Skip to content
KitploitKITPLOIT
도구익스플로잇블로그
Log in
제출
도구익스플로잇블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

··피드·문의·개인정보·© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
agent-scan — Security scanner for AI agents, MCP servers and agent skills. | Kitploit
도구/GitHubGitHub/snyk/agent-scan
Vulnerability ScannersDynamic Analysis (Sandboxing)Code AnalysisSecret DetectionSupply Chain SecurityAI SecurityAI Security #11위
GitHubsnyk/agent-scan

agent-scan

Security scanner for AI agents, MCP servers and agent skills.

2.9k258901일 전Kitploit 검토 완료

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
저장소 보기
공유
요청한 언어로 콘텐츠를 사용할 수 없습니다. 영어 버전을 표시합니다.

Snyk Agent Scan

Discover and scan agent components on your machine for prompt injections
and vulnerabilities (including agents, MCP servers, skills).

Note: We don't publish an npm package for Agent Scan. Install it via uvx or as a standalone binary.

Note: CLI output is experimental and subject to change

Agent Scan v0.5.x (planned for deprecation)

The raw output of this CLI — including issue codes, field names, severity labels, and response structure — is experimental and may change without notice between releases. We do not recommend building production workflows that depend on specific CLI output fields or issue codes.

Agent Scan v0.6 and later

The raw output of this CLI — including risk indicator names, scores, field names, and response structure — is experimental and may change without notice between releases. We do not recommend building production workflows that depend on specific CLI output fields or risk names.

If you are an enterprise customer using Snyk to manage agent security risk at scale, the CLI output may not reflect what is sent to and shown in the Evo platform. The underlying integration, discovery, and risk assessment that powers enterprise deployments is stable and supported — any changes will be communicated in line with standard Snyk product practices. Contact your account team for deployment guidance.

NEW Read our technical report on the emerging threats of the agent skill eco-system published together with Agent Scan 0.4, which adds support for scanning agent skills.

snyk-agent-scan snyk-agent-scan license snyk-agent-scan python version requirements

Agent Scan v0.5.x output

[!WARNING] Agent Scan v0.5.x uses issue-code output. This CLI line is planned for deprecation.

agent-scan-pretty

Agent Scan v0.6 and later output

Agent Scan v0.6 and later report showing scored MCP server and skill risks

Agent Scan helps you discover all your installed agent components (harnesses, MCP servers, and skills) and scans them for common threats like prompt injections, sensitive data handling, or malware payloads hidden in natural language. Ignore analysis on skills by using --no-skills.

Security Warning

⚠️ IMPORTANT: Scanning MCP configurations can execute commands or make outbound network requests.

To retrieve tool descriptions, Agent Scan starts stdio MCP servers by executing the commands in the config and connects to configured remote MCP server URLs with their configured headers.

Recommendations:

  • Run scans inside a sandbox (Docker container, VM, or disposable environment) when evaluating untrusted or third-party MCP configs
  • Review the consent prompt carefully during interactive scans; it shows the command or remote URL for each server
  • Use --dangerously-run-mcp-servers only in trusted environments where you've verified all MCP server commands and remote URLs

Remote MCP requests refuse destinations resolving to link-local addresses or known cloud-metadata endpoints (169.254.0.0/16, fe80::/10, fd00:ec2::254, and 100.100.100.200). Loopback and private addresses remain allowed for local and internal MCP servers. HTTP redirects are not followed. DNS is validated before each request, but resolution again at connection time leaves a DNS-rebinding window.

By default, Agent Scan requires explicit user consent (y/n) before contacting each discovered MCP server during foreground interactive runs. Background and push-key scans continue to inspect remote servers automatically for fleet coverage, but do not start stdio servers unless --dangerously-run-mcp-servers is set.

Quick Start

Choose one of two ways to run Agent Scan:

  1. Run the Python package with uvx using the instructions below.
  2. Download a standalone binary for your platform from GitHub Releases. Releases also include the SBOM, checksums, signed checksums, and source code archives.

Before using either option:

  1. Sign up at Snyk and get an API token from https://app.snyk.io/account (API Token → KEY → click to show).
  2. Set the token as an environment variable before running any scan:
    export SNYK_TOKEN=your-api-token-here
    

Run with uvx

Have uv installed on your system. Choose the instructions for your CLI version.

Agent Scan v0.5.x

The examples pin v0.5.17 as a concrete v0.5.x release:

# Scan the whole machine
uvx [email protected]

# Scan a specific MCP configuration
uvx [email protected] ~/.vscode/mcp.json

# Scan a single agent skill
uvx [email protected] ~/path/to/my/SKILL.md

# Scan all Claude skills
uvx [email protected] ~/.claude/skills

[!WARNING] v0.5.x uses issue-code output and the 2025-09-02 analysis API. This CLI line is planned for deprecation.

Agent Scan v0.6 and later

# Scan the whole machine
uvx snyk-agent-scan@latest

# Scan a specific MCP configuration
uvx snyk-agent-scan@latest ~/.vscode/mcp.json

# Scan a single agent skill
uvx snyk-agent-scan@latest ~/path/to/my/SKILL.md

# Scan all Claude skills
uvx snyk-agent-scan@latest ~/.claude/skills

v0.6 and later use the risk-based output and the 2026-07-10 analysis API.

Both versions scan MCP servers, tools, prompts, resources, and skills, and automatically discover supported agent configurations such as Claude Code/Desktop, Cursor, Gemini CLI, and Windsurf.

Run with a standalone binary

Download the binary for your operating system and architecture from the latest GitHub Release. The release page also provides an SBOM (sbom-<version>.json), checksum files, and GitHub-generated source code archives. See Verifying Standalone Binaries to verify your download.

Highlights

  • Auto-discover MCP configurations, agent tools, skills
  • Scanning of Claude, Cursor, GitHub Copilot, Windsurf, Gemini CLI, Amp, Amazon Q, and other agents.

Agent Scan v0.5.x

도구 다운로드