Snyk Agent Scan MCP and Skill Security Scanner
Snyk Agent Scan automatically discovers and scans AI agent components including MCP servers, agent skills, and agent harnesses for security vulnerabilities like prompt injections, tool poisoning, tool shadowing, and malware payloads. It supports Claude Code, Cursor, Windsurf, Gemini CLI, VS Code, and more.
Installation
Use the upstream install or setup path that matches your environment:
- uv run pip install -e .
- uv run -m src.agent_scan.cli
Requirements and caveats from upstream:
Basic usage or getting-started notes:
Use --dangerously-run-mcp-servers only in trusted environments where you've verified all MCP server commands
To get started:
Sign up at Snyk and get an API token from https://app.snyk.io/account (API Token → KEY → click to show).
Extracted from upstream docs: https://raw.githubusercontent.com/snyk/agent-scan/HEAD/README.md