# Scan agent repos for repo-poisoning, unsafe AI config files, and MCP attack surfaces with MEDUSA

> Run a focused preflight scan over agent and MCP repositories to catch poisoned instruction files, dangerous configs, and AI-specific supply-chain risks before merge or deployment.

- Skill: `agentskillexchange/scan-agent-repos-for-repo-poisoning-unsafe-ai-config-files-a` (Agent Skill)
- Install (CLI): `npx skillmds@latest add agentskillexchange/scan-agent-repos-for-repo-poisoning-unsafe-ai-config-files-a`
- Raw SKILL.md: https://api.skillmd.com/api/skills/agentskillexchange/scan-agent-repos-for-repo-poisoning-unsafe-ai-config-files-a/raw
- Safety review: pending (external: skill-scanner PASS, skillspector PASS)
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: AI & ML
- Author: agentskillexchange (https://skillmd.com/u/agentskillexchange)
- Updated: 2026-09-08
- Page: https://skillmd.com/skills/agentskillexchange/scan-agent-repos-for-repo-poisoning-unsafe-ai-config-files-a

---


# Scan agent repos for repo-poisoning, unsafe AI config files, and MCP attack surfaces with MEDUSA

Run a focused preflight scan over agent and MCP repositories to catch poisoned instruction files, dangerous configs, and AI-specific supply-chain risks before merge or deployment.

## Prerequisites

Python 3 environment, pip, MEDUSA package, access to the local repo or target GitHub repository, and optional external linters for expanded coverage

## Installation

Use the upstream install or setup path that matches your environment:
- pip install medusa-security
- git clone https://github.com/yourusername/medusa.git
- pip install -e ".[dev]"

Requirements and caveats from upstream:
- [![Python](https://img.shields.io/badge/python-3.10%2B-blue.svg)](https://www.python.org/downloads/)
- | --quick | Quick scan (changed files only, requires git) |
- name: Set up Python

Basic usage or getting-started notes:
- ## 🚀 Quick Start
- bash
- # Run your first scan - that's it!

- Source: https://github.com/Pantheon-Security/medusa
- Extracted from upstream docs: https://raw.githubusercontent.com/Pantheon-Security/medusa/HEAD/README.md

## Documentation

- https://github.com/Pantheon-Security/medusa

## Source

- [Agent Skill Exchange](https://agentskillexchange.com/skills/scan-agent-repos-for-repo-poisoning-unsafe-ai-config-files-and-mcp-attack-surfaces-with-medusa/)

