Agent Scan (snyk-agent-scan) inventories installed agent components — harnesses, MCP servers, and skills — and scans for prompt injections, sensitive data handling, and malware in natural language skill documents. Version 0.4 added skill scanning with a technical report on emerging agent skill ecosystem threats.

Auto-discovers configurations across Claude Code/Desktop, Cursor, Gemini CLI, Windsurf, and Amazon Q. Skills risks include prompt injection (91% of malicious skills), malware payloads (100% of confirmed malicious skills), credential handling flaws, and hardcoded secrets. Use --no-skills to skip skill analysis.