{"id":"215a4c22-b9b5-4b32-b785-40e604ce699c","shortId":"mAAHfv","kind":"skill","title":"Snyk Agent Scan","tagline":"Scan your AI agents, MCP servers, and skills for security vulnerabilities from the command line. Snyk Agent Scan discovers and audits every agent component on your machine — detecting prompt injections, tool poisoning, toxic flows, malware payloads, and credential handling issues","description":"# Snyk Agent Scan\n\nScan your AI agents, MCP servers, and skills for security vulnerabilities from the command line. Snyk Agent Scan discovers and audits every agent component on your machine — detecting prompt injections, tool poisoning, toxic flows, malware payloads, and credential handling issues across 15+ distinct risk categories.\n\n## Prerequisites\n\nPython 3.10+, uv package manager, Snyk API token\n\n## Installation\n\nUse the upstream install or setup path that matches your environment:\n- uv run pip install -e .\n- uv run -m src.agent_scan.cli\n\nRequirements and caveats from upstream:\n- <a href=\"https://pypi.python.org/pypi/snyk-agent-scan\"><img src=\"https://img.shields.io/pypi/v/snyk-agent-scan.svg\" alt=\"snyk-agent-scan\"/></a>\n- <a href=\"https://pypi.python.org/pypi/snyk-agent-scan\"><img src=\"https://img.shields.io/pypi/l/snyk-agent-scan.svg\" alt=\"snyk-agent-scan license\"/></a>\n- <a href=\"https://pypi.python.org/pypi/snyk-agent-scan\"><img src=\"https://img.shields.io/pypi/pyversions/snyk-agent-scan.svg\" alt=\"snyk-agent-scan python version requirements\"/></a>\n\nBasic usage or getting-started notes:\n- **Use --dangerously-run-mcp-servers** only in trusted environments where you've verified all MCP server commands\n- To get started:\n- **Sign up at [Snyk](https://snyk.io)** and get an API token from [https://app.snyk.io/account](https://app.snyk.io/account) (API Token → KEY → click to show).\n\n- Source: https://github.com/snyk/agent-scan\n- Extracted from upstream docs: https://raw.githubusercontent.com/snyk/agent-scan/HEAD/README.md\n\n## Documentation\n\n- https://github.com/snyk/agent-scan/blob/main/docs/scanning.md\n\n## Source\n\n- [Agent Skill Exchange](https://agentskillexchange.com/skills/snyk-agent-scan/)","tags":["snyk","agent","scan","skills","agentskillexchange","agent-skills","ai-agents","ai-tools","awesome-list","claude-code","codex","cursor"],"capabilities":["skill","source-agentskillexchange","skill-snyk-agent-scan","topic-agent-skills","topic-ai-agents","topic-ai-tools","topic-awesome-list","topic-claude-code","topic-codex","topic-cursor","topic-llm","topic-mcp","topic-npx-skills","topic-openclaw","topic-skills-catalog"],"categories":["skills"],"synonyms":[],"warnings":[],"endpointUrl":"https://skills.sh/agentskillexchange/skills/snyk-agent-scan","protocol":"skill","transport":"skills-sh","auth":{"type":"none","details":{"cli":"npx skills add agentskillexchange/skills","source_repo":"https://github.com/agentskillexchange/skills","install_from":"skills.sh"}},"qualityScore":"0.454","qualityRationale":"deterministic score 0.45 from registry signals: · indexed on github topic:agent-skills · 8 github stars · SKILL.md body (1,725 chars)","verified":false,"liveness":"unknown","lastLivenessCheck":null,"agentReviews":{"count":0,"score_avg":null,"cost_usd_avg":null,"success_rate":null,"latency_p50_ms":null,"narrative_summary":null,"summary_updated_at":null},"enrichmentModel":"deterministic:skill-github:v1","enrichmentVersion":1,"enrichedAt":"2026-05-18T19:12:32.573Z","embedding":null,"createdAt":"2026-05-18T13:19:30.549Z","updatedAt":"2026-05-18T19:12:32.573Z","lastSeenAt":"2026-05-18T19:12:32.573Z","tsv":"'/account](https://app.snyk.io/account)':168 '/skills/snyk-agent-scan/)':196 '/snyk/agent-scan':178 '/snyk/agent-scan/blob/main/docs/scanning.md':189 '/snyk/agent-scan/head/readme.md':185 '15':88 '3.10':94 'across':87 'agent':2,7,20,26,45,50,63,69,191 'agentskillexchange.com':195 'agentskillexchange.com/skills/snyk-agent-scan/)':194 'ai':6,49 'api':99,163,169 'app.snyk.io':167 'app.snyk.io/account](https://app.snyk.io/account)':166 'audit':24,67 'basic':127 'categori':91 'caveat':124 'click':172 'command':17,60,151 'compon':27,70 'credenti':41,84 'danger':136 'dangerously-run-mcp-serv':135 'detect':31,74 'discov':22,65 'distinct':89 'doc':182 'document':186 'e':117 'environ':112,143 'everi':25,68 'exchang':193 'extract':179 'flow':37,80 'get':131,153,161 'getting-start':130 'github.com':177,188 'github.com/snyk/agent-scan':176 'github.com/snyk/agent-scan/blob/main/docs/scanning.md':187 'handl':42,85 'inject':33,76 'instal':101,105,116 'issu':43,86 'key':171 'line':18,61 'm':120 'machin':30,73 'malwar':38,81 'manag':97 'match':110 'mcp':8,51,138,149 'note':133 'packag':96 'path':108 'payload':39,82 'pip':115 'poison':35,78 'prerequisit':92 'prompt':32,75 'python':93 'raw.githubusercontent.com':184 'raw.githubusercontent.com/snyk/agent-scan/head/readme.md':183 'requir':122 'risk':90 'run':114,119,137 'scan':3,4,21,46,47,64 'secur':13,56 'server':9,52,139,150 'setup':107 'show':174 'sign':155 'skill':11,54,192 'skill-snyk-agent-scan' 'snyk':1,19,44,62,98,158 'snyk.io':159 'sourc':175,190 'source-agentskillexchange' 'src.agent_scan.cli':121 'start':132,154 'token':100,164,170 'tool':34,77 'topic-agent-skills' 'topic-ai-agents' 'topic-ai-tools' 'topic-awesome-list' 'topic-claude-code' 'topic-codex' 'topic-cursor' 'topic-llm' 'topic-mcp' 'topic-npx-skills' 'topic-openclaw' 'topic-skills-catalog' 'toxic':36,79 'trust':142 'upstream':104,126,181 'usag':128 'use':102,134 'uv':95,113,118 've':146 'verifi':147 'vulner':14,57","prices":[{"id":"6bf4d490-9d6e-4c25-8df7-065385c338b9","listingId":"215a4c22-b9b5-4b32-b785-40e604ce699c","amountUsd":"0","unit":"free","nativeCurrency":null,"nativeAmount":null,"chain":null,"payTo":null,"paymentMethod":"skill-free","isPrimary":true,"details":{"org":"agentskillexchange","category":"skills","install_from":"skills.sh"},"createdAt":"2026-05-18T13:19:30.549Z"}],"sources":[{"listingId":"215a4c22-b9b5-4b32-b785-40e604ce699c","source":"github","sourceId":"agentskillexchange/skills/snyk-agent-scan","sourceUrl":"https://github.com/agentskillexchange/skills/tree/main/skills/snyk-agent-scan","isPrimary":false,"firstSeenAt":"2026-05-18T13:19:30.549Z","lastSeenAt":"2026-05-18T19:12:32.573Z"}],"details":{"listingId":"215a4c22-b9b5-4b32-b785-40e604ce699c","quickStartSnippet":null,"exampleRequest":null,"exampleResponse":null,"schema":null,"openapiUrl":null,"agentsTxtUrl":null,"citations":[],"useCases":[],"bestFor":[],"notFor":[],"kindDetails":{"org":"agentskillexchange","slug":"snyk-agent-scan","github":{"repo":"agentskillexchange/skills","stars":8,"topics":["agent-skills","ai-agents","ai-tools","awesome-list","claude-code","codex","cursor","llm","mcp","npx-skills","openclaw","skills-catalog"],"license":"mit","html_url":"https://github.com/agentskillexchange/skills","pushed_at":"2026-05-18T19:02:17Z","description":"The open catalog of AI agent skills — 2,000+ security-scanned skills for Claude Code, Cursor, Codex, and more.","skill_md_sha":"5dd6c1038a634193e2f6822a1fb33394a7e3a63d","skill_md_path":"skills/snyk-agent-scan/SKILL.md","default_branch":"main","skill_tree_url":"https://github.com/agentskillexchange/skills/tree/main/skills/snyk-agent-scan"},"layout":"multi","source":"github","category":"skills","frontmatter":{"name":"Snyk Agent Scan","description":"Scan your AI agents, MCP servers, and skills for security vulnerabilities from the command line. Snyk Agent Scan discovers and audits every agent component on your machine — detecting prompt injections, tool poisoning, toxic flows, malware payloads, and credential handling issues across 15+ distinct risk categories."},"skills_sh_url":"https://skills.sh/agentskillexchange/skills/snyk-agent-scan"},"updatedAt":"2026-05-18T19:12:32.573Z"}}