AcademySkillsDevelopment

Prism Scanner: security checks for AI agent skills and MCP

Security and engineering teams that review third-party AI agent extensions before allowing them on company devices.

  • Recommendedour rating
  • 27gitHub stars
  • Apache-2.0licence
  • 6 months agolast update
git clone https://github.com/aidongise-cell/prism-scanner.git
README.md

Loading the file...

What it does

An open-source scanner that analyzes the code of AI agent skills, plugins and MCP servers for malicious behavior before you install them. It also checks the system for leftover traces after an uninstall. Its 39 detection rules cover code, prompts and skill descriptions, including manipulative wording aimed at agents. It is installed with pip and runs from the command line.

Use cases

  1. 01Review a new agent skill before it reaches a laptop
  2. 02Scan MCP servers for suspicious code patterns
  3. 03Check for leftover files after removing an extension

Questions about
Prism Scanner: security checks for AI agent skills and MCP.

What is Prism Scanner: security checks for AI agent skills and MCP used for?

Security and engineering teams that review third-party AI agent extensions before allowing them on company devices. An open-source scanner that analyzes the code of AI agent skills, plugins and MCP servers for malicious behavior before you install them. It also checks the system for leftover traces after an uninstall. Its 39 detection rules cover code, prompts and skill descriptions, including manipulative wording aimed at agents. It is installed with pip and runs from the command line.

How do I install Prism Scanner: security checks for AI agent skills and MCP?

Run this in your terminal: git clone https://github.com/aidongise-cell/prism-scanner.git

Is Prism Scanner: security checks for AI agent skills and MCP open source?

Yes. The code is on GitHub (aidongise-cell/prism-scanner) under the Apache-2.0 licence.

Is Prism Scanner: security checks for AI agent skills and MCP safe to use?

It passed our automatic scan for credential theft, hidden instructions and risky install commands. Third party open source software. Sabemos AI does not maintain it. Check the code and permissions before you connect it to company data.