Skip to main content

Snyk Labs

Featured article

Introducing Agent Scan - Skill Inspector: Detect Malicious Skills Instantly

Headshot of Krysztof Huszcza

Krysztof Huszcza


As organizations adopt AI agents, visibility into what those agents can actually do, including tools, permissions, external dependencies, and hidden execution paths, becomes increasingly critical. Traditional security tooling was never built to understand agent “skills” or MCP-based supply chains.

With AI agent skills becoming part of real developer workflows. A single install command can connect an autonomous agent to your codebase, system tools, or external services. Unlike installing a passive library, these skills can execute logic, retrieve data, and trigger downstream actions on your behalf.

Snyk Agent Scan - Skill Inspector helps developers and security teams detect malicious skills, insecure configurations, and leaked secrets before they reach production, and until now, it has been available via our CLI. 

Latest Demos and Research

Featured Video

Vibe Coding with Claude Agentic AI Tool

Experiments

Where security meets curiosity

Explore projects from Snyk Labs

ai-bom-scan

Python

A tool to scan Snyk AI-BOMs for specific components in Snyk organizations

December 16, 2025


8

7

0

ai-promoter

Python

A simple web application that makes it easy for employees at your company to see and promote content you're creating!

October 30, 2025


3

0

0

mcp-server-nodejs-api-docs

JavaScript

MCP Server for the Node.js API documentation

August 18, 2025


4

2

0