Snyk Agent Scan
Security scanner for AI agents, MCP servers and agent skills. Auto-discovers configs from Claude Code, Cursor, Windsurf, Gemini CLI. Detects 15+ risks: prompt injection, tool poisoning, tool shadowing, toxic flows. Formerly mcp-scan.
Strengths
- Detects 15+ risks: prompt injection, tool poisoning, tool shadowing, toxic flows
- Auto-discovers configs: Claude Code, Cursor, Windsurf, Gemini CLI scanned
- One uvx snyk-agent-scan@latest command scans the whole machine in 30 seconds
- Detailed reports: offending MCP server, risk type, suggested remediation
Limitations
- Advanced features (auto-fix, CI integration) require a paid Snyk token
- Possible false positives on legitimate MCP servers with rich descriptions
- Scope limited to agent configs, does not scan your app source code
Best for
- Any Claude Code setup with community MCP servers installed
- Before every commit or deployment of a new MCP server to production