PromptHub
Back to Blog
Developer Tools Security

snyk/agent-scan: Security Scanner for AI Agents and MCP Servers

B

Bright Coding

Author

10 min read 10 views
snyk/agent-scan: Security Scanner for AI Agents and MCP Servers

snyk/agent-scan: Security Scanner for AI Agents and MCP Servers

AI agents and Model Context Protocol (MCP) servers are becoming standard infrastructure in developer workflows. Tools like Claude, Cursor, and Windsurf extend their capabilities through third-party MCP servers and agent skills—yet these same extension points introduce supply-chain risks that traditional security scanners weren't built to catch. Prompt injections, tool poisoning, and malware payloads hidden in natural language instructions can turn helpful agents into attack vectors.

snyk/agent-scan is a purpose-built security scanner that discovers and analyzes agent components on your machine. It inventories installed agents, MCP servers, and skills, then flags specific security issues including prompt injections, toxic flows, and hardcoded secrets. With 2,779 GitHub stars and active development as of July 2026, it represents one of the first focused attempts to secure the emerging agent ecosystem. This article covers what it does, how it works, and how to integrate it into your security workflow.

What is snyk/agent-scan?

snyk/agent-scan is an open-source security scanner maintained by Snyk, released under the Apache License 2.0 and primarily written in Python↗ Bright Coding Blog. It occupies a new and rapidly evolving category: agent supply-chain security. While conventional scanners focus on dependencies, containers, or infrastructure, this tool targets the unique risks introduced by AI agent architectures—specifically the MCP servers and skills that agents execute on behalf of users.

The project launched with support for major agent platforms and has expanded to cover 12+ agents across macOS, Linux, and Windows. Its 246 forks suggest active community interest, though the project is currently closed to external contributions. Snyk positions it as both a standalone CLI tool for individual developers and a managed component (via Snyk Evo) for enterprise security teams monitoring agent deployments at scale.

The timing is significant. The README references a technical report on "the emerging threats of the agent skill ecosystem," published alongside version 0.4. As agents gain permissions to read files, execute commands, and access APIs, the attack surface shifts from the agent itself to the components it blindly trusts. snyk/agent-scan attempts to make that trust boundary visible and verifiable.

Key Features

Auto-discovery across agent ecosystems. snyk/agent-scan automatically detects installed agents and their configurations without manual path specification. It supports Claude Desktop, Claude Code, Cursor, Windsurf, VS Code, Gemini CLI, Amazon Q, Codex, Kiro, OpenCode, Antigravity, OpenClaw, and Amp—covering the majority of mainstream agent platforms as of mid-2026.

15+ distinct security risk detections. The scanner identifies specific issue types with documented codes:

  • MCP server risks: Prompt Injection (E001), Tool Poisoning (E001), Tool Shadowing (E002), Toxic Flows
  • Skill risks: Prompt Injection (E004), Malware Payloads (E006), Untrusted Content (W011), Credential Handling (W007), Hardcoded Secrets (W008)

Cross-platform coverage. The tool operates on macOS, Linux, and Windows (with WSL for some agents), scanning configurations at four scopes: system-wide, user-level, project/workspace, and extension/plugin.

Interactive consent for MCP server execution. A critical safety feature: because scanning MCP configurations requires executing the commands defined in them, snyk/agent-scan prompts for explicit approval before starting each stdio MCP server. It displays the exact command, arguments, and redacted environment variables that will run.

Dual operation modes. Scan Mode produces local CLI reports; Background Mode (MDM) enables continuous monitoring with centralized reporting to Snyk Evo for enterprise deployments.

GPG-signed releases. Binary distributions include signed checksums for integrity verification, with documented verification steps using Snyk's published public key.

Use Cases

Pre-commit agent security review. Before adding a new MCP server to your Claude or Cursor configuration, run snyk/agent-scan to identify prompt injection vectors or excessive permissions. The interactive consent flow lets you inspect exactly what code will execute before it runs on your machine.

CI/CD pipeline integration. In automated environments, use --dangerously-run-mcp-servers (with appropriate sandboxing) to scan configurations as part of build pipelines. The --json output enables programmatic evaluation of scan results for gating deployments.

Enterprise agent governance. Security teams using Snyk Evo can deploy Background Mode to maintain continuous inventory of agent components across developer machines, with centralized visibility into tool poisoning attempts or policy violations.

Third-party skill evaluation. When evaluating agent skills from public repositories or marketplaces, scan SKILL.md files or skill directories before installation. The malware payload detection specifically targets threats hidden in natural language instructions.

Incident response and forensics. After detecting suspicious agent behavior, use snyk-agent-scan inspect to enumerate tools, prompts, and resources without triggering security checks—useful for understanding what capabilities a compromised configuration exposed.

Installation & Setup

snyk/agent-scan requires a Snyk API token and Python environment management via uv.

Prerequisites

  1. Sign up for Snyk at snyk.io and obtain an API token from https://app.snyk.io/account (API Token → KEY → click to show).

  2. Set the token as an environment variable:

export SNYK_TOKEN=your-api-token-here
  1. Install uv, the Python package manager:
# Follow instructions at https://docs.astral.sh/uv/getting-started/installation/

Running the Scanner

The recommended invocation uses uvx to run the latest version without permanent installation:

# Full machine scan (auto-discovers all agents, MCP servers, skills)
uvx snyk-agent-scan@latest

This command discovers configurations across supported agents and performs security analysis. The first run will prompt for consent before executing any MCP server commands.

Targeted Scans

For specific files or directories:

# Scan a specific MCP configuration file
uvx snyk-agent-scan@latest ~/.vscode/mcp.json

# Scan a single agent skill
uvx snyk-agent-scan@latest ~/path/to/my/SKILL.md

# Scan all Claude skills
uvx snyk-agent-scan@latest ~/.claude/skills

Verification (Optional)

For standalone binaries downloaded from GitHub Releases, verify integrity:

# Import Snyk's GPG key
gpg --import snyk-code-signing-public.pgp

# Verify checksums signature
gpg --verify sha256sums.txt.asc

# Verify binary matches checksum (Linux/macOS with coreutils)
grep agent-scan-<version>-<os>-<arch> sha256sums.txt.asc | sha256sum -c -

Real Code Examples

Example 1: Basic Full Scan

The simplest invocation discovers and scans all agent components:

uvx snyk-agent-scan@latest

This runs the default scan command with auto-discovery. The tool searches known configuration paths for each supported agent, prompts for MCP server execution consent, and outputs a formatted report of findings. No arguments are required for the common case of auditing your local development machine.

Example 2: Scanning a Specific MCP Configuration

When you need to evaluate a configuration before adding it to your agent:

uvx snyk-agent-scan@latest ~/.vscode/mcp.json

This targets a single MCP configuration file rather than performing full discovery. Useful in CI contexts where you want to validate a specific configuration change, or when evaluating a shared team configuration before adoption.

Example 3: CI/CD Non-Interactive Scan

For automated environments where interactive consent is impossible:

uvx snyk-agent-scan@latest --dangerously-run-mcp-servers --json

Critical security note: The --dangerously-run-mcp-servers flag bypasses interactive consent and automatically executes all MCP server commands. The README explicitly warns to use this only in trusted environments where all MCP server commands have been verified—ideally inside sandboxed containers or disposable VMs.

Example 4: Inspecting Without Security Checks

To enumerate capabilities without triggering security analysis:

snyk-agent-scan inspect ~/custom/config.json

The inspect command prints tool descriptions, prompts, and resources without verification. Use this when you need to understand what an MCP server exposes before deciding whether to run security checks, or for debugging configuration issues.

Advanced Usage & Best Practices

Sandbox untrusted configurations. The README's security warning is unambiguous: scanning MCP configurations executes their defined commands. For third-party or untrusted configs, run snyk/agent-scan inside Docker↗ Bright Coding Blog containers, VMs, or other disposable environments. Never use --dangerously-run-mcp-servers with configurations you haven't personally reviewed.

Use --no-skills when appropriate. If your security concern is strictly MCP server-related, adding --no-skills skips skill analysis and reduces scan time. Conversely, if you're auditing a skills-only environment, target skill directories directly.

Interpret experimental output cautiously. Snyk explicitly notes that CLI output—including issue codes, field names, and severity labels—is experimental and subject to change. Do not build production automation that depends on specific output formats. For stable integrations, contact Snyk about designated APIs rather than scraping CLI output.

Monitor with enterprise tooling. For security teams, the Background Mode (MDM) integration with Snyk Evo provides centralized monitoring without requiring developers to manually run scans. This addresses the governance gap when agent adoption spreads organically across engineering teams.

Comparison with Alternatives

Direct competitors in agent-specific security scanning remain limited as of mid-2026. The field is emerging, with most security tooling still focused on traditional software supply chains rather than agent architectures.

Tool/Approach Focus snyk/agent-scan Differentiation
Invariant MCP-Scan MCP security research and scanning snyk/agent-scan adds enterprise management (Snyk Evo), broader agent support, and official Snyk maintenance
General SCA scanners (Snyk Open Source, etc.) Dependency vulnerabilities snyk/agent-scan addresses agent-specific risks (prompt injection, tool poisoning) that dependency scanners cannot detect
Manual MCP server audit Human review of configurations snyk/agent-scan automates detection across 15+ risk types and scales to enterprise inventories

Invariant Labs' MCP-Scan (referenced in the README's further reading) represents the closest conceptual alternative, with published research on tool poisoning and toxic flows. snyk/agent-scan distinguishes itself through official Snyk backing, broader platform coverage, and enterprise integration paths. However, developers prioritizing pure open-source community governance may prefer alternatives until snyk/agent-scan opens contributions.

FAQ

Is snyk/agent-scan free to use? The CLI is open-source under Apache 2.0. Enterprise Background Mode requires Snyk Evo licensing; contact Snyk for details.

Which Python versions are supported? Check PyPI badges for current requirements; the demo specifies Python 3.13.

Can I contribute code? No—external contributions are not accepted. File GitHub issues for suggestions or bug reports.

Does it work without a Snyk account? No; a Snyk API token is required for all scans.

Is the CLI output stable for scripting? No—output format is explicitly experimental. Use designated APIs for stable integrations.

What happens if I decline an MCP server during scan? The server is recorded with user_declined and never started; remaining servers continue processing.

Does snyk/agent-scan store my MCP tool call contents? No—the README states tool call contents and results are not stored or logged.

Conclusion

snyk/agent-scan addresses a genuine and growing security gap: the blind trust that AI agents place in MCP servers and skills. With support for 12+ agent platforms, 15+ specific detection types, and both individual CLI and enterprise management modes, it provides actionable visibility into a previously opaque attack surface.

The tool is best suited for developers actively using Claude, Cursor, Windsurf, or similar agents who want to audit their configurations before exploitation. Security teams adopting agents organization-wide will find the Snyk Evo integration path particularly valuable. The experimental CLI output and contribution closure are current limitations to weigh against the benefits of focused, maintained agent security scanning.

Start with a full machine scan: uvx snyk-agent-scan@latest. Review the full documentation on GitHub, and consider whether your agent configurations deserve the same scrutiny you apply to traditional dependencies.

For related reading on securing AI infrastructure, see [INTERNAL_LINK: AI supply chain security best practices].

Comments (0)

Comments are moderated before appearing.

No comments yet. Be the first to share your thoughts!

Recommended Prompts

View All
All tools