Snyk claims its released agent-scan can identify security risks in AI agents, MCP servers, and agent skills, potentially providing a practical predeployment security scanner for agent ecosystems.
state: expiredheat: lowuncertainty: highknownscott: mediumagentic-security mcp-security agent-toolingSnyk
What is this?
Snyk has released Agent Scan in open preview, a CLI that discovers local AI-agent configurations and assesses MCP servers, tools, and agent skills before deployment. Snyk says it detects more than 15 risk types, including prompt injection, tool poisoning or shadowing, toxic flows, malicious code, credential handling, and hardcoded secrets across agents such as Claude, Cursor, Windsurf, and Gemini CLI. The supplied material establishes the product’s availability and claimed scope, but provides no independent evidence of detection accuracy or practical effectiveness; use requires a Snyk account/API token.
Why it matters to Scott
The radar already tracks this scanner pattern in AgentShield and SkillPreflight, so Snyk’s release is another unvalidated implementation rather than a new security thesis. It could still be practically tested as a predeployment gate for Scott’s MCP IP Wiki and agent architectures, but the supplied evidence does not establish detection effectiveness or whether scanning can replace his load-bearing runtime containment and authority controls.
ip:framework.agent-provenance-stackip:framework.siloosip:source.mcp-as-the-tool-belt-standard-giving-ai-agents-hands-and-eyes-ebookdev:project.mcp-ip-wikiradar:agentshield-offline-agent-scannerradar:skillpreflight-agent-skill-scoringradar:concept.mcp-securityradar:concept.agent-skills
queries asked of Scott's wikis
- MCP server trust and tool supply-chain security
- predeployment scanning for agent tools and skills
- prompt injection and tool-poisoning defenses
- agent harness capability discovery and permissions
- static analysis versus runtime guardrails for agents
- security gates for coding-agent configurations
Measured heat
no measured readings yet — the hourly heat pass fills this in
How the heat travelled
no chain yet — the hourly chain pass fills this in
Evidence (2) — ⭐ canonical anchor
Interpretation history
2026-09-03T17:55:53Z
Repeated checks have produced no independent testing, adoption, or implementation evidence, leaving this as an established but unvalidated release in an already-known scanner category. The episode has faded beyond its near-term horizon and should be reopened only on benchmarks, field use, or consequential adoption.
2026-09-01T16:52:58Z
The staleness check produced no new evidence and failed to reobserve the source, so the case remains an established release with unvalidated effectiveness. Keep it cold pending independent benchmarks, field use, or consequential adoption.
2026-08-30T16:31:03Z
No new evidence changes the initial interpretation: the release is established, but detection quality and practical advantage over existing agent-security scanners remain unvalidated. The unchanged reobservation adds no momentum, so the case cools while awaiting independent testing or adoption.
2026-08-30T16:28:51Z
grounded: known/medium — The radar already tracks this scanner pattern in AgentShield and SkillPreflight, so Snyk’s release is another unvalidated implementation rather than a new secur
2026-08-30T16:27:15Z
case created — A first-party open-source release addresses a concrete security gap across several rapidly adopted agent extension formats.
Decision trace
- 09-04 03:55expireRepeated checks have produced no independent testing, adoption, or implementation evidence, leaving this as an established but unvalidated release in an already-known scanner category. The episode has
- 09-04 03:55alert_silentThe only delta is another unchanged staleness observation; no new fact affects Scott’s decisions or warrants interruption.
- 09-04 03:55alert_routeThe only delta is another unchanged staleness observation; no new fact affects Scott’s decisions or warrants interruption.
- 09-02 02:52repriceThe staleness check produced no new evidence and failed to reobserve the source, so the case remains an established release with unvalidated effectiveness. Keep it cold pending independent benchmarks,
- 09-02 02:52alert_silentThere is no substantive new delta—only elapsed time and a failed reobservation—so interruption would add no value before the next briefing.
- 09-02 02:52alert_routeThere is no substantive new delta—only elapsed time and a failed reobservation—so interruption would add no value before the next briefing.
- 08-31 02:31repriceNo new evidence changes the initial interpretation: the release is established, but detection quality and practical advantage over existing agent-security scanners remain unvalidated. The unchanged re
- 08-31 02:31alert_silentThis is only a legacy-state re-evaluation with no substantive delta; the established release was already assessed and can wait for the next briefing unless benchmarks, field results, or consequential
- 08-31 02:31alert_routeThis is only a legacy-state re-evaluation with no substantive delta; the established release was already assessed and can wait for the next briefing unless benchmarks, field results, or consequential
- 08-31 02:29alert_silentSnyk’s first-party release establishes that agent-scan exists, but the supplied evidence shows no detection results, distinctive coverage, or validated advantage over scanner patterns already tracked.
- 08-31 02:29surface_candidateSnyk’s first-party release establishes that agent-scan exists, but the supplied evidence shows no detection results, distinctive coverage, or validated advantage over scanner patterns already tracked.
- 08-31 02:29alert_routeSnyk’s first-party release establishes that agent-scan exists, but the supplied evidence shows no detection results, distinctive coverage, or validated advantage over scanner patterns already tracked.
- 08-31 02:28groundThe radar already tracks this scanner pattern in AgentShield and SkillPreflight, so Snyk’s release is another unvalidated implementation rather than a new security thesis. It could still be practicall
- 08-31 02:27createA first-party open-source release addresses a concrete security gap across several rapidly adopted agent extension formats.