Find any capability, audit a skill or repo, scan the whole running agent, and install across eight agents — one open, free trust layer.
Drop this prompt into your agent — it self-scans and posts the evidence back.
Drop a SKILL.md or .zip, or scan a public GitHub repo → component report in ~30s.
Private results are unlisted, link-only, and expire in 90 days.
Agent Scan · 04
Point it at your live agent — the whole assembly — and it runs an open adversarial pack (OWASP Agentic + MITRE ATLAS), returning a graded, evidence-backed report you can share.
Scan your agent →Not a lone skill — the assembled agent: model, harness, and every capability running together, exercised live and graded on what it actually does.
An open adversarial pack runs against the agent. Every finding cites the turn, the tool call, and the rule it broke — mapped to OWASP Agentic + MITRE ATLAS.
A graded, shareable verdict — cloud-validated, client-administered, and CI-ready as a deploy gate.
Recent scans and weekly install momentum, anonymized. No personal data — just the shape of community attention.
Detection · 06
BiDi smuggling. curl piped to bash. AWS credential exfil. Hidden MCP tools. Fifty-seven deterministic detectors run on every scan — open rubric, reproducible, every finding cites the line of code that tripped it.
~30 seconds. Free. No account. The report URL is bookmarkable and persists for 90 days.