Skip to content
Back to skills

Snyk Agent Scan

ASecurity

Scan your AI agents, MCP servers, and skills for security vulnerabilities from the command line. Snyk Agent Scan discovers and audits every agent component on your machine — detecting prompt injections, tool poisoning, toxic flows, malware payloads, and credential handling issues across 15+ distinct risk categories.

  • 41 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added October 10, 2026
ai-agentspythonrustgogitapisecuritydocumentation

Works with

  • cli
  • api
  • mcp

Security analysis

A92/100
  • mediumInstalls packages at runtime which could introduce malicious dependencies

Pro shows the line behind each finding and how to fix it

Scanned October 10, 2026

npx -y skills add skillmds/skillmd --skill snyk-agent-scan --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Snyk Agent Scan?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Snyk Agent Scan
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/skillmds-snyk-agent-scan/badge)](https://www.skillsdirectory.com/skills/skillmds-snyk-agent-scan)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: "Snyk Agent Scan"
slug: "snyk-agent-scan"
description: "Scan your AI agents, MCP servers, and skills for security vulnerabilities from the command line. Snyk Agent Scan discovers and audits every agent component on your machine — detecting prompt injections, tool poisoning, toxic flows, malware payloads, and credential handling issues across 15+ distinct risk categories."
github_stars: 2508
verification: "security_reviewed"
source: "https://github.com/snyk/agent-scan"
author: "Snyk"
publisher_type: "company"
category: "Security & Verification"
framework: "MCP"
tool_ecosystem:
  github_repo: "snyk/agent-scan"
  github_stars: 2508
---


# Snyk Agent Scan

Scan your AI agents, MCP servers, and skills for security vulnerabilities from the command line. Snyk Agent Scan discovers and audits every agent component on your machine — detecting prompt injections, tool poisoning, toxic flows, malware payloads, and credential handling issues across 15+ distinct risk categories.

## Prerequisites

Python 3.10+, uv package manager, Snyk API token

## Installation

Use the upstream install or setup path that matches your environment:
- uv run pip install -e .
- uv run -m src.agent_scan.cli

Requirements and caveats from upstream:
- <a href="https://pypi.python.org/pypi/snyk-agent-scan"><img src="https://img.shields.io/pypi/v/snyk-agent-scan.svg" alt="snyk-agent-scan"/></a>
- <a href="https://pypi.python.org/pypi/snyk-agent-scan"><img src="https://img.shields.io/pypi/l/snyk-agent-scan.svg" alt="snyk-agent-scan license"/></a>
- <a href="https://pypi.python.org/pypi/snyk-agent-scan"><img src="https://img.shields.io/pypi/pyversions/snyk-agent-scan.svg" alt="snyk-agent-scan python version requirements"/></a>

Basic usage or getting-started notes:
- **Use --dangerously-run-mcp-servers** only in trusted environments where you've verified all MCP server commands
- To get started:
- **Sign up at [Snyk](https://snyk.io)** and get an API token from [https://app.snyk.io/account](https://app.snyk.io/account) (API Token → KEY → click to show).

- Source: https://github.com/snyk/agent-scan
- Extracted from upstream docs: https://raw.githubusercontent.com/snyk/agent-scan/HEAD/README.md

## Documentation

- https://github.com/snyk/agent-scan/blob/main/docs/scanning.md

## Source

- [Agent Skill Exchange](https://agentskillexchange.com/skills/snyk-agent-scan/)

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…