Honest pros, cons, and verdict on this security tool
✅ MIT-licensed and fully open source — no vendor gating on higher-value features
Starting Price
Free (MIT license)
Free Tier
No
Category
security
Skill Level
Developer
An open-source, MIT-licensed security scanner — "npm audit for AI agents and MCP servers" — that audits code, MCP tools, prompts, skills, and AI-suggested dependencies over MCP or CLI.
Sinewave's agent-security-scanner-mcp positions itself as "npm audit for AI agents and MCP servers": a free, MIT-licensed scanner that checks code, MCP tools, prompts, skills, and AI-suggested dependencies before your agent trusts them. It is built MCP-first — one command (`npx agent-security-scanner-mcp init claude-code`) installs it as an MCP server into Claude Code, Cursor, Claude Desktop, Windsurf, Cline, Kilo Code, OpenCode, or Cody, exposing tools the agent can call itself. The full version ships 1,700+ security rules across 12 languages with AST and taint analysis, cross-file data-flow tracking, and around 19 MCP tools: scan_security and fix_security (120 auto-fix templates), scan_project with A-F grading, scan_git_diff for PR reviews, check_package and scan_packages that verify imports against 4.3M+ real packages to catch AI-hallucinated dependencies, scan_agent_prompt (59 prompt-injection rules with multi-encoding bypass hardening), scan_agent_action for pre-execution ALLOW/WARN/BLOCK checks on shell commands, and scan_mcp_server, which grades third-party MCP servers for unicode poisoning, tool-name spoofing, and rug pulls. Later versions add CycloneDX SBOM generation with OSV.dev CVE scanning, SOC2/GDPR technical compliance evaluation, an LLM-powered code-review agent with intent profiling (works via Claude CLI with no API key), and GitHub Actions CI integration. A lightweight sibling package, @prooflayer/security-scanner (81.5KB, 400+ rules, zero Python), covers fast regex-only scanning. The project claims 97.7% benchmark precision.
per month
Sinewave Agent Security Scanner delivers on its promises as a security tool. While it has some limitations, the benefits outweigh the drawbacks for most users in its target market.
An open-source, MIT-licensed security scanner — "npm audit for AI agents and MCP servers" — that audits code, MCP tools, prompts, skills, and AI-suggested dependencies over MCP or CLI.
Yes, Sinewave Agent Security Scanner is good for security work. Users particularly appreciate mit-licensed and fully open source — no vendor gating on higher-value features. However, keep in mind precision claim (97.7%) is self-reported on the vendor's own benchmark, not an independent evaluation.
Sinewave Agent Security Scanner starts at Free (MIT license). Check their pricing page for the most current rates and features included in each plan.
Sinewave Agent Security Scanner is best for Auditing an MCP server before adding it to Claude Code, Cursor, or Windsurf and Letting a coding agent scan and auto-fix its own generated code. It's particularly useful for security professionals who need advanced features.
There are several security tools available. Compare features, pricing, and user reviews to find the best option for your needs.
Last verified March 2026