Security for the AI agent supply chain — scan agent skills and MCP servers for tool poisoning, exfiltration, and rug pulls.
Project description
vnx
Security for the AI agent supply chain.
vnx scans AI agent skills (SKILL.md + scripts) and MCP servers for what static
scanners miss: tool poisoning, credential exfiltration chains, rug pulls,
hidden-unicode smuggling, typosquats, and prompt-injection payloads — with an
evidence-based confidence engine built to keep false positives near zero.
╔═══════════════════════════════════╗
║ scan · gate · proxy ║
║ one engine, three checkpoints ║
╚═══════════════════════════════════╝
This is the
0.0.1name-reservation build. The full scanner (v0.2.0) is in final release preparation — 839 tests, CI-enforced benchmark of 100% recall on 12 rebuilt real-world incident PoCs (postmark-mcp, ClawHavoc, SANDWORM_MODE, Invariant tool-poisoning) and 0% false positives on benign skills. Star the repo to catch the drop.
What ships in v0.2.0
vnx scan— enumerate-everything static analysis: hidden files,.docx/zip unpacking,.pycvs source divergence, anti-truncation. 9 analyzers + an Opengrep taint engine tracing source→sink chains (env→network, file→egress, arg→exec). Correlation grouping collapses noise into named threats.vnx gate— blocking security hooks for Claude Code, Cursor, Codex CLI, and VS Code: malicious skills and MCP calls get denied before execution.vnx proxy— a runtime MCP firewall: tool-manifest pinning (rug-pull detection), argument DLP, response injection scanning, hash-chained audit log.- Offline-first. Zero accounts, zero telemetry, zero required API keys. Optional local-LLM (Ollama) and reputation layers are opt-in, never required.
- SARIF, GitHub Action, pre-commit, Docker, MCP-server mode — drops into whatever pipeline you already run.
Try the placeholder
uvx vnx # or: pipx run vnx
Links
- Repo: github.com/vnxrun/vnx
- Site: vnx.run
Apache-2.0 · built in public · no telemetry, ever
Project details
Release history Release notifications | RSS feed
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file vnx-0.0.1.tar.gz.
File metadata
- Download URL: vnx-0.0.1.tar.gz
- Upload date:
- Size: 7.1 kB
- Tags: Source
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/6.1.0 CPython/3.13.14
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
17e588ff542bbfb1329e2da1969afc38bbc005847eabce83af5003221d7bfea7
|
|
| MD5 |
f7a2e2720240016a3964f0708e6b0510
|
|
| BLAKE2b-256 |
ee99930e49318bc1d00743903bf5fcfbd5c9876929a9d3d5592ab5d0752b1906
|
Provenance
The following attestation bundles were made for vnx-0.0.1.tar.gz:
Publisher:
release.yml on vnxrun/vnx
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
vnx-0.0.1.tar.gz -
Subject digest:
17e588ff542bbfb1329e2da1969afc38bbc005847eabce83af5003221d7bfea7 - Sigstore transparency entry: 2277197194
- Sigstore integration time:
-
Permalink:
vnxrun/vnx@7f05410b7115f66e667c150562a61e6107a89aeb -
Branch / Tag:
refs/heads/main - Owner: https://github.com/vnxrun
-
Access:
private
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
release.yml@7f05410b7115f66e667c150562a61e6107a89aeb -
Trigger Event:
workflow_dispatch
-
Statement type:
File details
Details for the file vnx-0.0.1-py3-none-any.whl.
File metadata
- Download URL: vnx-0.0.1-py3-none-any.whl
- Upload date:
- Size: 7.5 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/6.1.0 CPython/3.13.14
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
bd40cfbc03aa42c3215bdb2c8eca3ffd5726bfc25d18ee57f2e3e0e7d3bfcfe3
|
|
| MD5 |
dfb6a058e173613396b751b9699fd4ca
|
|
| BLAKE2b-256 |
e7aec3bfe233661afacf67417125cc3d0a7d9686c8168a046d4d5cb277f87414
|
Provenance
The following attestation bundles were made for vnx-0.0.1-py3-none-any.whl:
Publisher:
release.yml on vnxrun/vnx
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
vnx-0.0.1-py3-none-any.whl -
Subject digest:
bd40cfbc03aa42c3215bdb2c8eca3ffd5726bfc25d18ee57f2e3e0e7d3bfcfe3 - Sigstore transparency entry: 2277197589
- Sigstore integration time:
-
Permalink:
vnxrun/vnx@7f05410b7115f66e667c150562a61e6107a89aeb -
Branch / Tag:
refs/heads/main - Owner: https://github.com/vnxrun
-
Access:
private
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
release.yml@7f05410b7115f66e667c150562a61e6107a89aeb -
Trigger Event:
workflow_dispatch
-
Statement type: