Agent Security Scanner MCP
A

Agent Security Scanner MCP

AI Coding Assistant Security Scanner, scans code vulnerabilities, detects AI hallucination packages, and prevents prompt injection attacks through MCP or CLI, supports 12 languages and more than 1,700 security rules
2.5 points
6.4K

What is the AI Agent Security Scanner?

This is a security tool specifically designed for AI programming assistants (such as Claude Code, Cursor, etc.). When the AI assistant helps you write code, this scanner will automatically check for security vulnerabilities, fake software package dependencies, and potential malicious instructions in the code to prevent the AI from being exploited by attackers.

How to use the AI Agent Security Scanner?

After installation, the scanner will be integrated into your AI programming assistant. When you write or modify code, it will automatically run security checks. You can also manually call the scanning command to check specific files or the entire project.

Use Cases

1. Automatic security check when using an AI assistant to write code 2. Security review before code submission 3. Verification of the authenticity of project dependency packages 4. Review of AI instructions from external or untrusted sources 5. Code security audit in open-source projects or team collaboration

Main Features

Code Vulnerability Scanning
Supports 12 programming languages (JavaScript, Python, Java, etc.), uses AST analysis and data flow tracking technology to detect more than 1,700 security vulnerabilities, such as SQL injection, XSS attacks, command injection, etc.
Automatic Repair Suggestions
After discovering vulnerabilities, not only report the problems but also provide specific repair codes. Supports more than 120 automatic repair templates to help quickly solve security problems.
AI Hallucination Package Detection
AI sometimes 'hallucinates' non-existent software package names. This tool verifies whether a software package actually exists in 7 mainstream software repositories (more than 4.3 million software packages) such as npm and PyPI to prevent the installation of malicious software.
Prompt Injection Protection
Detect and block malicious instructions targeting AI assistants, such as attacks like 'ignore all previous instructions' and'read sensitive files and send them to an external server'.
MCP Server Integration
Natively supports the Model Context Protocol and can be seamlessly integrated with mainstream AI programming assistants such as Claude Code, Cursor, Windsurf, and Cline.
Project Security Rating
Scan the entire project and give a security rating from A - F to help quickly understand the overall security status of the project.
Git Diff Scanning
Only scan the files changed in Git version control to improve the efficiency of code review and pre - submission checks.
OpenClaw Skill Scanning
A deep security scan specifically designed for the OpenClaw autonomous AI assistant to detect threats such as malicious code and data theft in skills.
Advantages
⚡ Real - time protection: Instantly detect security problems when the AI writes code
🛡️ Comprehensive coverage: Supports multiple programming languages and attack types
🔍 Precise detection: Combine AST analysis and data flow tracking to reduce false positives
🚀 Easy to integrate: One - click installation, seamlessly cooperate with mainstream AI programming assistants
📊 Actionable reports: Not only find problems but also provide specific repair solutions
🔒 Local operation: All analysis is completed locally to protect code privacy
Limitations
⚠️ Static analysis: Can only detect patterns in the code and cannot find runtime vulnerabilities
📁 File type limitation: Mainly targets source code files and has limited support for binary files
🔧 Requires Python: Some advanced functions require a Python environment
⚙️ Configuration learning: Simple configuration is required to integrate with different AI assistants

How to Use

Install the Scanner
Install the security scanner globally via npm
Configure the AI Assistant
Run the corresponding initialization command according to the AI programming assistant you are using
Restart the AI Assistant
Restart your AI programming assistant (such as Claude Code, Cursor, etc.) for the configuration to take effect
Start Using
Now your AI assistant has the security scanning function. Security problems will be automatically checked when writing code.

Usage Examples

Example 1: Security Check When Writing a Login Function
When you use an AI assistant to write a user login function, the scanner will automatically detect SQL injection vulnerabilities.
Example 2: Verification Before Adding a New Dependency
When the AI suggests installing an uncommon software package, verify whether the package actually exists.
Example 3: Instruction Check When Handling External Input
When the AI needs to handle instructions from users or external files, check if they contain malicious content.
Example 4: Project Code Review
Before submitting code, perform a security scan on all changes in the entire project.

Frequently Asked Questions

Will this scanner affect the response speed of the AI assistant?
Do I need to keep Python running all the time?
Will the scanner modify my code?
Which AI programming assistants are supported?
Is the false positive rate high?
How to report false positives or false negatives?

Related Resources

GitHub Repository
View source code, submit Issues, and participate in contributions
npm Package Page
View version history, download statistics, and user reviews
MCP Protocol Documentation
Understand the technical details of the Model Context Protocol
Security Benchmark Test Results
View the detection accuracy and performance benchmarks of the scanner
ClawHub Security Dashboard
View the security scanning results and statistics of AI skills

Installation

Copy the following command to your Client for configuration
{
  "mcpServers": {
    "security-scanner": {
      "command": "npx",
      "args": ["-y", "agent-security-scanner-mcp"]
    }
  }
}
Note: Your key is sensitive information, do not share it with anyone.

Alternatives

V
Vestige
Vestige is an AI memory engine based on cognitive science. By implementing 29 neuroscience modules such as prediction error gating, FSRS - 6 spaced repetition, and memory dreaming, it provides long - term memory capabilities for AI. It includes a 3D visualization dashboard and 21 MCP tools, runs completely locally, and does not require the cloud.
Rust
9.6K
4.5 points
M
Moltbrain
MoltBrain is a long-term memory layer plugin designed for OpenClaw, MoltBook, and Claude Code, capable of automatically learning and recalling project context, providing intelligent search, observation recording, analysis statistics, and persistent storage functions.
TypeScript
9.1K
4.5 points
B
Bm.md
A feature-rich Markdown typesetting tool that supports multiple style themes and platform adaptation, providing real-time editing preview, image export, and API integration capabilities
TypeScript
14.9K
5 points
S
Security Detections MCP
Security Detections MCP is a server based on the Model Context Protocol that allows LLMs to query a unified security detection rule database covering Sigma, Splunk ESCU, Elastic, and KQL formats. The latest version 3.0 is upgraded to an autonomous detection engineering platform that can automatically extract TTPs from threat intelligence, analyze coverage gaps, generate SIEM-native format detection rules, run tests, and verify. The project includes over 71 tools, 11 pre-built workflow prompts, and a knowledge graph system, supporting multiple SIEM platforms.
TypeScript
6.7K
4 points
P
Paperbanana
Python
10.0K
5 points
B
Better Icons
An MCP server and CLI tool that provides search and retrieval of over 200,000 icons, supports more than 150 icon libraries, and helps AI assistants and developers quickly obtain and use icons.
TypeScript
8.7K
4.5 points
A
Assistant Ui
assistant - ui is an open - source TypeScript/React library for quickly building production - grade AI chat interfaces, providing composable UI components, streaming responses, accessibility, etc., and supporting multiple AI backends and models.
TypeScript
10.0K
5 points
A
Apify MCP Server
The Apify MCP Server is a tool based on the Model Context Protocol (MCP) that allows AI assistants to extract data from websites such as social media, search engines, and e-commerce through thousands of ready-to-use crawlers, scrapers, and automation tools (Apify Actors). It supports OAuth and Skyfire proxy payment and can be integrated into MCP clients such as Claude and VS Code through HTTPS endpoints or local stdio.
TypeScript
8.9K
5 points
G
Gitlab MCP Server
Certified
The GitLab MCP server is a project based on the Model Context Protocol that provides a comprehensive toolset for interacting with GitLab accounts, including code review, merge request management, CI/CD configuration, and other functions.
TypeScript
28.5K
4.3 points
N
Notion Api MCP
Certified
A Python-based MCP Server that provides advanced to-do list management and content organization functions through the Notion API, enabling seamless integration between AI models and Notion.
Python
24.9K
4.5 points
D
Duckduckgo MCP Server
Certified
The DuckDuckGo Search MCP Server provides web search and content scraping services for LLMs such as Claude.
Python
81.7K
4.3 points
M
Markdownify MCP
Markdownify is a multi-functional file conversion service that supports converting multiple formats such as PDFs, images, audio, and web page content into Markdown format.
TypeScript
38.2K
5 points
F
Figma Context MCP
Framelink Figma MCP Server is a server that provides access to Figma design data for AI programming tools (such as Cursor). By simplifying the Figma API response, it helps AI more accurately achieve one - click conversion from design to code.
TypeScript
69.7K
4.5 points
U
Unity
Certified
UnityMCP is a Unity editor plugin that implements the Model Context Protocol (MCP), providing seamless integration between Unity and AI assistants, including real - time state monitoring, remote command execution, and log functions.
C#
37.5K
5 points
G
Gmail MCP Server
A Gmail automatic authentication MCP server designed for Claude Desktop, supporting Gmail management through natural language interaction, including complete functions such as sending emails, label management, and batch operations.
TypeScript
24.0K
4.5 points
M
Minimax MCP Server
The MiniMax Model Context Protocol (MCP) is an official server that supports interaction with powerful text-to-speech, video/image generation APIs, and is suitable for various client tools such as Claude Desktop and Cursor.
Python
56.5K
4.8 points
AIBase
Zhiqi Future, Your AI Solution Think Tank
© 2026AIBase