
MCP'S
agent-scan
by Snyk
Overview
Security scanner for AI agents, MCP servers, and agent skills.
Details
snyk-agent-scan is a Snyk GitHub project described as a security scanner for AI agents, MCP servers, and agent skills. Its scanning documentation says it scans a machine for agents, MCP servers, and skills, and can auto-discover configurations for tools such as Claude, Cursor, Gemini CLI, and Windsurf. Its issue-code reference documents security issues detected by the scanner, including compromised MCP server risks such as prompt injection in tool descriptions.
When to Use
Scan a local machine for AI agents MCP servers and agent skills that may need security review. Review detected agent or MCP-server findings against Snyk’s issue-code reference including compromised MCP server risks such as prompt injection in tool descriptions.
Getting Started
- Open the GitHub repository at https://github.com/snyk/agent-scan.
- Read the scanning documentation at https://github.com/snyk/agent-scan/blob/main/docs/scanning.md.
- Run a scan in an environment where agent
- MCP server
- or skill configurations may exist
- then review findings using the issue-code reference at https://github.com/snyk/agent-scan/blob/main/docs/issue-codes.md.
Key Features
- •Scans a machine for agents
- •MCP servers
- •and skills.
- •Auto-discovers configurations for tools such as Claude
- •Cursor
- •Gemini CLI
- •and Windsurf.
- •Documents detected security issues in an issue-code reference.
- •Includes coverage for compromised MCP server risks such as prompt injection in tool descriptions.
Capabilities
- •agent-security-scanning
- •mcp-server-scanning
- •agent-skill-scanning
- •configuration-auto-discovery
- •security-issue-reporting
Last updated Jun 4, 2026