Skip to main content

agentscan

The trust layer for AI agent skills.

A deterministic, local security scanner for AI agent skills — plus the Trusted Distribution: a curated, continuously audited package registry.

pip install agentscan-cli

agentscan scan ~/.claude/skills     # free, local, deterministic
agentscan activate                  # Trusted Distribution license
agentscan search                    # what's available
agentscan install security-engineer # one command, verified
agentscan update                    # like brew upgrade

The scanner (free, open source, MIT)

Scan any skill, MCP server, or agent config for what it actually does — shell, exfiltration, secrets, supply-chain, obfuscation — before you run it in your agent.

  • Facts, not verdicts. Every finding is a checkable fact with file:line. The scanner never calls anything "malicious" — that verdict is yours.
  • Deterministic, not ML. Regex, entropy, structure. Same input, same report, every time.
  • Zero dependency, zero execution. Pure Python stdlib. Never runs a skill, never calls out, works offline.
$ agentscan scan ~/Downloads/suspicious-skill

agentscan 0.4.0  /home/you/Downloads/suspicious-skill
scanned 1 artifact(s), 14 finding(s)

  ARTIFACT  [claude-skill] auto-updater
  CRITICAL [exfil] Local secret read piped to network
           SKILL.md:41
  CRITICAL [secrets] AWS Access Key
           SKILL.md:24
  ...
  summary: critical=3 high=2 medium=5 low=2 info=2
  note: findings are observed patterns, not verdicts. Review each before acting.

Exit codes: 0 clean · 1 findings at/above threshold · 2 usage error.

What it checks

Check Observes
shell bash/sh/python -c/node -e/exec/eval/subprocess invocations
filesystem rm -r/-f, shutil.rmtree, git reset --hard/clean/push --force, chmod 777
network curl/wget/fetch/requests, URLs, credential-in-URL, IP literals, cleartext http
secrets 20+ token formats (AWS, GitHub, Slack, Stripe, OpenAI, Anthropic, JWT, PEM…)
license declared license — recognized vs. unrecognized vs. missing
supply_chain curl|bash pipes, git clone, unpinned pip/npm, script downloads
prompt_patterns high-risk prompt-manipulation phrasing — flagged, never "detected"
exfil credentialed webhooks, env-in-URL, secret-read → network
obfuscation decode-to-execute chains, nested eval/exec, hex escapes
config_tamper remote MCP servers, hook commands, npm lifecycle scripts

Artifacts detected: claude-skill, mcp-server, cursor-rules, context-file, github-actions, npm-package, generic.

Usage

python3 -m agentscan <dir>                  # human report
python3 -m agentscan <dir> --json           # machine-readable
python3 -m agentscan <dir> --sarif          # SARIF 2.1.0 (GitHub code scanning)
python3 -m agentscan <dir> --severity high  # only high+ fails exit code

The Trusted Distribution (paid)

Access to curated, security-reviewed packages. Buy once ($49), receive a license key, activate, install. No dashboard, no browser login, no accounts — it's a developer tool.

Buy ($49, Polar)
  ↓
License key (XXXX-XXXX-XXXX)
  ↓
pip install agentscan-cli
  ↓
agentscan activate            → POST /api/verify-license
  ↓
agentscan search              → GET  /api/packages
  ↓
agentscan install <package>   → download → sha256 → extract → install
  ↓
agentscan update              → like brew upgrade

Architecture

PyPI (agentscan CLI, MIT)
   ↓
agentscan.baldbee.me (Next.js site + API route handlers)
   ↓
Polar (license verification — source of truth, no users table)
   ↓
agentscan-registry (private GitHub repo)
   ├── packages/        source of truth
   ├── packages.json    generated catalog (sha256 per package)
   └── GitHub Releases  tarball distribution
   ↓
~/.agentscan/  license · installed.json · config.json · cache/
~/.claude/skills/<package>/  installed package

The website and API are the same Next.js application. No separate backend, no database, no object storage. Git is the source of truth; GitHub Releases are the CDN.

Commands

agentscan activate                 # prompt for license → verify → store
agentscan logout                   # remove local license
agentscan whoami                   # show active license
agentscan search                   # catalog from GET /api/packages
agentscan install <package>        # verified install into Claude Code
agentscan update                   # upgrade installed packages
agentscan verify                   # signature · latest · audit · intact

Local state

Everything lives in ~/.agentscan/:

~/.agentscan/
  license          the activated license (JSON)
  installed.json   {package-id: version}
  config.json      api_url override (optional)
  cache/           downloaded tarballs

Package format

A package is not just a skill. It may contain agents, skills, slash commands, templates, workflows, and knowledge:

security-engineer/
  manifest.json     id, title, version, description, license, requires
  agents/           optional agent definitions
  skills/           SKILL.md files
  commands/         optional slash commands
  templates/        optional templates
  knowledge/        reference material
  audit.json        latest deterministic scan result
  signature.sig     placeholder — real signing lands with the Polar milestone
  README.md

manifest.json ships one package definition per the catalog shape:

{ "packages": [ { "id": "security-engineer", "title": "Security Engineer",
  "version": "1.0.1", "description": "…", "sha256": "…",
  "release": "v1.0.1", "asset": "security-engineer-1.0.1.tar.gz" } ] }

Status of the paid layer

The API endpoints and license verification are currently mocked:

  • POST /api/verify-license accepts any well-formed XXXX-XXXX-XXXX key. Real validation against Polar is the next milestone; the CLI response shape (customer, plan, expiry) is already the Polar contract.
  • Package downloads are real: served from the private GitHub registry, checksum-verified end to end.
  • signature.sig is a placeholder; cryptographic signing is designed in (agentscan verify is structured to add it without CLI changes).

The numbers (4,000 skills measured)

We scanned a random sample of 4,000 unique skills across 174 public repos:

Signal % of skills
No recognizable license 93.6%
Invokes shell / interpreter 75.3%
Supply-chain patterns (curl|bash, unpinned installs) 23.1%
Credential-format strings 14.7%
Destructive filesystem ops 7.6%
Exfiltration sinks 4.2%
Prompt-manipulation phrasing 3.3%
Obfuscation chains 0.4%
Any high/critical finding 18.0%

Full methodology: CORPUS-REPORT.md


Development

python3 -m unittest discover -s tests -v   # 49 tests

Pure stdlib, Python 3.8+, works offline. To point the CLI at a local server:

export AGENTSCAN_API_URL=http://localhost:3100   # overrides the default API

License

MIT © baldbee

Independent project. Not affiliated with Anthropic, Snyk, or any vendor. Patterns modeled on gitleaks/trufflehog (secrets), OWASP Agentic Top 10, MCPGuard threat taxonomy, and Snyk's ToxicSkills findings.

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

agentscan_cli-0.4.0.tar.gz (40.2 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

agentscan_cli-0.4.0-py3-none-any.whl (41.3 kB view details)

Uploaded Python 3

File details

Details for the file agentscan_cli-0.4.0.tar.gz.

File metadata

  • Download URL: agentscan_cli-0.4.0.tar.gz
  • Upload date:
  • Size: 40.2 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/7.0.0 CPython/3.11.15

File hashes

Hashes for agentscan_cli-0.4.0.tar.gz
Algorithm Hash digest
SHA256 2e242004ee392776eec0a57c019a9013639f99c2ae32a6a52f1d74eb75295e6e
MD5 ac15c68140ca3efaad9149efeb47908f
BLAKE2b-256 9707d47d31eece629bb53b4efad08d8abbb32e4c55e5e2a5e88de0dc71c517df

See more details on using hashes here.

File details

Details for the file agentscan_cli-0.4.0-py3-none-any.whl.

File metadata

  • Download URL: agentscan_cli-0.4.0-py3-none-any.whl
  • Upload date:
  • Size: 41.3 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/7.0.0 CPython/3.11.15

File hashes

Hashes for agentscan_cli-0.4.0-py3-none-any.whl
Algorithm Hash digest
SHA256 fae5dd5653046c7774682622a46bd40b4d77e2db3929ce9c1ac21e6c0c58656f
MD5 b9d5acc193ba8c730d88bff8168ec220
BLAKE2b-256 5019adab0505bbc6f61d7785d0539983488fe4af52449b595056f433e849bfe2

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page