{"repo":"sinewaveai/agent-security-scanner-mcp","free":true,"listed":false,"github":"https://github.com/sinewaveai/agent-security-scanner-mcp","clone":"git clone https://github.com/sinewaveai/agent-security-scanner-mcp.git","description":"Security scanner MCP server for AI coding agents. Prompt injection firewall, package hallucination detection (4.3M+ packages), 1000+ vulnerability rules with AST & taint analysis, auto-fix.","language":"JavaScript","stars":120,"topics":["ai-security","claude-code","cursor","hallucination-detection","mcp","mcp-server","prompt-injection","sast","security","vulnerability-scanner"],"license":"MIT","category":"mcp-servers","readme_excerpt":"agent-security-scanner-mcp Security scanner for AI coding agents, MCP servers, prompts, and AI-suggested packages. Run it before Claude Code, Cursor, Windsurf, Cline, OpenCode, or another agent trusts new code, tools, prompts, or dependencies. Copy-Paste Start Scan any repo and get an A-F agent security grade: Install the scanner into your AI coding client: Replace claude-code with cursor , claude-desktop , windsurf , cline , kilo-code , opencode , or cody . Audit an MCP server before adding it to an agent: Check AI-generated imports for package hallucinations: What It Catches Risk Why agents need it Command --- --- --- Vulnerable generated code Agents can introduce SQL injection, XSS, command injection, unsafe crypto, and secrets scan-project , scan-security , scan-diff MCP server attacks MCP tools can poison descriptions, spoof names, exfiltrate env vars, or execute commands scan-mcp Prompt injection Agents often process untrusted docs, tickets, pages, and tool output scan-prompt Unsafe agent actions Catch dangerous shell/file/network actions before execution scan-action Hallucinated packages AI often invents dependency names that attackers can later squat check-package , scan-packages SBOM and CVEs Generate CycloneDX SBOMs and scan dependencies with OSV.dev sbom-generate , sbom-vulnerabilities Semantic review LLM-powered review that uses project intent to find context-aware issues cr-agent Screenshots Project Scan MCP Server Audit Package Hallucination Detection Demos Run ","default_branch":null,"files":null,"tree":[],"storefront":"/r/sinewaveai","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/sinewaveai/agent-security-scanner-mcp/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}