AI Agent Security Scanner
Paste the following prompt into your AI chat to install this skill:
Please install @user_239f6ce2/agent-security-scanner-huyiwanghe following https://skillhub.cn/install/skillhub.md.
About this skill
Problem
Multi-agent environments leave local configurations, scripts, MCP definitions, memory files, and skill files behind. Manual audits can miss hardcoded credentials, dangerous os.system or subprocess calls, suspicious data exfiltration URLs, prompt injection, MCP poisoning, and dependency supply-chain risks. The issue is not only malicious files, but scattered configs, behaviors, and dependencies across agent directories.
How It Works
The skill runs locally after license activation, then discovers targets:
- Built-in definitions: covers common AI coding and agent frameworks.
- Custom registry: add targets via config/custom_agents.json.
- General discovery: scans the user home directory and identifies unknown agents using markers such as MEMORY.md, AGENTS.md, mcp.json, agents/, and skills/.
It then executes 41 L1-L3 encrypted rules and 14 L4-L6 sensor rules, covering credential leakage, command execution, network requests, file operations, prompt injection, remote script execution, obfuscated encoding, supply-chain risk, MCP poisoning, and behavioral anomalies. It outputs self-contained HTML reports and structured JSON alert data, with date-based reports, incremental scans, and alert reuse.
Boundaries and Notes
The tool scans only agent data directories under the user home directory and does not access sensitive system paths such as /etc, /root, or Windows system directories; results remain in local HTML, JSON, and SQLite stores. Optional AI triage is disabled by default, and enabling it requires user-provided API endpoint and key configuration. The rule library is encrypted; --list-rules exposes the rule catalog, but concrete regex patterns are not published. Scheduled scans overwrite the current day's report while keeping date-named history.
Use Cases
- Security engineers scan local AI agents before release to check hardcoded credentials, dangerous commands, and prompt injection risks.
- Platform ops inspect multiple agent directories on developer machines and generate the day's HTML report plus JSON alert data.
- Compliance auditors export structured alerts to review AI agent configs, MCP definitions, and skill files for risk items.
- Agent developers scan `mcp.json`, scripts, and memory files before committing a custom skill to avoid sensitive paths and suspicious requests.
Best For
- Security engineers who audit AI agent configs, scripts, and MCP files.
- Platform ops engineers who maintain multiple local agents and need scheduled security inspections.
- Compliance auditors who need local HTML and JSON reports as evidence.
- Agent developers who check skill files, API keys, and dangerous commands before release.
Related Skills
A lightweight wrapper and automation tool for Jaeger-related GitHub scenarios.
Vault Wrap is a wrapping skill for Vault and GitHub automation.
Port management, threat-intel audits, drift checks, and multi-node monitoring for self-hosted infrastructure.
Provides health checks for HTTP, TCP, Ping, and log sources with dynamic-threshold alerts, anomaly detection, and scheduled inspection reports.