Agent security & threat detection
Snyk Agent Scan (formerly MCP-Scan)
Apache-2.0 command line scanner that discovers locally installed agent components — harnesses, MCP servers, skills — and checks tools, prompts and resources for prompt injection, tool poisoning, cross-origin escalation and tool changes, with a proxy mode that inspects live MCP traffic. Some checks call Snyk's hosted API.
open_source · generally available · Research snapshot 2026-09-06
Visit the official product source ↗Where it fits
Agent security & threat detection · Agent discovery & inventory · Runtime authorization & controls
Useful conversation with: CISO, AppSec engineer, Platform engineer.
Ask for a demonstration
Demonstrate scanning our developers' MCP configurations and show what a tool-poisoning and rug-pull finding looks like, plus which checks require the hosted API.
Capabilities and evidence
Support labels reflect the supplied research. Documentation and vendor claims are not independent product tests. “Not established” means the researcher did not find support; it does not prove a capability is absent.
Documented by provider
The repository states the tool discovers installed agent components including harnesses, MCP servers and skills and scans MCP servers, tools, prompts, resources and skills for prompt injections, sensitive data handling and malware payloads hidden in natural language.
Limit: Detection quality is not quantified; local checks are supplemented by the Agent Scan API, so fully offline coverage is unclear.
Source s1
Documented by provider
Earlier project documentation describes a proxy mode that monitors MCP connections in real time, checks tool calls, applies data-flow constraints and detects PII and indirect prompt injection, plus tool pinning that hashes tools to detect rug-pull changes.
Limit: Proxy-mode guardrailing relied on Invariant Guardrailing models via an API; feature naming changed after the rename to Agent Scan.
Source s2 · Source s3
Independently corroborated
Snyk announced its acquisition of Invariant Labs, adding research on MCP vulnerabilities, tool poisoning and runtime detection to Snyk Labs and its AI Trust Platform.
Limit: Vendor announcement; it does not state the licensing or long-term open-source commitment for the scanner.
Source s4
Limitations to discuss
- Repository redirect means older documentation and the current tool name diverge
- Cloud API dependency for some checks
Sources
- snyk/agent-scan · Snyk / GitHub · official repository
Access date reported by researcher: 2026-09-06 - invariantlabs-ai/mcp-scan (redirects to snyk/agent-scan) · GitHub · official repository
Access date reported by researcher: 2026-09-06 - Introducing MCP-Scan · Invariant Labs · official release
Access date reported by researcher: 2026-09-06 - Snyk acquires Invariant Labs · Snyk · official release
Access date reported by researcher: 2026-09-06
Listing does not imply partnership, supplier status, a working DutyGraph integration, or a compliance certification.
Suggest a correction