About AgentScan
AgentScan is a security scanner for the skills that AI coding agents load, such as those used by Claude Code. Skills run with your permissions, so it reads a skill directory before installation and reports what it would do, including shell commands, network calls, secrets and the licence, with the exact line responsible for each finding.
The scan is deterministic and never executes or uploads the skill. It is installed as a command-line tool with pipx and offers commands to scan a folder, search a catalog of reviewed skills, install a bundle called Trust Pack and update installed items. It detects the agent runtime automatically and supports Claude Code, OpenAI Codex, OpenCode, Hermes and Grok Build. A web page also lets you paste a skill to scan it. The site describes the project as open source, though it is listed here as a proprietary product and no licence is stated. It also has a pricing page for paid offerings.
Key features
- Scans skills before installation
- Flags shell commands, network calls and secrets
- Reports the exact line for each finding
- Works offline with no execution of the skill
- Searchable catalog of reviewed skills
- Auto-detects Claude, Codex, OpenCode, Hermes and Grok
Good fit for
- →Vetting a downloaded Claude skill
- →Checking skill licences before use
- →Distributing reviewed workflows to a team
- Tags
- security
- ai-agents
- skill-scanner
- claude-code
- cli
- offline
- supply-chain
AgentScan: questions and answers
- What is AgentScan used for?
- AgentScan is a local, offline scanner that checks AI agent skills for shell commands, network calls, secrets and licensing before you install them, plus a catalog of reviewed skills. It is a good fit for vetting a downloaded Claude skill, checking skill licences before use and distributing reviewed workflows to a team.
- Is AgentScan free?
- Yes. AgentScan has a free plan.
- Is AgentScan open source?
- No. AgentScan is proprietary (closed-source) software. In the Security category, open-source options include Syft, Grype and Horusec.
- Can I self-host AgentScan?
- Yes. Although AgentScan is closed source, it can be self-hosted on your own servers, and the vendor also offers a hosted version.
Open-source alternatives to AgentScan
See all
Syft
Security
CLI tool and library for generating a Software Bill of Materials from container images and
Apache-2.0★ 9.6k
Grype
Security
A vulnerability scanner for container images and filesystems
Apache-2.0vs Snyk★ 13k
Horusec
Security
Horusec is an open source tool that improves identification of vulnerabilities in your pro
Apache-2.0vs Checkmarx★ 1.3k
Legitify
Security
Detect and remediate misconfigurations and security risks across all your GitHub and GitLa
Apache-2.0★ 889
Cryptomator
Security
Cryptomator for Windows, macOS, and Linux: Secure client-side encryption for your cloud st
GPL-3.0vs Tresorit★ 16k
VeraCrypt
Security
Disk encryption with strong security based on TrueCrypt
OSS★ 12k
SaaS alternatives to AgentScan
See all
Socket
Security
Supply chain security that detects risky open source packages before install
SaaS
Snyk
Security
Developer security platform that scans code, dependencies, containers and IaC
SaaS
Aikido Security
Security
All-in-one application security platform for code, cloud and runtime scanning
SaaS
Checkmarx
Security
Application security testing platform with SAST, SCA and API security
SaaSVeracode
Security
Application security testing platform covering static, dynamic and software composition
SaaSBeesecure
Security
Security scanning platform that finds vulnerabilities in codebases for developers and indie hackers
SaaS

