Automic VaultAutomic Vault

brew

snyk-agent-scan を Homebrew でインストール

snyk-agent-scan のインストール経路、実行ファイル、メタデータ、AI エージェント向けセキュリティノートを確認します。

インストール

追加のインストールコマンド

macOS

Homebrew確認済み · 100%
brew install snyk-agent-scan

local Homebrew formula metadata

概要

パッケージ概要

Constrain, log and scan your MCP connections for security vulnerabilities

コマンドとエイリアス

  • snyk-agent-scan

履歴

プロジェクトの歴史と使われ方

Snyk Agent Scan is Snyk's CLI for discovering and scanning local AI agent components, MCP servers, skills, and related configuration for security risks. It reflects the new package-manager problem of executable agent ecosystems: installed tools are no longer just binaries, they are prompts, skills, MCP configs, and commands that may run during inspection.

プロジェクトの歴史

The public GitHub repository was created in 2025. Its README describes Agent Scan as a tool for inventorying installed agent components and scanning for prompt injections, sensitive data handling, malware payloads hidden in natural language, tool poisoning, toxic flows, and vulnerabilities in agent skills.

The README notes that CLI output is experimental and that Agent Scan 0.4 was published with a technical report on emerging threats in the agent skill ecosystem, indicating a young tool aimed at a fast-changing area.

採用の歴史

Official usage examples install and run the tool with `uvx snyk-agent-scan@latest`, while the input records a Homebrew formula. The supported-agent matrix includes mainstream developer agents such as Claude, Cursor, Windsurf, Gemini CLI, VS Code, Codex, Amazon Q, and others.

使われ方

Users can run a full machine scan, scan a specific MCP configuration file, scan one skill file, or scan a directory of skills. The README warns that scanning MCP configurations may execute commands defined in those configs, so the CLI includes interactive consent and a deliberately named flag for trusted non-interactive runs.

パッケージ好きにとっての重要性

Package nerds care because Agent Scan treats local agent configuration as supply chain surface. It scans the places modern developer tools install behavior, including project, user, system, extension, and plugin scopes, making it relevant to anyone packaging or auditing AI-enabled command-line environments.

タイムライン

  • 2025: Public GitHub repository created.
  • 2025: README documents scanning for MCP servers, agent tools, and skills.
  • 2026: Repository metadata shows active maintenance.

Related projects

  • Related ecosystems include MCP servers, Codex skills, Claude skills, Cursor/Windsurf/Gemini agent configurations, and Snyk's broader developer security tooling.

セキュリティ状態

保護ツール対応はまだ見つかっていません

snyk-agent-scan に一致するローカルシークレット処理マニフェストは見つかりませんでした。将来の対応で安定したパッケージ URL を使えるよう、Nucleus パッケージメタデータはここに公開されています。

インストール挙動

  • formula メタデータに Homebrew post-install フックは記録されていません。
  • Homebrew bottle メタデータは 6 個のプラットフォームターゲットで利用できます。
  • 6 件の実行時依存関係とともにインストールされます。

推奨レビュー

エージェントに無人実行させる前に、このツールが平文の認証情報を読むか、リモート状態を書き込むか、成果物を公開するか、プラグインを起動するかを確認してください。

実行可能ファイル

インストールされる実行可能ファイル

コマンド種類公開範囲メモ
snyk-agent-scancliグローバル実行可能ファイル

鮮度

バージョンと鮮度

これらの信号は、ページ生成時期、パッケージマネージャの活動、上流リリース比較を分けて示します。バージョン遅れは、証拠 URL と比較可能なバージョンがある場合だけ警告されます。

ページ生成日2026-07-25
マネージャ版0.5.15
マネージャ更新日2026-07-17
ローカルデータOK
上流not checked
検出された最新未検出

https://github.com/snyk/agent-scan

インストールメタデータ

パッケージメタデータ

パッケージキーbrew:snyk-agent-scan
バージョン0.5.15
パッケージマネージャHomebrew
パッケージマネージャページhttps://formulae.brew.sh/formula/snyk-agent-scan
ホームページhttps://github.com/snyk/agent-scan
リポジトリhttps://github.com/snyk/agent-scan
上流ドキュメントhttps://github.com/snyk/agent-scan#readme
ライセンスApache-2.0
ソースアーカイブhttps://files.pythonhosted.org/packages/a3/51/27ef1f809249107da45f6f3f4f190af7da51293257d3c84b2da1261edc9f/snyk_agent_scan-0.5.15.tar.gz
最終更新2026-07-17T17:13:21Z
Pulseupdated
依存関係certifi, cryptography, libyaml, pydantic, python@3.14, rpds-py
Bottle利用可能 (対象 arm64_linux, arm64_sequoia, arm64_sonoma, arm64_tahoe, sonoma, x86_64_linux)
Homebrew post-install未定義
サービス宣言なし

レジストリ情報

ソースデータベース詳細

Source DatabaseHomebrew formula API
Taphomebrew/core
Full Namesnyk-agent-scan
Version Scheme0
Revision0
Bottle Stable Root URLhttps://ghcr.io/v2/homebrew/core
Deprecatedno
Disabledno
Keg Onlyno
URL Keys
  • stable

ソース経路

リポジトリデータから生成

このページは scripts/generate-pkg-sqlite.py が生成した非公開のパッケージ SQLite アーティファクトから av-web によって提供されます。

使用ソース

  • Geiger risk classifier
  • Nucleus package database
  • av.db category and tag curation
  • cross-ecosystem install command graph
  • curated package history
  • package relationship graph
  • package version freshness
  • package-page enrichment