Snyk Labs

Featured article
Introducing Agent Scan - Skill Inspector: Detect Malicious Skills Instantly
Krysztof Huszcza
As organizations adopt AI agents, visibility into what those agents can actually do, including tools, permissions, external dependencies, and hidden execution paths, becomes increasingly critical. Traditional security tooling was never built to understand agent “skills” or MCP-based supply chains.
With AI agent skills becoming part of real developer workflows. A single install command can connect an autonomous agent to your codebase, system tools, or external services. Unlike installing a passive library, these skills can execute logic, retrieve data, and trigger downstream actions on your behalf.
Snyk Agent Scan - Skill Inspector helps developers and security teams detect malicious skills, insecure configurations, and leaked secrets before they reach production, and until now, it has been available via our CLI.
Latest Demos and Research
Step into the Lab
Get updates on future incubations or apply to co-build with us.
Featured Video
Vibe Coding with Claude Agentic AI Tool
Experiments
Where security meets curiosity
Explore projects from Snyk Labs
ai-bom-scan
Python
A tool to scan Snyk AI-BOMs for specific components in Snyk organizations
December 16, 2025
8
7
0
ai-promoter
Python
A simple web application that makes it easy for employees at your company to see and promote content you're creating!
October 30, 2025
3
0
0
mcp-server-nodejs-api-docs
JavaScript
MCP Server for the Node.js API documentation
August 18, 2025
4
2
0










