Skip to main content
aitoolsatlas.ai
BlogAbout

Explore

  • All Tools
  • Comparisons
  • Best For Guides
  • Blog

Company

  • About
  • Contact
  • Editorial Policy

Legal

  • Privacy Policy
  • Terms of Service
  • Affiliate Disclosure
Privacy PolicyTerms of ServiceAffiliate DisclosureEditorial PolicyContact

© 2026 aitoolsatlas.ai. All rights reserved.

Find the right AI tool in 2 minutes. Independent reviews and honest comparisons of 890+ AI tools.

  1. Home
  2. Tools
  3. Sinewave Agent Security Scanner
OverviewPricingReviewWorth It?Free vs PaidDiscountAlternativesComparePros & ConsIntegrationsTutorialChangelogSecurityAPI
security🔴Developer
S

Sinewave Agent Security Scanner

An open-source, MIT-licensed security scanner — "npm audit for AI agents and MCP servers" — that audits code, MCP tools, prompts, skills, and AI-suggested dependencies over MCP or CLI.

Starting atFree (MIT license)
Visit Sinewave Agent Security Scanner →
💡

In Plain English

An open-source, MIT-licensed security scanner — "npm audit for AI agents and MCP servers" — that audits code, MCP tools, prompts, skills, and AI-suggested dependencies over MCP or CLI.

OverviewFeaturesPricingUse CasesFAQ

Overview

Sinewave's agent-security-scanner-mcp positions itself as "npm audit for AI agents and MCP servers": a free, MIT-licensed scanner that checks code, MCP tools, prompts, skills, and AI-suggested dependencies before your agent trusts them. It is built MCP-first — one command (npx agent-security-scanner-mcp init claude-code) installs it as an MCP server into Claude Code, Cursor, Claude Desktop, Windsurf, Cline, Kilo Code, OpenCode, or Cody, exposing tools the agent can call itself. The full version ships 1,700+ security rules across 12 languages with AST and taint analysis, cross-file data-flow tracking, and around 19 MCP tools: scansecurity and fixsecurity (120 auto-fix templates), scanproject with A-F grading, scangitdiff for PR reviews, checkpackage and scanpackages that verify imports against 4.3M+ real packages to catch AI-hallucinated dependencies, scanagentprompt (59 prompt-injection rules with multi-encoding bypass hardening), scanagentaction for pre-execution ALLOW/WARN/BLOCK checks on shell commands, and scanmcp_server, which grades third-party MCP servers for unicode poisoning, tool-name spoofing, and rug pulls. Later versions add CycloneDX SBOM generation with OSV.dev CVE scanning, SOC2/GDPR technical compliance evaluation, an LLM-powered code-review agent with intent profiling (works via Claude CLI with no API key), and GitHub Actions CI integration. A lightweight sibling package, @prooflayer/security-scanner (81.5KB, 400+ rules, zero Python), covers fast regex-only scanning. The project claims 97.7% benchmark precision.

🎨

Vibe Coding Friendly?

▼
Difficulty:intermediate

Suitability for vibe coding depends on your experience level and the specific use case.

Learn about Vibe Coding →

Was this helpful?

Key Features

Feature information is available on the official website.

View Features →

Pricing Plans

Open source

Free (MIT license)

  • ✓Full scanner via npm/npx
  • ✓1,700+ rules, 12 languages, AST + taint analysis
  • ✓All MCP tools, SBOM, compliance, and CI features
  • ✓Lightweight @prooflayer/security-scanner variant (81.5KB, 400+ rules)
See Full Pricing →Free vs Paid →Is it worth it? →

Ready to get started with Sinewave Agent Security Scanner?

View Pricing Options →

Best Use Cases

🎯

Auditing an MCP server before adding it to Claude Code, Cursor, or Windsurf

⚡

Letting a coding agent scan and auto-fix its own generated code

🔧

Catching AI-hallucinated package names before installing dependencies

🚀

Gating CI/CD and PRs with security scans and SBOM diffs

💡

Screening external input for prompt injection before an agent acts on it

Pros & Cons

✓ Pros

  • ✓MIT-licensed and fully open source — no vendor gating on higher-value features
  • ✓MCP-first design lets the coding agent scan its own output without a human in the loop
  • ✓Purpose-built for agent-specific failure modes: prompt injection, hallucinated packages, tool spoofing
  • ✓Claimed 97.7% benchmark precision, with 120 auto-fix templates to close the loop from detection to remediation
  • ✓Lightweight @prooflayer variant is a viable pre-commit or CI check when the full scanner is too heavy

✗ Cons

  • ✗Precision claim (97.7%) is self-reported on the vendor's own benchmark, not an independent evaluation
  • ✗Full scanner requires Python plus the AST toolchain — heavier install than a pure JS pre-commit hook
  • ✗Auto-fixes are template-based; complex vulnerabilities may need human review after the rewrite
  • ✗Rule coverage is language-broad but you should still verify depth for your specific stack
  • ✗MCP server auditing scores are only as good as the point-in-time snapshot — a compliant server can still rug-pull on a later run

Frequently Asked Questions

How much does Sinewave Agent Security Scanner cost?+

Sinewave Agent Security Scanner pricing starts at Free (MIT license). They offer a single pricing plan.
🦞

New to AI tools?

Read practical guides for choosing and using AI tools

Read Guides →

Get updates on Sinewave Agent Security Scanner and 370+ other AI tools

Weekly insights on the latest AI tools, features, and trends delivered to your inbox.

No spam. Unsubscribe anytime.

User Reviews

No reviews yet. Be the first to share your experience!

Quick Info

Category

security

Website

github.com/sinewaveai/agent-security-scanner-mcp
🔄Compare with alternatives →

Try Sinewave Agent Security Scanner Today

Get started with Sinewave Agent Security Scanner and see if it's the right fit for your needs.

Get Started →

Need help choosing the right AI stack?

Take our 60-second quiz to get personalized tool recommendations

Find Your Perfect AI Stack →

Want a faster launch?

Explore 20 ready-to-deploy AI agent templates for sales, support, dev, research, and operations.

Browse Agent Templates →

More about Sinewave Agent Security Scanner

PricingReviewAlternativesFree vs PaidPros & ConsWorth It?Tutorial

📚 Related Articles

MCP Security Best Practices: Keep Your AI Tools Safe

Explore MCP Security Best Practices: Keep Your AI Tools Safe with our comprehensive guide. Practical insights, expert analysis, and actionable strategies to help you succeed.

2026-04-085 min read

AI Agent Security: The Complete Enterprise Guide for 2026

Comprehensive guide to securing AI agents in enterprise environments. Learn governance, compliance, and deployment strategies for production-ready AI systems.

2026-04-085 min read

A2A Protocol Security and Governance: What You Need to Know

A2A protocol was built with enterprise security from day one. Here's how it handles authentication, authorization, and trust between AI agents — plus the governance challenges you need to prepare for.

2026-04-085 min read

AI Agent Security for Business: Protecting Your Automated Systems from Real-World Threats (2026)

AI agents that handle business operations introduce new security risks that traditional cybersecurity doesn't cover. Here's how to protect your agents from prompt injection, data theft, and operational failures — with practical tools and implementation strategies.

2026-02-2717 min read