security check

Nobody reads what their agent installs. We do.

Your agent installs AI skills, MCP servers and npm packages on a single chat message. Paste what you're about to install and see exactly what it does before it ever runs on your machine.

Paste the install command you were about to run. We read the published files as text — we never run them.

try:

Automated risk assessment. Not a guarantee of safety.

What we look at

One careless install can hand a stranger your SSH keys, cloud credentials and every file on disk — or plant hidden instructions your agent will follow without ever showing you. A check takes seconds.

npm package security check

  • Install scripts that fetch or run code on your machine
  • Code that touches SSH keys, cloud credentials, tokens or wallets
  • Where it sends data, and whether those places are known
  • Release age, provenance, maintainer changes and known advisories

MCP security scanner

  • Every tool it offers, and what each one claims to do
  • Hidden instructions and invisible characters in tool descriptions
  • Tools that steer your agent towards other tools or secrets
  • A fingerprint of the tool list, so you are told when it changes

Recent checks, with real findings

Every report below came from a live package or server — read the findings before you install.

loading…