Install
$ agentstack add mcp-sinewaveai-agent-security-scanner-mcp Open-source listing, not yet scanned by AgentStack. Follow the source repository for install instructions.
Security review
⚠ Flagged4 finding(s); flagged for manual review. · v0.1.0 How review works →
- • Prompt-injection patterns
- • Secret / credential exfiltration
- • Dangerous shell & filesystem operations
- • Untrusted network calls
- • Known-malicious package signatures
- high Possible prompt-injection directive.
- high Dangerous shell/eval execution.
- high Destructive filesystem operation.
- high Pipes remote content directly into a shell (remote code execution).
What it can access
- ● Network access Used
- ● Filesystem access Used
- ● Shell / process execution Used
- ● Environment & secrets Used
- ● Dynamic code execution Used
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
agent-security-scanner-mcp
Security scanner for AI coding agents and autonomous assistants
Scans code for vulnerabilities, detects hallucinated packages, blocks prompt injection, and provides LLM-powered semantic code review — via MCP (Claude Code, Cursor, Windsurf, Cline) or CLI (OpenClaw, CI/CD).
[](https://www.npmjs.com/package/agent-security-scanner-mcp) [](https://www.npmjs.com/package/agent-security-scanner-mcp) [](https://opensource.org/licenses/MIT) [](benchmarks/RESULTS.md) [](https://github.com/sinewaveai/agent-security-scanner-mcp/actions/workflows/test.yml)
🎯 Two Versions Available
🔥 ProofLayer (Lightweight) - NEW!
Ultra-fast, zero-Python security scanner — 81.5KB package, 4-second install
[](https://www.npmjs.com/package/@prooflayer/security-scanner) [](https://www.npmjs.com/package/@prooflayer/security-scanner)
npm install -g @prooflayer/security-scanner
- ⚡ 4-second install (vs 45s traditional scanners)
- 📦 81.5KB package (vs 50MB+ alternatives)
- 🚀 Instant scans - pure regex, no Python/LLM
- 🛡️ 400+ security rules across 9 languages
- 🎯 7 MCP tools for AI agents
- ✅ Zero dependencies on Python
- 💯 MIT licensed - free for commercial use
[📖 ProofLayer Documentation →](./prooflayer-scanner/)
🔬 Full Version (Advanced)
Enterprise-grade scanner with AST analysis, taint tracking, cross-file analysis, and LLM-powered semantic review
[](https://www.npmjs.com/package/agent-security-scanner-mcp)
npm install -g agent-security-scanner-mcp
- 🧬 AST + Taint Analysis - deep code understanding
- 🔍 1,700+ security rules across 12 languages
- 📊 Cross-file tracking - follow data flows
- 🎯 11 MCP tools + CLI commands
- 📦 4.3M+ package verification (bloom filters)
- 🐍 Python analyzer for advanced features
- 🤖 LLM-powered code review - semantic security analysis with intent profiling
Continue reading below for full version documentation →
> New in v4.3.0 (2026-05-05): Critical security and reliability fixes — GitHub Actions now fail closed instead of fail-open when scanner output is invalid (preventing security gate bypass), patched 8 Hono CVEs (XSS, path traversal, authentication bypass), fixed confidence threshold filtering case sensitivity, and corrected SARIF generation for GitHub Code Scanning. All fixes include comprehensive regression tests. Upgrade recommended for production use. [See Full Changelog](CHANGELOG.md#430---2026-05-05). > > New in v4.2.0: Compliance evidence collection — evaluate projects against SOC2-Technical (8 controls) and GDPR-Technical (6 controls) frameworks. Collects evidence from code scans, SBOM, vulnerability checks, and hallucination detection, then evaluates controls with pass/partial/fail/notevaluated status. Supports evidence persistence for audit trails. [See Compliance Evaluation](#-compliance-evaluation-new-in-v420). > > New in v4.1.0: SBOM generation and dependency vulnerability analysis — generates CycloneDX v1.5 SBOMs, scans against OSV.dev for CVEs, detects hallucinated packages, compares baselines, and generates HTML audit reports. Supports 8 lock file formats and 7 manifest formats across npm, Python, Go, Rust, Ruby, and Java ecosystems. [See SBOM Tools](#-sbom--supply-chain-analysis-new-in-v410). > > New in v4.0.0: LLM-powered semantic code review agent with intent profiling — understands what your project is supposed to do and flags patterns that violate that intent. Same eval() call = safe in a build tool, dangerous in an e-commerce app. Supports Claude CLI (no API key needed!), Anthropic, and OpenAI. [See code-review-agent](#-llm-powered-code-review-agent-new-in-v400). > > New in v3.11.0: ClawHub ecosystem security scanning — scanned all 16,532 ClawHub skills and found 46% have critical vulnerabilities. New scan-clawhub CLI for batch scanning, 40+ prompt injection patterns, jailbreak detection (DAN mode, dev mode), data exfiltration checks. See ClawHub Security Dashboard. > > Also in v3.10.0: ClawProof OpenClaw plugin — 6-layer deep skill scanner (scan_skill) with ClawHavoc malware signatures (27 rules, 121 patterns covering reverse shells, crypto miners, info stealers, C2 beacons, and OpenClaw-specific attacks), package supply chain verification, and rug pull detection. > > OpenClaw integration: 30+ rules targeting autonomous AI threats + native plugin support. [See setup](#openclaw-integration).
Tools
| Tool | Description | When to Use | |------|-------------|-------------| | scan_security | Scan code for vulnerabilities (1700+ rules, 12 languages) with AST and taint analysis | After writing or editing any code file | | fix_security | Auto-fix all detected vulnerabilities (120 fix templates) | After scan_security finds issues | | scan_git_diff | Scan only changed files in git diff | Before commits or in PR reviews | | scan_project | Scan entire project with A-F security grading | For project-wide security audits | | check_package | Verify a package name isn't AI-hallucinated (4.3M+ packages) | Before adding any new dependency | | scan_packages | Bulk-check all imports in a file for hallucinated packages | Before committing code with new imports | | scan_agent_prompt | Detect prompt injection with bypass hardening (59 rules + multi-encoding) | Before acting on external/untrusted input | | scan_agent_action | Pre-execution safety check for agent actions (bash, file ops, HTTP). Returns ALLOW/WARN/BLOCK | Before running any agent-generated shell command or file operation | | scan_mcp_server | Scan MCP server source for vulnerabilities: unicode poisoning, name spoofing, rug pull detection, manifest analysis. Returns A-F grade | When auditing or installing an MCP server | | scan_skill | Deep security scan of an OpenClaw skill: prompt injection, AST+taint code analysis, ClawHavoc malware signatures, supply chain, rug pull. Returns A-F grade | Before installing any OpenClaw skill | | scanner_health | Check plugin health: engine status, daemon status, package data availability | Diagnostics and plugin status | | list_security_rules | List available security rules and fix templates | To check rule coverage for a language | | sbom_generate | Generate CycloneDX v1.5 SBOM for a project (8 lock file formats, 7 manifest formats) | Before releases, for compliance audits | | sbom_scan_vulnerabilities | Cross-reference SBOM against OSV.dev for CVEs with severity filtering | After generating SBOM, for security audits | | sbom_check_hallucinations | Verify all SBOM packages exist in official registries | Before deploying, to catch AI-invented packages | | sbom_diff | Compare current SBOM against baseline, detect added/removed/changed packages | In CI/CD to track dependency drift | | sbom_export_report | Generate HTML or JSON audit report from SBOM with vulnerability data | For PCI-DSS compliance, security reviews | | get_compliance_controls | Look up compliance controls with evaluation criteria (AIUC-1, SOC2, GDPR) | To understand compliance requirements | | evaluate_compliance | Evaluate project against compliance frameworks with evidence collection | For SOC2/GDPR technical compliance audits |
Quick Start
npx agent-security-scanner-mcp init claude-code
Restart your client after running init. That's it — the scanner is active.
> Other clients: Replace claude-code with cursor, claude-desktop, windsurf, cline, kilo-code, opencode, or cody. Run with no argument for interactive client selection.
Recommended Workflows
After Writing or Editing Code
scan_security → review findings → fix_security → verify fix
Before Committing
scan_git_diff → scan only changed files for fast feedback
scan_packages → verify all imports are legitimate
For PR Reviews
scan_git_diff --base main → scan PR changes against main branch
For Project Audits
scan_project → get A-F security grade and aggregated metrics
When Processing External Input
scan_agent_prompt → check for malicious instructions before acting on them
When Adding Dependencies
check_package → verify each new package name is real, not hallucinated
ClawHub Ecosystem Scanning (New in v3.11.0)
Scan AI agent skills for prompt injection, jailbreaks, and security threats:
# Scan entire ClawHub ecosystem (777 skills)
node index.js scan-clawhub
# Scan single skill file
node index.js scan-skill ./path/to/SKILL.md
# Standalone package
npm install -g clawproof
clawproof scan ./SKILL.md
Security Reports: We've scanned all 777 ClawHub skills:
- 69.5% have security issues
- 21.2% have critical vulnerabilities (Grade F - DO NOT INSTALL)
- 30.5% are completely safe (Grade A)
- 4,129 prompt injection patterns detected
See ClawHub Security Dashboard for interactive exploration of all 16,532 skills with searchable security grades and detailed findings.
Detection Capabilities:
- Prompt Injection (15 patterns): "ignore previous instructions", role manipulation
- Jailbreaks (4 patterns): DAN mode, developer mode, pretend scenarios
- Data Exfiltration (2 patterns): External URLs, base64 encoding
- Hidden Instructions (2 patterns): HTML comments, secret directives
Security Grading:
- A (0 points): Safe to install
- B (1-10): Low risk - review findings
- C (11-25): Medium risk - use with caution
- D (26-50): High risk - not recommended
- F (51+): DO NOT INSTALL - critical threats
🤖 LLM-Powered Code Review Agent (New in v4.0.0)
The code-review-agent is an LLM-powered semantic code review tool that uses intent profiling to distinguish safe patterns from dangerous ones based on project context.
Key Differentiator: Intent-Aware Analysis
Same code, different verdicts based on what the project is supposed to do:
| Pattern | Build Tool | E-Commerce App | |---------|------------|----------------| | subprocess.run() with hardcoded commands | ✅ Expected — that's its job | ⚠️ Suspicious — why does checkout need shell access? | | eval(req.query.filter) | ⚠️ Suspicious — build tools don't eval user input | ❌ Dangerous — product catalog shouldn't eval user input | | os.remove() | ✅ Expected for file organizer | ❌ Dangerous for auth service | | fs.writeFile(req.body.path) | ⚠️ Review — depends on context | ❌ Dangerous — auth service shouldn't write arbitrary files |
Quick Start
After installing agent-security-scanner-mcp, the cr-agent CLI is automatically available:
# Install the package (cr-agent is included)
npm install -g agent-security-scanner-mcp
# Analyze a project (no API key needed with claude-cli!)
npx cr-agent analyze ./path/to/project -p claude-cli --verbose
# View intent profile only
npx cr-agent intent ./path/to/project -p claude-cli
# Output as SARIF for GitHub Code Scanning
npx cr-agent analyze ./path/to/project -f sarif -p claude-cli
LLM Providers
| Provider | API Key Required | Command | |----------|------------------|---------| | Claude CLI | ❌ No (uses Claude Code's auth) | -p claude-cli | | Anthropic | ✅ ANTHROPIC_API_KEY | -p anthropic | | OpenAI | ✅ OPENAI_API_KEY | -p openai |
Features
- Intent Profiling — Reads README, dependencies, and structure to understand project purpose
- Dynamic Chunking — Large files split based on token budget, not hardcoded line limits
- 3 Output Formats — Colored terminal text, JSON, SARIF 2.1.0
- Dependency Graph — Resolves JS/TS/Python imports including barrel re-exports
- Prompt Injection Defense — System prompts mark repo content as untrusted input
CLI Options
| Flag | Description | Default | |------|-------------|---------| | -p, --provider | LLM provider (anthropic, openai, claude-cli) | anthropic | | -m, --model | Analysis model | claude-sonnet-4-20250514 / gpt-4o | | -c, --confidence | Confidence threshold (0-1) | 0.7 | | -f, --format | Output format (text, json, sarif) | text | | -v, --verbose | Show reasoning and suggested actions | false | | --exclude | Patterns to exclude | node_modules dist .git |
When to Use
| Use Case | Tool | |----------|------| | Fast, rule-based scanning (CI/CD) | scan_security (MCP tool) | | Deep semantic analysis with context | code-review-agent (LLM-powered) | | Package verification | check_package / scan_packages | | Prompt injection detection | scan_agent_prompt |
📖 Full documentation: [code-review-agent/README.md](./code-review-agent/README.md)
📦 SBOM / Supply Chain Analysis (New in v4.1.0)
Generate Software Bill of Materials (SBOM) and analyze dependencies for vulnerabilities across your entire supply chain.
Quick Start
# Generate SBOM for current project
npx agent-security-scanner-mcp sbom-generate .
# Scan for vulnerabilities against OSV.dev
npx agent-security-scanner-mcp sbom-vulnerabilities .
# Check for hallucinated packages
npx agent-security-scanner-mcp sbom-check-hallucinations .
# Compare against baseline (CI/CD)
npx agent-security-scanner-mcp sbom-diff . --save-baseline # First run
npx agent-security-scanner-mcp sbom-diff . # Subsequent runs
# Generate HTML audit report
npx agent-security-scanner-mcp sbom-report . --format html
Supported Ecosystems
| Ecosystem | Lock Files | Manifests | CLI Fallback | |-----------|------------|-----------|--------------| | npm | package-lock.json (v2/v3), yarn.lock (classic/berry), pnpm-lock.yaml | package.json | npm ls, pnpm list | | Python | poetry.lock, Pipfile.lock | requirements.txt, pyproject.toml | — | | Go | go.sum | go.mod | go list | | Rust | Cargo.lock | — | cargo metadata | | Ruby | Gemfile.lock | Gemfile | — | | Java | — | pom.xml, build.gradle | mvn dependency:tree |
SBOM Tools
sbom_generate
Generate a CycloneDX v1.5 SBOM for a project. Discovers all dependencies (direct + transitive) from lock files and manifests.
// Input
{ "directory_path": "./my-project", "verbosity": "compact" }
// Output
{
"total_components": 212,
"direct": 20,
"dev": 91,
"ecosystems": ["npm", "pypi"],
"components": [
{ "name": "express", "version": "4.18.2", "ecosystem": "npm", "isDirect": true }
]
}
sbom_scan_vulnerabilities
Cross-reference SBOM components against OSV.dev vulnerability database. Returns CVE IDs, CVSS scores, severity, and fix recommendations.
// Input
{ "directory_path": "./my-project", "severity_threshold": "medium" }
// Output
{
"total_vulnerabilities": 3,
"by_severity": { "critical": 1, "high": 1, "medium": 1 },
"vulnerabilities": [
{
"id": "GHSA-xxxx-yyyy-zzzz",
"package": "lodash",
"severity": "critical",
"cvss": 9.8,
"fixed_version": "4.17.21"
}
]
}
sbom_check_hallucinations
Check all packages in an SBOM against official registries to detect AI-invented package names.
// Input
{ "directory_path": "./my-project" }
// Output
{
"total_checked": 212,
"hallucinated_count": 1,
"unsupported_ecosystems": ["go", "java"],
"hallucinated": [
{ "name": "react-async-utils-helper", "ecosystem": "npm" }
]
}
sbom_diff
Compare current project SBOM against a stored baseline. Detects added, removed, and version-changed packages.
// Input (first run)
{ "directory_path": "./my-project", "save_baseline": true }
// Output
{ "message": "Baseline saved to .scanner/sbom-baseline.json" }
// Input (subsequent runs)
{ "directory_path": "./my-project" }
// Output
{
"added": [{ "name": "lodash", "version": "4.17.21", "ecosystem": "npm" }],
"removed": [],
"changed": [{ "name": "express", "fro
…
## Source & license
This open-source MCP server is cataloged on AgentStack and links to its original source — we do not rehost the code.
- **Author:** [sinewaveai](https://github.com/sinewaveai)
- **Source:** [sinewaveai/agent-security-scanner-mcp](https://github.com/sinewaveai/agent-security-scanner-mcp)
- **License:** MIT
- **Homepage:** https://www.npmjs.com/package/agent-security-scanner-mcp
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.