What it does
An open-source scanner that analyzes the code of AI agent skills, plugins and MCP servers for malicious behavior before you install them. It also checks the system for leftover traces after an uninstall. Its 39 detection rules cover code, prompts and skill descriptions, including manipulative wording aimed at agents. It is installed with pip and runs from the command line.
Use cases
- 01Review a new agent skill before it reaches a laptop
- 02Scan MCP servers for suspicious code patterns
- 03Check for leftover files after removing an extension