hand-tuned positive-pattern rules.
v2026.5.8 — medusa secrets: scan AI chat & shell histories for leaked credentials (21 issuer types) with interactive [y/n/s/a/q] purge.
v2026.5.7 — Indirect PI rules (101/102), supply chain import scanner, macOS/Windows multiprocessing fix.
v2026.5.5 — security hardening release (argv injection defenses, git SSRF, HMAC cache integrity, markdown XSS fix).
External Linters (optional): MEDUSA auto-detects bandit, eslint, shellcheck, etc. if installed. See Optional Tools Guide.
Your PyPI token might be in your Claude chat history right now.
Developers paste API keys, tokens, and credentials into AI assistants every day —
"deploy this with pypi-AgEI...", "use my ghp_... to push", "the AWS key is AKIA...".
The assistants keep those conversations in plaintext on disk. Anyone with read access
to $HOME — or any future malware with shell access — can grep -r 'sk-\|ghp_\|AKIA' ~/
and harvest production credentials in seconds.
medusa secrets scan finds them. medusa secrets purge cleans them up.
medusa secrets scan
Scanning 118 file(s)...
── claude-code ──────────────────────────────────────────────
/home/ross/.claude/history.jsonl (13 finding(s))
[CRITICAL] Anthropic API key (anthropic)
/home/ross/.claude/history.jsonl:1005:13
sk-ant-api03***...***
[CRITICAL] PyPI API token (pypi)
/home/ross/.claude/history.jsonl:125:94
pypi-AgEIc***...***
[CRITICAL] GitHub fine-grained PAT (github)
/home/ross/.claude/history.jsonl:2306:13
github_pat_11A***...***
[HIGH] HuggingFace token (huggingface)
/home/ross/.claude/history.jsonl:3387:13
hf_JOi***...***
...
Total: 13 credentials across 1 file(s).
Report: /home/ross/.medusa/secrets-scan/secrets-20260519-074452.json
medusa secrets purge