What it does
An offline security scanner for AI-agent repositories, skills, plugins and MCP servers. It runs locally with no dependencies and no telemetry, so you can audit untrusted code before it reaches your agent.
Use cases
- 01Scan a skill before installing it
- 02Audit an MCP server repository for risky code
- 03Review a plugin from an unknown source