# Agent Security Scanner MCP (MCP server)

> Agent Security Scanner MCP is an MCP server that adds developer tools to AI assistants such as Claude Desktop, Claude Code and Cursor. Security layer for AI agents: blocks prompt injection, detects fake packages, scans vulnerabilities. It has 122 GitHub stars, is released under the MIT license and runs locally with npx -y agent-security-scanner-mcp.

Security scanner for AI coding agents, MCP servers, prompts, and AI-suggested packages. Run it before Claude Code, Cursor, Windsurf, Cline, OpenCode, or another agent trusts new code, tools, prompts, or dependencies.

## Key facts

| Fact | Value |
|---|---|
| Repository | https://github.com/sinewaveai/agent-security-scanner-mcp |
| GitHub stars | 122 |
| License | MIT |
| Language | JavaScript |
| Transport | stdio |
| Packages | npm: agent-security-scanner-mcp |
| Remote URL | none |
| Needs API key | no |
| Official | no |
| Works with | Claude Desktop, Claude Code, Cursor, VS Code |
| Category | Developer tools |
| Latest release | v4.4.5 (Jun 22, 2026) |
| Last commit | Sep 2, 2026 |
| MCP registry name | io.github.sinewaveai/agent-security-scanner-mcp |

## Install

### Claude Desktop (claude_desktop_config.json)

```json
{
  "mcpServers": {
    "agent-security-scanner-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "agent-security-scanner-mcp"
      ]
    }
  }
}
```

Settings > Developer > Edit Config. macOS: ~/Library/Application Support/Claude/, Windows: %APPDATA%\Claude\. Restart Claude Desktop afterwards.

### Claude Code

```sh
claude mcp add --transport stdio agent-security-scanner-mcp -- npx -y agent-security-scanner-mcp
```

### Cursor (.cursor/mcp.json)

```json
{
  "mcpServers": {
    "agent-security-scanner-mcp": {
      "type": "stdio",
      "command": "npx",
      "args": [
        "-y",
        "agent-security-scanner-mcp"
      ]
    }
  }
}
```

Project file; use ~/.cursor/mcp.json to enable it in every project.

### VS Code (.vscode/mcp.json)

```json
{
  "servers": {
    "agent-security-scanner-mcp": {
      "type": "stdio",
      "command": "npx",
      "args": [
        "-y",
        "agent-security-scanner-mcp"
      ]
    }
  }
}
```

Config formats checked against the official docs on 2026-10-07.

## Similar MCP servers

- [Gemini CLI](https://appsgit.com/mcp-servers/gemini-cli): An open-source AI agent that brings the power of Gemini directly into your terminal. (107,240 stars, Apache-2.0)
- [Front-End Checklist](https://appsgit.com/mcp-servers/front-end-checklist): Review frontend code and live pages against 386 quality-gated web development rules. (74,390 stars, MIT)
- [Claude Flow](https://appsgit.com/mcp-servers/claude-flow): AI orchestration with hive-mind swarms, neural networks, and 87 MCP tools for enterprise dev. (74,016 stars, MIT, needs API key)
- [Codebase Memory](https://appsgit.com/mcp-servers/codebase-memory): Codebase knowledge graph for AI agents — 162 languages, sub-ms queries, 99% fewer tokens. (45,917 stars, MIT)
- [Bytedance Filesystem](https://appsgit.com/mcp-servers/bytedance-filesystem): MCP server for filesystem access. (39,206 stars, Apache-2.0)
- [GitHub](https://appsgit.com/mcp-servers/github): Connect AI assistants to GitHub - manage repos, issues, PRs, and workflows through natural language. (33,414 stars, MIT, official, needs API key)

---

Canonical page: https://appsgit.com/mcp-servers/agent-security-scanner-mcp
Source: appsgit (https://appsgit.com), the app store for github. Data from the GitHub API, refreshed nightly.
Machine access: JSON API https://appsgit.com/api/v1/apps (OpenAPI: https://appsgit.com/openapi.json), MCP server https://mcp.appsgit.com/mcp, full index https://appsgit.com/llms-full.txt.
