macOS
brew install snyk-agent-scanlocal Homebrew formula metadata
安装
brew install snyk-agent-scanlocal Homebrew formula metadata
概览
Constrain, log and scan your MCP connections for security vulnerabilities
历史
Snyk Agent Scan is Snyk's CLI for discovering and scanning local AI agent components, MCP servers, skills, and related configuration for security risks. It reflects the new package-manager problem of executable agent ecosystems: installed tools are no longer just binaries, they are prompts, skills, MCP configs, and commands that may run during inspection.
The public GitHub repository was created in 2025. Its README describes Agent Scan as a tool for inventorying installed agent components and scanning for prompt injections, sensitive data handling, malware payloads hidden in natural language, tool poisoning, toxic flows, and vulnerabilities in agent skills.
The README notes that CLI output is experimental and that Agent Scan 0.4 was published with a technical report on emerging threats in the agent skill ecosystem, indicating a young tool aimed at a fast-changing area.
Official usage examples install and run the tool with `uvx snyk-agent-scan@latest`, while the input records a Homebrew formula. The supported-agent matrix includes mainstream developer agents such as Claude, Cursor, Windsurf, Gemini CLI, VS Code, Codex, Amazon Q, and others.
Users can run a full machine scan, scan a specific MCP configuration file, scan one skill file, or scan a directory of skills. The README warns that scanning MCP configurations may execute commands defined in those configs, so the CLI includes interactive consent and a deliberately named flag for trusted non-interactive runs.
Package nerds care because Agent Scan treats local agent configuration as supply chain surface. It scans the places modern developer tools install behavior, including project, user, system, extension, and plugin scopes, making it relevant to anyone packaging or auditing AI-enabled command-line environments.
安全态势
没有找到 snyk-agent-scan 的匹配本地密钥处理 manifest。Nucleus 软件包元数据仍在此发布,以便未来覆盖拥有稳定的软件包 URL。
在无人值守的代理使用前,请检查该工具是否读取明文凭据、写入远程状态、发布制品或调用插件。
可执行文件
| 命令 | 类型 | 暴露范围 | 备注 |
|---|---|---|---|
snyk-agent-scan | cli | 全局可执行文件 |
新鲜度
这些信号区分页生成时间、软件包管理器活动和上游发布比较。只有存在证据 URL 和可比较版本时,才会提示版本落后。
https://github.com/snyk/agent-scan
安装元数据
| 软件包键 | brew:snyk-agent-scan |
|---|---|
| 版本 | 0.5.15 |
| 软件包管理器 | Homebrew |
| 软件包管理器页面 | https://formulae.brew.sh/formula/snyk-agent-scan |
| 主页 | https://github.com/snyk/agent-scan |
| 仓库 | https://github.com/snyk/agent-scan |
| 上游文档 | https://github.com/snyk/agent-scan#readme |
| 许可证 | Apache-2.0 |
| 源码归档 | https://files.pythonhosted.org/packages/a3/51/27ef1f809249107da45f6f3f4f190af7da51293257d3c84b2da1261edc9f/snyk_agent_scan-0.5.15.tar.gz |
| 最后更新 | 2026-07-17T17:13:21Z |
| Pulse | updated |
| 依赖 | certifi, cryptography, libyaml, pydantic, python@3.14, rpds-py |
| Bottle | 可用 (于 arm64_linux, arm64_sequoia, arm64_sonoma, arm64_tahoe, sonoma, x86_64_linux) |
| Homebrew post-install | 未定义 |
| 服务 | 未声明 |
注册表事实
| Source Database | Homebrew formula API |
|---|---|
| Tap | homebrew/core |
| Full Name | snyk-agent-scan |
| Version Scheme | 0 |
| Revision | 0 |
| Bottle Stable Root URL | https://ghcr.io/v2/homebrew/core |
| Deprecated | no |
| Disabled | no |
| Keg Only | no |
| URL Keys |
|
来源线索
此页面由 av-web 从 scripts/generate-pkg-sqlite.py 生成的私有软件包 SQLite 工件提供。
View the package source record on GitHub.