# Statically scan agent repos for prompt injection and unsafe MCP configs with Agent Audit

> Audit agent code, prompts, and MCP configuration for prompt-injection surfaces, taint issues, and unsafe tool exposure before shipping.

- Skill: `agentskillexchange/statically-scan-agent-repos-for-prompt-injection-and-unsafe-` (Agent Skill)
- Install (CLI): `npx skillmds@latest add agentskillexchange/statically-scan-agent-repos-for-prompt-injection-and-unsafe-`
- Raw SKILL.md: https://api.skillmd.com/api/skills/agentskillexchange/statically-scan-agent-repos-for-prompt-injection-and-unsafe-/raw
- Safety review: pending (external: skill-scanner PASS, skillspector PASS)
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: AI & ML
- Author: agentskillexchange (https://skillmd.com/u/agentskillexchange)
- Updated: 2026-09-08
- Page: https://skillmd.com/skills/agentskillexchange/statically-scan-agent-repos-for-prompt-injection-and-unsafe-

---


# Statically scan agent repos for prompt injection and unsafe MCP configs with Agent Audit

Audit agent code, prompts, and MCP configuration for prompt-injection surfaces, taint issues, and unsafe tool exposure before shipping.

## Prerequisites

agent-audit, local agent repository or config tree

## Installation

Use the upstream install or setup path that matches your environment:
- pip install agent-audit
- git clone https://github.com/HeadyZhang/agent-audit

Requirements and caveats from upstream:
- [![Python](https://img.shields.io/pypi/pyversions/agent-audit.svg)](https://pypi.org/project/agent-audit/)
- | T6 | [openai-agents-python](https://github.com/openai/openai-agents-python) | 25 | ASI-01, ASI-02 |
- | T7 | [adk-python](https://github.com/google/adk-python) | 40 | ASI-02, ASI-04, ASI-10 |

Basic usage or getting-started notes:
- Install
- bash
- Scan your project

- Source: https://github.com/HeadyZhang/agent-audit
- Extracted from upstream docs: https://raw.githubusercontent.com/HeadyZhang/agent-audit/HEAD/README.md

## Documentation

- https://headyzhang.github.io/agent-audit/

## Source

- [Agent Skill Exchange](https://agentskillexchange.com/skills/statically-scan-agent-repos-for-prompt-injection-and-unsafe-mcp-configs-with-agent-audit/)

