An open-source, MIT-licensed security scanner — "npm audit for AI agents and MCP servers" — that audits code, MCP tools, prompts, skills, and AI-suggested dependencies over MCP or CLI.
An open-source, MIT-licensed security scanner — "npm audit for AI agents and MCP servers" — that audits code, MCP tools, prompts, skills, and AI-suggested dependencies over MCP or CLI.
Sinewave's agent-security-scanner-mcp positions itself as "npm audit for AI agents and MCP servers": a free, MIT-licensed scanner that checks code, MCP tools, prompts, skills, and AI-suggested dependencies before your agent trusts them. It is built MCP-first — one command (npx agent-security-scanner-mcp init claude-code) installs it as an MCP server into Claude Code, Cursor, Claude Desktop, Windsurf, Cline, Kilo Code, OpenCode, or Cody, exposing tools the agent can call itself. The full version ships 1,700+ security rules across 12 languages with AST and taint analysis, cross-file data-flow tracking, and around 19 MCP tools: scansecurity and fixsecurity (120 auto-fix templates), scanproject with A-F grading, scangitdiff for PR reviews, checkpackage and scanpackages that verify imports against 4.3M+ real packages to catch AI-hallucinated dependencies, scanagentprompt (59 prompt-injection rules with multi-encoding bypass hardening), scanagentaction for pre-execution ALLOW/WARN/BLOCK checks on shell commands, and scanmcp_server, which grades third-party MCP servers for unicode poisoning, tool-name spoofing, and rug pulls. Later versions add CycloneDX SBOM generation with OSV.dev CVE scanning, SOC2/GDPR technical compliance evaluation, an LLM-powered code-review agent with intent profiling (works via Claude CLI with no API key), and GitHub Actions CI integration. A lightweight sibling package, @prooflayer/security-scanner (81.5KB, 400+ rules, zero Python), covers fast regex-only scanning. The project claims 97.7% benchmark precision.
Was this helpful?
Feature information is available on the official website.
View Features →Free (MIT license)
Ready to get started with Sinewave Agent Security Scanner?
View Pricing Options →Weekly insights on the latest AI tools, features, and trends delivered to your inbox.
No reviews yet. Be the first to share your experience!
Get started with Sinewave Agent Security Scanner and see if it's the right fit for your needs.
Get Started →Take our 60-second quiz to get personalized tool recommendations
Find Your Perfect AI Stack →Explore 20 ready-to-deploy AI agent templates for sales, support, dev, research, and operations.
Browse Agent Templates →Explore MCP Security Best Practices: Keep Your AI Tools Safe with our comprehensive guide. Practical insights, expert analysis, and actionable strategies to help you succeed.
Comprehensive guide to securing AI agents in enterprise environments. Learn governance, compliance, and deployment strategies for production-ready AI systems.
A2A protocol was built with enterprise security from day one. Here's how it handles authentication, authorization, and trust between AI agents — plus the governance challenges you need to prepare for.
AI agents that handle business operations introduce new security risks that traditional cybersecurity doesn't cover. Here's how to protect your agents from prompt injection, data theft, and operational failures — with practical tools and implementation strategies.