npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

agent-security-scanner-mcp

v4.5.9

Published

AI agent security scanner and npm audit for MCP servers, Claude Code, Cursor, and Windsurf. Find prompt injection, hallucinated packages, secrets, unsafe tools, and vulnerable code.

Readme

agent-security-scanner-mcp

Security scanner for AI coding agents, MCP servers, prompts, and AI-suggested packages.

Run it before Claude Code, Cursor, Windsurf, Cline, OpenCode, or another agent trusts new code, tools, prompts, or dependencies.

npm total downloads npm version License: MIT CI

Copy-Paste Start

Scan any repo and get an A-F agent security grade:

npx agent-security-scanner-mcp scan-project . --verbosity compact

Install the scanner into your AI coding client:

npx agent-security-scanner-mcp init claude-code

Replace claude-code with cursor, claude-desktop, windsurf, cline, kilo-code, opencode, or cody.

Audit an MCP server before adding it to an agent:

npx agent-security-scanner-mcp scan-mcp ./path/to/mcp-server --verbosity compact

Check AI-generated imports for package hallucinations:

npx agent-security-scanner-mcp scan-packages ./src/app.ts npm --verbosity compact

What It Catches

| Risk | Why agents need it | Command | | --- | --- | --- | | Vulnerable generated code | Agents can introduce SQL injection, XSS, command injection, unsafe crypto, and secrets | scan-project, scan-security, scan-diff | | MCP server attacks | MCP tools can poison descriptions, spoof names, exfiltrate env vars, or execute commands | scan-mcp | | Prompt injection | Agents often process untrusted docs, tickets, pages, and tool output | scan-prompt | | Unsafe agent actions | Catch dangerous shell/file/network actions before execution | scan-action | | Hallucinated packages | AI often invents dependency names that attackers can later squat | check-package, scan-packages | | SBOM and CVEs | Generate CycloneDX SBOMs and scan dependencies with OSV.dev | sbom-generate, sbom-vulnerabilities | | Semantic review | LLM-powered review that uses project intent to find context-aware issues | cr-agent |

Screenshots

Project Scan

Project scan demo

MCP Server Audit

MCP audit demo

Package Hallucination Detection

Package hallucination demo

Demos

Run a safe local demo that creates intentionally vulnerable fixtures, scans them, and cleans them up.

# MCP audit demo: tool poisoning, spoofed tool name, command execution, secret exposure
npx agent-security-scanner-mcp demo --type mcp --no-prompt

# Package hallucination demo: real imports mixed with fake AI-generated package names
npx agent-security-scanner-mcp demo --type packages --no-prompt

Expected demo shape:

{
  "grade": "F",
  "findings_count": 8,
  "findings": [
    {
      "rule": "mcp.description-injection",
      "severity": "ERROR",
      "message": "Tool description contains imperative language directed at the LLM."
    },
    {
      "rule": "mcp.tool-name-spoofing",
      "severity": "ERROR",
      "message": "Tool name is close to a well-known MCP tool name."
    }
  ]
}

Install In Your Agent

npx agent-security-scanner-mcp init claude-code

| Client | Setup | | --- | --- | | Claude Code | npx agent-security-scanner-mcp init claude-code | | Cursor | npx agent-security-scanner-mcp init cursor | | Claude Desktop | npx agent-security-scanner-mcp init claude-desktop | | Windsurf | npx agent-security-scanner-mcp init windsurf | | Cline | npx agent-security-scanner-mcp init cline | | Kilo Code | npx agent-security-scanner-mcp init kilo-code | | OpenCode | npx agent-security-scanner-mcp init opencode | | Cody | npx agent-security-scanner-mcp init cody | | Interactive picker | npx agent-security-scanner-mcp init |

Then restart the client. Your agent can call the scanner as an MCP tool.

Agent Playbook

Paste this into an agent task when you want it to work safely:

Before trusting new code, dependencies, prompts, or MCP tools, run:

1. npx agent-security-scanner-mcp scan-project . --verbosity compact
2. npx agent-security-scanner-mcp scan-packages ./src/app.ts npm --verbosity compact when imports change
3. npx agent-security-scanner-mcp scan-mcp ./path/to/mcp-server --verbosity compact before adding MCP servers
4. npx agent-security-scanner-mcp scan-diff --base main --target HEAD before opening a PR

Fix high-confidence security findings before continuing.

Common Workflows

Before You Trust An Agent-Written PR

npx agent-security-scanner-mcp scan-diff --base main --target HEAD --verbosity compact
npx agent-security-scanner-mcp scan-packages ./src/app.ts npm --verbosity compact

Before Installing An MCP Server

npx agent-security-scanner-mcp scan-mcp ./path/to/mcp-server --verbosity compact

Before Adding A Dependency Suggested By AI

npx agent-security-scanner-mcp check-package express npm
npx agent-security-scanner-mcp scan-packages ./package.json npm --verbosity compact

Add CI

npx agent-security-scanner-mcp init-ci github

Generate Share Copy From A Real Scan

npx agent-security-scanner-mcp scan-project . --verbosity compact > scan-result.json
npx agent-security-scanner-mcp share-kit --scan-result scan-result.json --output share-kit.md

Optional Product Updates

On the first interactive CLI run, ProofLayer may ask for an email address:

ProofLayer updates? Email (optional, Enter to skip):

Press Enter to skip. The CLI sends aggregate prompt metrics such as prompted, skipped, invalid, or submitted so ProofLayer can understand opt-in friction. If an email is entered, the CLI sends only the email address to ProofLayer's lead endpoint. It does not require login and does not upload source code, scan results, prompts, secrets, paths, package metadata, or dashboard data. Set PROOFLAYER_DISABLE_EMAIL_CAPTURE=1 or pass --no-email-capture to disable the prompt.

ProofLayer also sends privacy-safe aggregate install, runtime, and value events so we can distinguish npm downloads from real usage and understand whether scans deliver useful results. These events include package version, command name, TTY/CI status, platform, Node major version, package manager, anonymous install hash, first successful scan, scan count, vulnerability and severity counts, files-scanned count, grade, policy result, duration bucket, and aggregate remediation outcomes. They do not include email, username, repository path, current working directory, source code, raw findings, rule IDs, prompts, secrets, dependency names, or scan contents. Set PROOFLAYER_DISABLE_TELEMETRY=1 to disable aggregate telemetry.

After reviewing findings, CLI and MCP users can explicitly record aggregate remediation outcomes. ProofLayer never infers acceptance merely because a finding was displayed:

npx agent-security-scanner-mcp record-outcome --accepted 3 --dismissed 1 --fixed 2

Open The Enterprise Dashboard

npx agent-security-scanner-mcp login
npx agent-security-scanner-mcp scan-project . --save-history --verbosity compact
npx agent-security-scanner-mcp dashboard --project .

The login command opens a web UI and stores a private ProofLayer session on your machine. The dashboard reads saved .scanner/results history, shows previous scans, trends, finding hotspots, workstation signals, and enterprise policy/evidence previews.

Enterprise teams can opt in to cloud dashboard sync without uploading source code, prompts, secrets, or raw findings:

npx agent-security-scanner-mcp login --email [email protected] --company "Acme" --dashboard-sync-opt-in --telemetry-opt-in
npx agent-security-scanner-mcp scan-project . --save-history --verbosity compact

The opt-in cloud payload is metadata-only: project hash, package version, OS, command name, scan grade, files scanned, issue counts, severity counts, and duration. Hosted deployments can point the CLI at private endpoints with PROOFLAYER_DASHBOARD_URL, PROOFLAYER_API_URL, --dashboard-url, or --api-url.

CLI Reference

| Command | Use | | --- | --- | | scan-project <dir> | Full project scan with A-F grade | | scan-security <file> | Single-file security scan | | scan-diff --base main --target HEAD | Scan changed files only | | scan-mcp <path> | Audit an MCP server before install | | scan-prompt "<text>" | Detect prompt injection and jailbreak attempts | | scan-action <type> <value> | Pre-execution safety check for shell/file/network actions | | record-outcome | Record aggregate accepted, dismissed, and fixed counts | | check-package <name> <ecosystem> | Verify one package exists | | scan-packages <file> <ecosystem> | Verify imports/dependencies in a file | | doctor | Check local setup health | | quickstart --client cursor | Generate repo-specific next steps | | share-kit | Generate public-safe launch/share copy | | login | Open ProofLayer Enterprise login; supports opt-in dashboard sync | | dashboard --project . | Open local enterprise dashboard with scan history | | export-vanta | Export scan evidence to the ProofLayer Vanta integration |

All scanner outputs support context-friendly verbosity:

--verbosity minimal   # counts only, best for CI
--verbosity compact   # default, best for agents and humans
--verbosity full      # audit/debug detail

MCP Tools For Agents

When installed as an MCP server, agents get these tool families:

| Tool family | Purpose | | --- | --- | | scan_security, fix_security, scan_git_diff, scan_project | Code and repo security | | scan_mcp_server, scan_skill | MCP and AI skill security | | scan_agent_prompt, scan_agent_action | Prompt/action safety | | check_package, scan_packages | Package hallucination detection | | sbom_generate, sbom_scan_vulnerabilities, sbom_diff, sbom_export_report | Supply-chain and release evidence | | get_compliance_controls, evaluate_compliance | SOC2/GDPR/AIUC-1 technical evidence | | scanner_health | Runtime diagnostics |

Why Developers Install It

  • One npx command gives an A-F security grade for AI-written code.
  • MCP-specific checks catch risks that normal SAST tools miss.
  • Package hallucination detection checks 4.3M+ package names across npm, PyPI, RubyGems, crates.io, pub.dev, CPAN, and raku.land.
  • Output is compact by default so coding agents can read it without burning the context window.
  • Works as a CLI, MCP server, GitHub Action workflow, Apify Actor, and semantic review agent.
  • MIT licensed.

Semantic Code Review

cr-agent is bundled with the npm package for LLM-powered semantic review. It reads project intent, then looks for code that violates that intent.

npx cr-agent analyze ./path/to/project -p claude-cli --verbose
npx cr-agent analyze ./path/to/project -p openai --format sarif

Use it when rule-based scanning is not enough and the question is, "Does this code make sense for what this project is supposed to do?"

SBOM And Compliance Evidence

npx agent-security-scanner-mcp sbom-generate .
npx agent-security-scanner-mcp sbom-vulnerabilities .
npx agent-security-scanner-mcp sbom-check-hallucinations .
npx agent-security-scanner-mcp evaluate-compliance . --framework soc2-technical

Useful before releases, SOC 2 evidence collection, vendor reviews, and AI-generated dependency changes.

Apify Actor

Run the scanner as an Apify Actor when you want a hosted API or scheduled scans:

{
  "actorId": "folkloric_morale/agent-security-scanner",
  "input": {
    "target": "repository",
    "repoUrl": "https://github.com/your-org/your-agent.git",
    "repositoryScanMode": "quick",
    "includeTestFiles": false,
    "maxRepositoryFiles": 150,
    "severityThreshold": "medium"
  }
}

Latest Release

v4.5.9 adds one-time first-scan activation, aggregate scan-value telemetry, and explicit remediation outcome tracking with a strict privacy allowlist.

Detailed release history lives in CHANGELOG.md. The older README-embedded changelog is archived at archive/README_CHANGELOG_ARCHIVE.md.

FAQ

Is this only for MCP servers? No. It scans normal repos, diffs, prompts, actions, packages, SBOMs, MCP servers, and AI skills.

Does it send my source code anywhere? Rule-based CLI and MCP scans are local. cr-agent uses the provider you choose for semantic review.

What does the optional email prompt send? Aggregate prompt metrics such as prompted/skipped/invalid/submitted, and only the email address when a user types one.

What does aggregate telemetry send? Install/runtime events and aggregate value metrics: version, command, TTY/CI status, platform, Node major version, package manager, client hint, anonymous install hash, scan counts, vulnerability/severity counts, grade, policy result, duration bucket, and explicitly reported remediation outcomes. It never sends paths, code, raw findings, rule IDs, prompts, secrets, or dependency names. Disable it with PROOFLAYER_DISABLE_TELEMETRY=1.

Is it a replacement for npm audit? No. It complements npm audit by catching AI-specific risks: hallucinated packages, prompt injection, MCP tool poisoning, unsafe agent actions, and vulnerable generated code.

What should I run first? Run npx agent-security-scanner-mcp scan-project . --verbosity compact.

Links

License

MIT