Agent security & threat detection

Snyk Agent Scan (formerly MCP-Scan)

Apache-2.0 command line scanner that discovers locally installed agent components — harnesses, MCP servers, skills — and checks tools, prompts and resources for prompt injection, tool poisoning, cross-origin escalation and tool changes, with a proxy mode that inspects live MCP traffic. Some checks call Snyk's hosted API.

open_source · generally available · Research snapshot 2026-09-06

Visit the official product source ↗

Where it fits

Agent security & threat detection · Agent discovery & inventory · Runtime authorization & controls

Useful conversation with: CISO, AppSec engineer, Platform engineer.

Ask for a demonstration

Demonstrate scanning our developers' MCP configurations and show what a tool-poisoning and rug-pull finding looks like, plus which checks require the hosted API.

Capabilities and evidence

Support labels reflect the supplied research. Documentation and vendor claims are not independent product tests. “Not established” means the researcher did not find support; it does not prove a capability is absent.

Documented by provider

The repository states the tool discovers installed agent components including harnesses, MCP servers and skills and scans MCP servers, tools, prompts, resources and skills for prompt injections, sensitive data handling and malware payloads hidden in natural language.

Limit: Detection quality is not quantified; local checks are supplemented by the Agent Scan API, so fully offline coverage is unclear.

Source s1

Documented by provider

Earlier project documentation describes a proxy mode that monitors MCP connections in real time, checks tool calls, applies data-flow constraints and detects PII and indirect prompt injection, plus tool pinning that hashes tools to detect rug-pull changes.

Limit: Proxy-mode guardrailing relied on Invariant Guardrailing models via an API; feature naming changed after the rename to Agent Scan.

Source s2 · Source s3

Independently corroborated

Snyk announced its acquisition of Invariant Labs, adding research on MCP vulnerabilities, tool poisoning and runtime detection to Snyk Labs and its AI Trust Platform.

Limit: Vendor announcement; it does not state the licensing or long-term open-source commitment for the scanner.

Source s4

Limitations to discuss

Sources

  1. snyk/agent-scan · Snyk / GitHub · official repository
    Access date reported by researcher: 2026-09-06
  2. invariantlabs-ai/mcp-scan (redirects to snyk/agent-scan) · GitHub · official repository
    Access date reported by researcher: 2026-09-06
  3. Introducing MCP-Scan · Invariant Labs · official release
    Access date reported by researcher: 2026-09-06
  4. Snyk acquires Invariant Labs · Snyk · official release
    Access date reported by researcher: 2026-09-06

Listing does not imply partnership, supplier status, a working DutyGraph integration, or a compliance certification.

Suggest a correction