Agent Security Scanner MCP
A

Agent Security Scanner MCP

AI Coding Assistant Security Scanner, scans code vulnerabilities, detects AI hallucination packages, and prevents prompt injection attacks through MCP or CLI, supports 12 languages and more than 1,700 security rules
2.5 points
3.2K

What is the AI Agent Security Scanner?

This is a security tool specifically designed for AI programming assistants (such as Claude Code, Cursor, etc.). When the AI assistant helps you write code, this scanner will automatically check for security vulnerabilities, fake software package dependencies, and potential malicious instructions in the code to prevent the AI from being exploited by attackers.

How to use the AI Agent Security Scanner?

After installation, the scanner will be integrated into your AI programming assistant. When you write or modify code, it will automatically run security checks. You can also manually call the scanning command to check specific files or the entire project.

Use Cases

1. Automatic security check when using an AI assistant to write code 2. Security review before code submission 3. Verification of the authenticity of project dependency packages 4. Review of AI instructions from external or untrusted sources 5. Code security audit in open-source projects or team collaboration

Main Features

Code Vulnerability Scanning
Supports 12 programming languages (JavaScript, Python, Java, etc.), uses AST analysis and data flow tracking technology to detect more than 1,700 security vulnerabilities, such as SQL injection, XSS attacks, command injection, etc.
Automatic Repair Suggestions
After discovering vulnerabilities, not only report the problems but also provide specific repair codes. Supports more than 120 automatic repair templates to help quickly solve security problems.
AI Hallucination Package Detection
AI sometimes 'hallucinates' non-existent software package names. This tool verifies whether a software package actually exists in 7 mainstream software repositories (more than 4.3 million software packages) such as npm and PyPI to prevent the installation of malicious software.
Prompt Injection Protection
Detect and block malicious instructions targeting AI assistants, such as attacks like 'ignore all previous instructions' and'read sensitive files and send them to an external server'.
MCP Server Integration
Natively supports the Model Context Protocol and can be seamlessly integrated with mainstream AI programming assistants such as Claude Code, Cursor, Windsurf, and Cline.
Project Security Rating
Scan the entire project and give a security rating from A - F to help quickly understand the overall security status of the project.
Git Diff Scanning
Only scan the files changed in Git version control to improve the efficiency of code review and pre - submission checks.
OpenClaw Skill Scanning
A deep security scan specifically designed for the OpenClaw autonomous AI assistant to detect threats such as malicious code and data theft in skills.
Advantages
⚡ Real - time protection: Instantly detect security problems when the AI writes code
🛡️ Comprehensive coverage: Supports multiple programming languages and attack types
🔍 Precise detection: Combine AST analysis and data flow tracking to reduce false positives
🚀 Easy to integrate: One - click installation, seamlessly cooperate with mainstream AI programming assistants
📊 Actionable reports: Not only find problems but also provide specific repair solutions
🔒 Local operation: All analysis is completed locally to protect code privacy
Limitations
⚠️ Static analysis: Can only detect patterns in the code and cannot find runtime vulnerabilities
📁 File type limitation: Mainly targets source code files and has limited support for binary files
🔧 Requires Python: Some advanced functions require a Python environment
⚙️ Configuration learning: Simple configuration is required to integrate with different AI assistants

How to Use

Install the Scanner
Install the security scanner globally via npm
Configure the AI Assistant
Run the corresponding initialization command according to the AI programming assistant you are using
Restart the AI Assistant
Restart your AI programming assistant (such as Claude Code, Cursor, etc.) for the configuration to take effect
Start Using
Now your AI assistant has the security scanning function. Security problems will be automatically checked when writing code.

Usage Examples

Example 1: Security Check When Writing a Login Function
When you use an AI assistant to write a user login function, the scanner will automatically detect SQL injection vulnerabilities.
Example 2: Verification Before Adding a New Dependency
When the AI suggests installing an uncommon software package, verify whether the package actually exists.
Example 3: Instruction Check When Handling External Input
When the AI needs to handle instructions from users or external files, check if they contain malicious content.
Example 4: Project Code Review
Before submitting code, perform a security scan on all changes in the entire project.

Frequently Asked Questions

Will this scanner affect the response speed of the AI assistant?
Do I need to keep Python running all the time?
Will the scanner modify my code?
Which AI programming assistants are supported?
Is the false positive rate high?
How to report false positives or false negatives?

Related Resources

GitHub Repository
View source code, submit Issues, and participate in contributions
npm Package Page
View version history, download statistics, and user reviews
MCP Protocol Documentation
Understand the technical details of the Model Context Protocol
Security Benchmark Test Results
View the detection accuracy and performance benchmarks of the scanner
ClawHub Security Dashboard
View the security scanning results and statistics of AI skills

Installation

Copy the following command to your Client for configuration
{
  "mcpServers": {
    "security-scanner": {
      "command": "npx",
      "args": ["-y", "agent-security-scanner-mcp"]
    }
  }
}
Note: Your key is sensitive information, do not share it with anyone.

Alternatives

V
Vestige
Vestige is an AI memory engine based on cognitive science. By implementing 29 neuroscience modules such as prediction error gating, FSRS - 6 spaced repetition, and memory dreaming, it provides long - term memory capabilities for AI. It includes a 3D visualization dashboard and 21 MCP tools, runs completely locally, and does not require the cloud.
Rust
5.6K
4.5 points
B
Better Icons
An MCP server and CLI tool that provides search and retrieval of over 200,000 icons, supports more than 150 icon libraries, and helps AI assistants and developers quickly obtain and use icons.
TypeScript
5.7K
4.5 points
A
Assistant Ui
assistant - ui is an open - source TypeScript/React library for quickly building production - grade AI chat interfaces, providing composable UI components, streaming responses, accessibility, etc., and supporting multiple AI backends and models.
TypeScript
7.5K
5 points
A
Apify MCP Server
The Apify MCP Server is a tool based on the Model Context Protocol (MCP) that allows AI assistants to extract data from websites such as social media, search engines, and e-commerce through thousands of ready-to-use crawlers, scrapers, and automation tools (Apify Actors). It supports OAuth and Skyfire proxy payment and can be integrated into MCP clients such as Claude and VS Code through HTTPS endpoints or local stdio.
TypeScript
7.6K
5 points
R
Rsdoctor
Rsdoctor is a build analysis tool specifically designed for the Rspack ecosystem, fully compatible with webpack. It provides visual build analysis, multi - dimensional performance diagnosis, and intelligent optimization suggestions to help developers improve build efficiency and engineering quality.
TypeScript
10.5K
5 points
N
Next Devtools MCP
The Next.js development tools MCP server provides Next.js development tools and utilities for AI programming assistants such as Claude and Cursor, including runtime diagnostics, development automation, and document access functions.
TypeScript
10.8K
5 points
T
Testkube
Testkube is a test orchestration and execution framework for cloud-native applications, providing a unified platform to define, run, and analyze tests. It supports existing testing tools and Kubernetes infrastructure.
Go
7.6K
5 points
M
MCP Windbg
An MCP server that integrates AI models with WinDbg/CDB for analyzing Windows crash dump files and remote debugging, supporting natural language interaction to execute debugging commands.
Python
11.6K
5 points
N
Notion Api MCP
Certified
A Python-based MCP Server that provides advanced to-do list management and content organization functions through the Notion API, enabling seamless integration between AI models and Notion.
Python
20.4K
4.5 points
M
Markdownify MCP
Markdownify is a multi-functional file conversion service that supports converting multiple formats such as PDFs, images, audio, and web page content into Markdown format.
TypeScript
35.4K
5 points
D
Duckduckgo MCP Server
Certified
The DuckDuckGo Search MCP Server provides web search and content scraping services for LLMs such as Claude.
Python
72.2K
4.3 points
G
Gitlab MCP Server
Certified
The GitLab MCP server is a project based on the Model Context Protocol that provides a comprehensive toolset for interacting with GitLab accounts, including code review, merge request management, CI/CD configuration, and other functions.
TypeScript
24.6K
4.3 points
U
Unity
Certified
UnityMCP is a Unity editor plugin that implements the Model Context Protocol (MCP), providing seamless integration between Unity and AI assistants, including real - time state monitoring, remote command execution, and log functions.
C#
32.2K
5 points
F
Figma Context MCP
Framelink Figma MCP Server is a server that provides access to Figma design data for AI programming tools (such as Cursor). By simplifying the Figma API response, it helps AI more accurately achieve one - click conversion from design to code.
TypeScript
65.5K
4.5 points
G
Gmail MCP Server
A Gmail automatic authentication MCP server designed for Claude Desktop, supporting Gmail management through natural language interaction, including complete functions such as sending emails, label management, and batch operations.
TypeScript
22.1K
4.5 points
M
Minimax MCP Server
The MiniMax Model Context Protocol (MCP) is an official server that supports interaction with powerful text-to-speech, video/image generation APIs, and is suitable for various client tools such as Claude Desktop and Cursor.
Python
48.9K
4.8 points
AIBase
Zhiqi Future, Your AI Solution Think Tank
© 2026AIBase