MEDUSA

A security scanner CLI for code and AI agents: vets .claude, hooks, MCP configs and SKILL.md before cloning and finds leaked keys

CLI

Medium risk

We rate an entry medium when the tool runs code, makes network calls or reads project files. Check what exactly it does before installing.

Why this level

  • Runs code and reads project files and histories
  • Reaches the network to vet remote repos
  • In-place redaction changes files
All reasons and checks

pantheon-security/medusa

Install

In your terminal, with SkillFoxx CLI

npx skillfoxx add cli/medusa

Detects the agents on your machine, checks the risk and pins the version.

Other ways to install

Install the tool

pipx install medusa-security

Without pipx, pip install medusa-security works too.

You will need: pipx

Checked against the repository on Sep 25, 2026, commit 5f217ed.

Text for your agent

Install the scanner: pip install medusa-security. Scan a project: medusa scan . Vet a remote repo: medusa scan --git owner/repo.

Other ways from the author
pip install medusa-security
medusa scan .

Works on Windows, macOS and Linux; external tools are optional.

This is third-party code. Review the repository files before installing.

What it does

MEDUSA scans projects and repositories against a large rule set aimed at vulnerabilities in code, AI apps, agents and MCP servers. With medusa scan --git you can vet any GitHub repo before cloning: the scanner recognizes dozens of AI editor config files that become attack vectors, including .cursor/mcp.json, CLAUDE.md, SKILL.md and AGENTS.md. medusa secrets scan finds leaked keys and tokens in Claude Code, Cursor and Copilot chat histories and in shell history, with interactive in-place redaction. It works right after install with no required external tools, and auto-detects installed linters such as bandit and eslint.

Who it is for. For developers and security engineers who install third-party skills, MCP servers and repos and want to vet them first.

Good fit when

  • Before cloning a third-party repo with skills or MCP
  • You need to check .claude, hooks and editor configs for anything suspicious
  • You need to find leaked keys in chat and shell history

Not a fit when

  • You need a full manual security audit
  • The project is outside supported languages and formats

Example request

Use medusa to vet this GitHub repo before I clone it

Limitations

It is a static signature and rule scanner: it catches known patterns but does not replace manual review or guarantee a project is safe. In-place secret redaction changes your files, so review the edits. Model scanning and external linters need extra tools.

How to disable. Remove the package: pip uninstall medusa-security, or delete the virtual environment that holds it.

Security check

  • Runs code and reads project files and histories
  • Reaches the network to vet remote repos
  • In-place redaction changes files

README in short

The README presents MEDUSA as an AI-first security scanner for agents and MCP that works right after pip install. It describes scanning a project, a remote repo and finding leaked secrets in chat and shell histories. It lists categories of dangerous editor config files and known supply chain attacks. There are extra modes for ML models and external linters. AGPL-3.0 licensed.

FAQ

Can I vet a repo without cloning it?

Yes, medusa scan --git owner/repo checks a remote repo and recognizes dangerous AI editor configs.

Does it change my files?

A normal scan only reads. Redacting leaked secrets in place changes files and is confirmed by you.

Editors’ pick

A code security audit skill by Cloudflare: the agent runs recon, coverage-led hunting and independent verification of findings, then produces a structured repor

SkillMedium riskNo VPN needed22.6KRepository stars
Editors’ pick

NVIDIA's open stack for running OpenClaw, Hermes and LangChain Deep Agents in OpenShell sandboxes with network policy and managed inference

CLIHigh risk22.6KRepository stars
Editors’ pick

Security scanner for agent skills and MCP servers: finds prompt injection, data exfiltration and supply chain risks before install

CLIMedium riskNo VPN needed18.5KRepository stars
Official

Static code analysis with rules that look like source code, plus a built-in MCP server for AI agents

CLIMedium risk16.8KRepository stars
Foxx AIMEDUSA

I am Foxx AI and I have already vetted this tool. Ask about install, setup or anything else, and I will keep it simple.