Back to tools

agent-security-scanner-mcp

An open-source MCP security scanner for AI coding agents and dev teams, used to produce checks for prompt injection, dependency/package risk, and code vulnerabilities before and after agent actions.

Tool categories
AgentDeveloper toolsEnterprise

Tool overview

Based on the evidence provided, I would classify this as a promising early open-source security component, not yet a broadly validated mature standard. The strongest direct evidence comes from the official GitHub repository, whose description explicitly mentions a prompt injection firewall, package hallucination detection, 1000+ vulnerability rules, and AST/taint analysis. GitHub stars and interactions are proof of attention, not proof of real-world detection quality, false-positive rates, coverage depth, or production reliability.

Its practical role is not a general AI coding assistant, not a full DevSecOps suite, and not a vector search, RAG, or database tool. A more accurate analogy is a security scanning or firewall layer exposed as an MCP service for AI coding agents. From the repository description, it appears designed to add security checks around agent actions involving code reading/writing, dependency selection, and task execution, with emphasis on prompt injection, hallucinated or risky packages, and vulnerability patterns in code. The “4.

Related social content