Snyk Agent Scan
A Snyk CLI that discovers installed MCP servers, skills and agents on your machine and checks them for prompt injections and malicious payloads
Medium risk
We rate an entry medium when the tool runs code, makes network calls or reads project files. Check what exactly it does before installing.
Why this level
- Reads agent configs and files on the machine and sends results to the Snyk cloud using a token
- When scanning MCP configurations it runs the commands defined in them, asking for consent by default
Install
In your terminal, with SkillFoxx CLI
npx skillfoxx add cli/snyk-agent-scanDetects the agents on your machine, checks the risk and pins the version.
Other ways to install
Install the tool
pipx install snyk-agent-scanWithout pipx, pip install snyk-agent-scan works too.
Install uv, set the token export SNYK_TOKEN=... and scan the machine: uvx snyk-agent-scan@latest. You can point it at a specific MCP config or the ~/.claude/skills folder.
Other ways from the author
export SNYK_TOKEN=your-api-token-here
uvx snyk-agent-scan@latestScans the whole machine. You can pass a path to an MCP config or a skills folder, for example uvx snyk-agent-scan@latest ~/.claude/skills.
This is third-party code. Review the repository files before installing.
What it does
Agent Scan discovers the agent components installed on your machine, MCP server configs, tools and skills, and checks them for common threats. It looks for prompt injections, tool poisoning and shadowing, toxic flows, malicious code, suspicious download URLs, insecure credential handling and hardcoded secrets. Auto-discovery covers Claude Code and Desktop, Cursor, VS Code, GitHub Copilot, Gemini CLI, Windsurf, Codex and other agents on macOS, Linux and Windows. It runs via uvx or as a signed standalone binary, prints results to the terminal and sends them to your Snyk account. Skill analysis can be turned off with --no-skills.
Who it is for. For security engineers, devops and developers who vet their MCP servers and skills before using them.
Good fit when
- Before connecting a new MCP server or skill from an untrusted source
- You need to audit all agent components on a work machine
- You need to add MCP and skill checks to CI or a regular security process
Not a fit when
- You have no Snyk account and SNYK_TOKEN; scans do not run without them
- You need a stable output contract: the CLI output is marked experimental
Example request
Scan my Claude Code MCP servers and skills for prompt injections and insecure credential handlingLimitations
You need a Snyk account and a token in SNYK_TOKEN, and results are sent to the Snyk cloud. When scanning MCP configurations the tool executes the commands defined in them to fetch tool descriptions, so scans are best run in a sandbox; by default each stdio server requires explicit consent. The maintainers call the CLI output experimental and may change it between releases. No npm package is published; install via uvx or the binary. Licensed under Apache-2.0.
How to disable. It is a one-off CLI with nothing to install into the system. When run via uvx the cache is cleared with uv's own tools; simply delete the standalone binary.
Security check
- Reads agent configs and files on the machine and sends results to the Snyk cloud using a token
- When scanning MCP configurations it runs the commands defined in them, asking for consent by default
README in short
The README describes Agent Scan as a security scanner for agent components: MCP servers, tools and skills. The tool auto-discovers configs of popular agents on macOS, Linux and Windows and looks for prompt injections, tool poisoning, toxic flows, malicious code, insecure credential handling and other risks. It runs via uvx or a signed standalone binary shipped with an SBOM, checksums and a GPG verification guide. It needs a SNYK_TOKEN, and results go to Snyk. The output format is marked experimental and no npm package is published.
FAQ
Is this an official Snyk tool?
Yes, the repository and the snyk-agent-scan package are published by Snyk itself under Apache-2.0.
Does the scanner really run commands from my configs?
Yes, when parsing an MCP configuration it starts the stdio servers to fetch tool descriptions. By default each run needs consent, and scans are best done in a sandbox.
Related
A code security audit skill by Cloudflare: the agent runs recon, coverage-led hunting and independent verification of findings, then produces a structured repor
NVIDIA's open stack for running OpenClaw, Hermes and LangChain Deep Agents in OpenShell sandboxes with network policy and managed inference
Security scanner for agent skills and MCP servers: finds prompt injection, data exfiltration and supply chain risks before install
Static code analysis with rules that look like source code, plus a built-in MCP server for AI agents