AgentGuard

Deep Scan

Deep Scan for AI Agent Components

Review skills, plugins, agents, and MCP servers for documented component risks before they become trusted dependencies.

A scan result supports review; it does not guarantee that a component or its future behavior is safe.

Control surfaceReview ready
01Skillsverify
02Pluginsverify
03Agentsverify
04MCP Serversverify
FEATURES / 01

Components and Risks

The public product surface names four component types and four risk categories for Deep Scan.

Component titles

Skills

Component titles

Plugins

Component titles

Agents

Component titles

MCP Servers

Risk titles

Prompt Injection

Risk titles

Malicious Tools

Risk titles

Credential Leaks

Risk titles
Backdoors

These documented categories are not a complete detection taxonomy or a coverage guarantee.

FEATURES / 02

Choose a Scan Path

Choose the Component

Identify the repository, package, MCP server, URL, skill, plugin, or agent you need to review.

Use Current Documentation

Follow the supported CLI, Quickstart, or API path available for that component.

Inspect and Record the Result

Review the finding with component provenance, permissions, dependencies, and configuration in view.

API note

The public API Reference lists repository, package, MCP-server, and URL scan endpoints. Live request and response behavior has not been verified in this audit.

FEATURES / 03

Review the Findings

Use the result to investigate
Component provenance
Requested permissions
Dependencies and external resources
Configuration and material changes
Do not infer
Complete risk coverage
Permanent safety after an update
Safe runtime behavior
A guaranteed detection outcome
FEATURES / 04

Lifecycle Scanning

Stage 1 title

Before Trust

Stage 1 copy

Use Deep Scan to review a component before it becomes a dependency.

After Material Change

Review the component again when its source, package, permissions, or configuration changes.

During Execution

Use Runtime Guard where the selected integration can evaluate documented high-risk actions.

Next step

Explore Runtime Guard

FEATURES / 05

Frequently Asked Questions

Which components can Deep Scan review?
The public homepage names skills, plugins, agents, and MCP servers.
Which risks are documented?
Prompt injection, malicious tools, credential leaks, and backdoors.
Does a clean scan guarantee safety?
No. Public evidence does not establish complete coverage or a safety guarantee.
Which package ecosystems are supported?
The reviewed evidence does not define a complete package-ecosystem list.

Review Before Trust

Use the documented integration, verify expected outcomes, and record any action that remains outside the control path.