‹ The Index

Agent Security Scanner

npm

AI agent security scanner and npm audit for MCP servers, Claude Code, Cursor, and Windsurf. Find prompt injection, hallucinated packages, secrets, unsafe tools, and vulnerable code.

Works with: Claude Code, Cursor, Claude Desktop, Codex CLI, Gemini CLI, Cline, Windsurf, VS Code (installable)
installable: each client documents how to load an MCP server of this type — that is the client's promise, not a claim verified against this capability

Category: Security — see all ranked ›

Work: Security review

Who it is for: Security engineer

Install (Claude Code):

claude mcp add agent-security-scanner -- npx -y agent-security-scanner-mcp
solid

“6 worked examples, 1 tools documented; short of deep on per-tool docs and a stated limitation and setup/auth”

This grade is wrong ›

Security audit

scanned 2026-08-19

Every finding is shown in full — which advisory, the version that fixes it, and the exact command run at install time. Nothing in this audit is behind a licence.

No known advisoriesclearchecked against OSV for 4.5.9 — this package, not its dependency tree
Runs a script at install timecodenode scripts/postinstall.js
No access inferred from declared dependenciesnothing it depends on reaches files, shell or network. This reads declarations only — built-in APIs are invisible to it, so absence of a declaration is not absence of access
No build provenanceno attestation — the published artifact cannot be traced to its source

What changed recently

You are reading this because you came looking. tashan Pro gives tashan doctor the history behind it, so a run over your own config says which of YOURS moved.

You searched for one. Check the rest of your stack:

npx tashan-cli doctor

Reads the config already on your machine and names what is dead, deprecated or running code at install time. No account, nothing uploaded.

tashan Pro$6/mo

We recorded 1 change to Agent Security Scanner in the last 45 days. Pro tells you on the day — for the servers in your own config, not the ones you thought to look up.

Start a 7-day trial › Everything measured on this page stays free.

Show your score

Measured this well? Put the live badge in your README — it updates as the score does.

tashan badge for Agent Security Scanner
[![tashan](https://tashan.sh/badge/pkg-agent-security-scanner-mcp.svg)](https://tashan.sh/capability/pkg-agent-security-scanner-mcp.html)

npm ↗  ·  source ↗  ·  pkg:agent-security-scanner-mcp

Already running this? Check your whole config — free, in your browser, nothing installed. Or npx tashan-cli doctor locally, which sends nothing at all.

Measured 2026-08-22  ·  scorer s5  ·  how  ·  something wrong here?